---
title: "Office 365 trust chain"
canonical: "https://docs.aryaka.com/space/KNOW/1269792861/Office%20365%20trust%20chain"
format: markdown
---
This document describes the steps that you need to perform to optimize SSL traffic to third-party cloud services like Microsoft Office 365. The deployment requires that your clients send SSL requests through the Aryaka Cloud and the nearest Aryaka POP serves these requests and intercepts the SSL handshake. This SSL negotiation is done using Aryaka’s private certificates. Aryaka’s solution minimizes configuration on client devices to make the solution work instead of extensive configuration of on-premise appliances or third-party services to make the solution work, which significantly reduces the burden to your organization. High level workflow The following events must occur after Aryaka turns on the services that allow customer traffic to traverse the network: Aryaka support personnel sends you the root CA file. You install and trust this root CA file to the client machines. You test your access to Office 365 applications. If you attempt to access the customer website without installing the Aryaka CA certificate, the following warning appears in your browser: The following warning appears when an Outlook client is used for access: This error indicates that the CA used to sign the certificate presented by the server is not known and trusted by the client. Installing the root certificate To prevent the trust errors from appearing, the client computers must have the Aryaka root CA installed and marked as trusted. There are two ways to do this: Using GPOs to propagate the trusted root certificate to all windows clients. Having users manually install the certificate on their computers. Using GPO to distribute the root certificate If the customer network has multiple Windows computers, it is recommended that the Aryaka root  certificate be distributed to them using GPO. This method ensures that all Windows clients using Chrome, Internet Explorer, or Outlook get the trusted root certificate and the clients function without seeing any certificate-related errors or warnings. This method is not supported if the client is a Firefox browser. You must manually install the certificate as described later in this topic. To configure the GPO Launch the Group Policy Manager and navigate to the suitable object. It is recommended that a new Domain Policy is configured so as to keep the configuration modular and easy to manage. In the Group Policy Object editor, navigate to  Computer Configuration  >  Windows Settings  >  Security Settings  >  Public Key Policies  >  Trusted Root Certification Authorities , then right-click and select  Import . Locate the certificate sent to you by Aryaka Support and import it. Inform users that they must do one of the following to get the new GPO to take effect: Run the  gdupdate /force  command from a terminal window command line. Log out and log back in. Installing the certificate manually If the customer network does not use GPO, or if the clients are using applications like Firefox that have custom configuration, users must install the certificate manually. To manually install the certificate on Windows 7 and IE 7/8/9 or Chrome Download the CA’s certificate and save it to your desktop. Ensure that the file extension is .crt. If necessary, rename the file to .crt. A certificate icon appears on your desktop. Double-click the certificate icon, select  Install Certificate , and then click  Next . Select  Place all certificates in the following store , click  Browse , select  Trusted Root Certificate Authorities , and then click  OK . Click  Next . Click  Finish . Select  Yes  to confirm that you want to install the certificate. A dialog confirms that the certificate was installed successfully. Close the certificate. To manually install the certificate on Windows 7 and Firefox 7 Download the CA’s certificate and save it to your desktop. Launch Firefox Go to  Tools  (or press Alt+T) >  Options  >  Advanced  >  Encryption  >  View Certificates  >  Authorities  >  Import . Click all three  Trusts this CA…  checkboxes.  Click  OK . To manually install the certificate on Mac OS X and Safari/Chrome Download the CA’s certificate and save it to your desktop. Ensure that the file extension is .crt. If necessary, rename the file to .crt. A certificate icon appears on your desktop. Double-click on the icon and enter the system password when prompted. The certificate opens in the Keychain Access application: Double-click the certificate and select the  Always Trust  option: To manually install the certificate on Mac OS X and Firefox Firefox does not use Keychain so you must add the CA to its security vault. Download the certificate to your Mac. Open Firefox, then navigate to  References  >  Advanced  >  Encryption  >  View Certificates . Click  Import  and select the downloaded certificate. The Certificate Manager appears: Click  OK . Aryaka Networks Inc appears in the CA List. Use your client to navigate to the service that uses Aryaka. The selected service opens and the SSL warning does  not  appear. In this topic Related topics Generate Office 365 certificates Manage static certificates Add static certificates Converting certificate file formats