cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Who rated this post

L1 Bithead

Not sure what happened to my last post, it hasn't come up (maybe because I included a certificate code) but I believe I found a quick solution.

 

Essentially I discovered my clients were hitting Anydesk relay sites of relay-xxxxxxx.net.anydesk.com (ie: relay-dbb2d168.net.anydesk.com). I used https://www.ssllabs.com/ssltest/index.html to check the above URL to see what certificates it was using and it's using INTERNALLY created certificates (WTF). No wonder why the PAs are denying it entirely!

 

NOTE: you cannot see its certificates jsut by browsing to the URL as it has an auto-forward to the Anydesk main site.

 

certificatesfound.png

 

The ssllabs site lets you download the certificates it discovers, you then need to import them into your PA and mark the AnyNet Root CA as a trusted Root CA and then it will work.

 

Annotation 2020-07-06 175218.png

 

I also added *.net.anydesk.com as a decryption exception.

Who rated this post