Skip to main content

Check out Interactive Visual Stories to gain hands-on experience with the SSE product features. Click here.

Skyhigh Security

Generate Certificate Authority (CA) and User Identity (.p12) Certificates using XCA Tool

The Skyhigh Mobile Client application enables end users to securely access the Internet and private applications from Android devices. When end users access websites or private applications, the traffic is forwarded to the Skyhigh SWG (Cloud & On-Prem) for policy enforcement before it is forwarded to the actual website or private application.

NOTES: 

  • This topic is intended for MDM administrators who manage end users' Android devices via the Skyhigh Mobile Client app. 
  • Skyhigh recommends creating a new user group and applying all relevant policies and configurations to the group. Once the Skyhigh Mobile Client setup and deployment are complete, MDM administrators can add new users to the group.

Prerequisites 

Generate a self-signed certificate authority(CA) and use this file to generate a user identity(.p12) file. Upload the CA file to the Skyhigh UI. Download the customer Tenant CA certificate from the Skyhigh UI.

  • MDM Setup: Create a VPN profile along with a user identity(.p12) file and  Customer tenant CA certificate and push it directly to the Android devices using MDM. 
  • BYOD Setup: Share the Customer tenant CA certificate and upload a user identity (.p12) file to the user. The user has to install the CA certificate and trust in the device settings. The user has to install the app and upload p12 file which creates VPN.
Generate Certificate Authority (CA) and User Identity (.p12) certificates

Create a self-signed CA file and use the same file to generate the User Identity files and sign those. 

NOTE: You can create one user identity file per user or device.

▼ Generate Certificates using XCA tool

You can generate the certificate using the XCA tool. For more detilas, see Generate VPN Authentication Certificates Using XCA

Upload CA certificate generated to the Skyhigh Security UI

 Upload the CA certificate generated in Step 1 to the Skyhigh Security UI.

NOTE: After this step, wait for 30-40 minutes before connecting VPN

  1. Go to Settings > Infrastructure > Web Gateway Setup.

    1.png
     
  2. Click Configure on the Skyhigh Mobile Cloud Security setting.

    2.png
     
  3. Click Upload and select the custom CA certificate.

NOTE: supported certificate formats are DER, PEM, CRT, and CER.

3.png

  1. Specify the User name and an optional User Group in the User Identity certificates. 

    4.png
     
  1. Click Save

    5.png
     
  1. Click Upload & Test and upload the User identity file with format as .cer, .crt, .pem or .der to validate the CA and user Identity file.

    6.png
     
  1. Click Save to save the configuration. 

    7.png
     
  1. Click Publish to apply the changes. 
Download Tenant Customer CA from Skyhigh UI 
  1. Go to Policy > Web Policy > Feature Configuration

    8.png

     
  1. Select HTTPS connections > Customer CA.

    9.png
     
  1. Select Customer CA and click Export to download the Customer CA file.

    10.png
  2. Share this Customer CA certificate with the user if selecting Manual VPN config. 
Download and Install the Customer Root CA Certificates and P12 Certificate
  1. Download the Customer Root CA certificate using this link
  2. Use the P12 certificate generated by the XCA tool. To generate, see User Identity (.p12) certificates section 
  3. To install the certificate, go to Settings > Security and Privacy > More security settings
  4. Tap Install from device storage.

    244_1.jpeg
  5. On the Install from device storage screen, perform the following: 
    1. To install the CA certificate, tap the CA certificate
  6. To install the VPN certificate, tap the VPN and app user certificate. 

    245_1.jpeg


    Once the certificates are installed or pushed to the device, install the Skyhigh Mobile Client app from the Google Play Store. For more information, see Skyhigh Mobile Client App for Android Devices.