DPI Certificate Not Available in the Browser
Symptom
The Deep Packet Inspection (DPI) certificate is not available in the web browser, even though DPI is enabled on the computer and no errors are reported.
Cause
This issue occurs when there are no Content Aware Policies (CAP) applied to the computer. The DPI certificate is only deployed and used if CAP policies are configured to monitor browsers or other applications controlled by DPI. For a full overview of DPI, including Stealthy vs. Regular DPI modes and known OS-specific limitations, see Deep Packet Inspection.
Resolution
- Open the Netwrix Endpoint Protector management console.
- In the left-side pane under Device Control, navigate to the Content Aware Protection section.
- Review and configure your Content Aware Policies (CAP) so that a policy applies to the affected computer and includes the browser as an Exit Point.
- Confirm the EPP Client installed correctly on the endpoint. See Agent Installation — on macOS, Deep Packet Inspection also requires the EPP Client to have Full Disk Access granted under System Preferences > Security & Privacy > Privacy.
- Visit a website in the affected browser. Endpoint Protector generates the DPI certificate the first time a monitored browser visits a site and caches it for later visits, so the certificate won't appear until a monitored transfer actually occurs.
The DPI certificate deploys automatically and transparently on Windows. On macOS and Linux, it requires manual installation. See Deep Packet Inspection Certificate for the OS-specific installation steps and the certificate status matrix used to diagnose availability and trust issues.
For detailed information and step-by-step instructions on configuring Content Aware Policies (CAP), refer to the following documentation: