- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
07-06-2020 04:23 AM
Not sure what happened to my last post, it hasn't come up (maybe because I included a certificate code) but I believe I found a quick solution.
Essentially I discovered my clients were hitting Anydesk relay sites of relay-xxxxxxx.net.anydesk.com (ie: relay-dbb2d168.net.anydesk.com). I used https://www.ssllabs.com/ssltest/index.html to check the above URL to see what certificates it was using and it's using INTERNALLY created certificates (WTF). No wonder why the PAs are denying it entirely!
NOTE: you cannot see its certificates jsut by browsing to the URL as it has an auto-forward to the Anydesk main site.
The ssllabs site lets you download the certificates it discovers, you then need to import them into your PA and mark the AnyNet Root CA as a trusted Root CA and then it will work.
I also added *.net.anydesk.com as a decryption exception.