Make coporate certificate valid for Twingate client (Ubuntu)

Hello guys. I’m sure it’s a know set up but I did not find info. I’m trying to deploy client in an Ubuntu VM on a corporate network and it’s detecting the proxy certificate as invalid.
“error trying to connect: invalid peer certificate contents: invalid peer certificate: UnknownIssuer”
I have this certificate added on /etc/ssl/certs/ca-certificates.crt, all other apps are working so maybe I’m missing an extra set up for twingate client.

Regards. -

Hi @paloncho06 - it may be that your ca-certificates is out of date - you can try to update them sudo apt-get install ca-certificates.

The other possibility here is that your corporate network may have SSL/TLS inspection going on and is trying to MITM the Twingate connections. We don’t support this and we recommend network admins to add exceptions to inspection for the Twingate client processes.

1 Like

Hello Emrul. Thanks for the data. We are indeed making SSL inspection, I just checked out perimeter firewall logs for Twingate flows and it’s happening.

Thanks for your support.
Regards. -

1 Like