Follow

SSL Inspector/Captive Portal Ignore Rules for Chromebooks

When using Chromebooks on a network with SSL Inspector configured to "Inspect All Traffic" or "Inspect Google Traffic", you will need Ignore Rules to allow the Chromebooks to authenticate.


As of (August 24th, 2016) you will need rules for the following hosts:

accounts.google.com gweb-gettingstartedguide.appspot.com
accounts.gstatic.com m.google.com
accounts.youtube.com omahaproxy.appspot.com
clients1.google.com pack.google.com
clients2.google.com safebrowsing-cache.google.com
clients3.google.com safebrowsing.google.com
clients4.google.com ssl.gstatic.com
commondatastorage.googleapis.com storage.googleapis.com
cros-omahaproxy.appspot.com tools.google.com
dl.google.com www.googleapis.com
dl-ssl.google.com www.gstatic.com

 

PLEASE NOTE: Google is known to change these addresses without warning.

 

To add the rules go to SSL Inspector Settings -> Rules -> Add Rule

The rule conditions should be "SSL: SNI Hostname" is: "<host>" and the Action should be "Ignore"

 

For example:

Was this article helpful?
0 out of 1 found this helpful
Have more questions? Submit a request

Comments

  • Avatar
    Adam Smith

    Did you find it unnecessary to include the dozen or so other URLs Google has as part of their white list in the instructions for SSL in your own white list?

  • Avatar
    Jaymes Driver

    I broke down and added all these sites to my allow list.

    I will test further if time allows but we are currently in a testing phase of some new hardware and we are unsure if this solution will best fit us.

Powered by Zendesk