Cisco Secure Access Help Manage Certificates Certificates for Internet Decryption

Last updated: Aug 29, 2025

Certificates for Internet Decryption

Certificates are required for secure internet access. Specifically, certificates are required to decrypt traffic in order to inspect it for threats, and to present notifications to end users when access is blocked or triggers a warning. Web security features and the intrusion prevention (IPS) feature all require decryption in order to be effective.

End-user devices that connect to resources through Secure Access must trust the connection with Secure Access. You must set up certificates to establish this trust.

For internet traffic, depending on the features you need, there are two ways for end-user devices to validate the certificate that Secure Access presents to end-user devices that connect to internet resources through Secure Access:

  1. You can install the self-signed Secure Access certificate into the browser trust stores of all end-user endpoint devices, or
  2. You can sign the Secure Access certificate using your corporate certificate authority (CA) so that it can be validated by an existing certificate in the trust store of end-user devices. This method also allows you to easily revoke the certificate if needed, without having to update all end-user devices.