Skip to content
Avanet

Deploy the Sophos DNS Protection Root Certificate

The DNS Protection Root Certificate allows users to see the HTTPS block page for a domain blocked by DNS Protection. Download the certificate from Sophos Fusion and install it as a trusted root certificate on the affected devices. This is the certificate for DNS Protection block pages, not the Sophos Firewall CA for TLS Inspection.

Requirements, license, and roles

The following requirements must be met before installation:

  • You can access My Products > DNS Protection > Installers in your Sophos Fusion tenant.
  • The certificate is installed on the devices where users need to see block pages.
  • An Active Directory Group Policy is available for centralized Windows deployment. Alternatively, you can install the certificate on individual Windows devices.
  • Keychain Access is available on macOS.
  • If you use Firefox, you must also take its separate certificate store into account.

Sophos doesn’t document a specific license tier or special administrator role for this procedure. If the DNS Protection menu item is missing, clarify the product entitlement and your access rights before proceeding with a file from another source.

Download the certificate

  1. In Sophos Fusion, open My Products > DNS Protection > Installers.
  2. Under Configure block pages, click Certificate.
  3. Download the DNS Protection Root Certificate.

The Installers page also provides IP addresses with a Copy action. These values are for DNS server configuration; the certificate installation described here uses only Certificate.

Choose a Windows deployment method and verify the installation

You can deploy the certificate to multiple Windows devices through Active Directory Group Policy. You can install it locally on a single computer. Sophos identifies these two deployment methods but doesn’t provide a complete Windows or GPO click path here. For the actual import, follow your organization’s established Windows or GPO procedure and install the certificate in the local computer’s certificate store.

After installation, open certlm.msc and go to Trusted Root Certification Authorities > Certificates. The certificate must be in the local computer store. Importing it only into a user’s certificate store doesn’t provide the same scope and may cause other users to continue seeing a certificate warning.

Install on macOS

  1. Import the downloaded certificate into a keychain using Keychain Access.
  2. Under Keychain Access > System > Certificates, open the installed certificate.
  3. Expand Trust and select Always Trust.

The System keychain is important when trust must apply to the device rather than to a single user.

Configure Firefox separately

Firefox requires the certificate to be added separately as a trusted root certificate or certificate authority, independently of the operating system. Don’t skip this step after installing the certificate on Windows or macOS.

Validation and expected result

Validation consists of two clearly separate steps:

  1. Under My Products > DNS Protection > Installers, click Copy next to URL, then open the copied URL in a browser. If the welcome message appears, the basic DNS Protection configuration is correct.
  2. Then, on a designated test device, open a domain that the active DNS Protection policy blocks. The expected result is the Sophos block page without a certificate warning.

The welcome message alone doesn’t confirm that the root certificate is in the correct store. Only the block page appearing without a warning validates the certificate path for the browser in use.

Troubleshoot by symptom

The block page appears with a certificate warning

First, check whether the DNS Protection Root Certificate is actually installed in the intended store:

  • Windows: certlm.msc under Trusted Root Certification Authorities > Certificates.
  • macOS: Keychain Access > System > Certificates, with Trust > Always Trust set for the certificate.
  • Firefox: A separate certificate entry is present and configured as trusted.

If the certificate is in the user store rather than the device store, trust may not apply to the user or browser being tested. Reinstall the certificate using the intended device deployment method instead of bypassing the browser warning.

The welcome page works, but the block page doesn’t appear

If the original website appears instead of the block page, first make sure the firewall uses DNS Protection for name resolution. In Web Proxy Mode, Pharming Protection can also prevent redirection to the block page.

Sophos specifies the following procedure for a targeted exception:

  1. Create an FQDN object for blockpage.dnsprotection.sophos.com.
  2. Create a firewall rule for HTTP and HTTPS from the affected internal zones and networks to the WAN zone. Use the FQDN object as the destination, select Allow, and don’t enable a web filtering option.
  3. Using the same selection criteria, create a TLS rule for the block page connection and select Do not decrypt.
  4. Open the blocked test domain again.

Keep the exception narrowly restricted to the block page service. If this change isn’t possible or hasn’t been approved, escalate it to the responsible firewall administrator; don’t disable TLS decryption or web filtering globally.

Safe rollback or offboarding

Sophos doesn’t document a general removal procedure for the DNS Protection Root Certificate. Therefore, don’t delete the certificate from production devices based on its display name, and don’t use an unverified removal command.

If you must reverse the deployment, first record how the certificate was deployed and which devices are affected. Then plan the rollback through the responsible Group Policy, device management platform, or local administrator, and retest both the welcome page and a block page after the change. Without a confirmed removal procedure, don’t continue with the rollback; involve your platform team or Sophos Support instead.

Operations, review, and lifecycle

For new devices and whenever the certificate changes, always use the current download from My Products > DNS Protection > Installers. After each deployment, test the welcome message on a single test device first, followed by the block page. Sophos doesn’t specify a fixed rotation interval or a general expiration or removal procedure. Don’t make assumptions about these details; verify them against the current Sophos help and your device management platform.

Distinction from DNS configuration and TLS Inspection

DNS server configuration, Filtering Policies, and specific firewall rules remain separate tasks. This article covers only downloading, trusting, and validating the DNS Protection Root Certificate, along with the closely related block page issue. This maintains the distinction between DNS Protection certificate management and the CA used for Sophos Firewall TLS Inspection.