Drag the actions into the order in which they occur as an HTTPS session passes through the Cisco WSA.
For HTTPS proxy/decryption, Cisco WSA first receives the client TLS hello and establishes the corresponding connection to the destination server, which supplies its certificate. WSA then sends the client a proxied certificate for that destination, allowing the client to encrypt and send the session key. Once the TLS key exchange completes, the encrypted data channel is established.
Community Discussion