

For these connections, Sophos Firewall only replaces the key in the certificate with the key used to re-encrypt the decrypted and inspected content, and signs the certificate with this key. Self-signed certificates allow end-to-end encryption but don't guarantee the website's identity.

Some servers use a self-signed certificate instead of a certificate signed by a CA.

Self-signed versus trusted CA certificates Self-signed certificates We recommend creating an SSL/TLS exclusion list for all Android devices. Android devices are known to generate SSL/TLS certificate errors, causing decryption to fail.
