The following is the workflow for configuring and deploying an intent-based SSL forward proxy policy in CSO:
If you want to use additional trusted certificates, import and install the certificates as explained in Step 3 and 4.
Note
Use the imported root certificate when you create the SSL proxy profile.
For trusted certificates, specify that all trusted certificates on the device are used (select All in the Trusted Certificate Authorities field).
Note
Ensure that the root and trusted certificates are imported into CSO before the policy is deployed.
If you have not installed the certificates referenced in the SSL proxy profile, then they are automatically installed when the SSL proxy policy is deployed.
Note If you do not import the certificate, the traffic does not go through for clients in the LAN segments.