Skip to main content

Apple macOS Setup

Describes Chrome DoH setup on macOS for POC/pilot using doh.surepath.ai/dns-query. Covers Chrome config, root CA, and bypass limits. Not for production; use PAC or SASE.

Overview

Admins should use this traffic redirection method only for trials, pilots, and limited deployments. In most cases, end users can bypass the security and governance that F5 SurePath AI provides with this method. For production deployments, customers should use a redirection method that resists bypass.

Devices accessing GenAI sites through SurePath AI must also install the SurePath AI security certificates. Installing certificates across many devices without automation or an MDM tool is an onerous task.

Prerequisites

  • SurePath AI Root Certificate (available from the organization's SurePath AI Field CTO)

  • DNS over HTTPS (DoH) address (in this document)

  • A web browser that supports DoH. This document uses Google Chrome to demonstrate the configuration.

Procedures

All Operating Systems and Browsers

All operating systems need these files and information.

  1. DoH server URL

  2. Configuration validation page

    1. This site also provides downloads of the SurePath AI security certificates for admins who do not already have them.

  3. Download certificates in different formats

Setup Chrome on Mac

  1. Select Chrome > Settings from the macOS menu bar, or click the three vertical dots next to the Google account icon on the right side of the Chrome menu bar

  2. From the left navigation bar select Privacy and security > Security

  3. Turn on Use secure DNS with the toggle

  4. Select Add custom DNS service provider from the drop down menu

  5. Enter the SurePath DoH server address into the field provided.

5. Leave this field, or the setting will not take effect.

Install the SurePath AI Security Certificate on Mac

  1. Locate the SurePath AI Root Certificate file, either downloaded directly or received separately.

  2. Right click on the file and select Open With > Keychain Access

  3. Enter the password or authenticate as required.

  4. Select the certificate. If it does not appear, search for SurePath AI in Keychain Access to locate and select it. The certificate shows This root certificate is not trusted.

5. Double-click the SurePath AI Root CA certificate (or right-click and select Get Info)

6. Expand and select Trust > When using this certificate > Always Trust

7. Close the window for the settings to take effect.

8. Setup is complete. Continue to configuration validation.

Configuration Validation

After completing interception with SASE software or a DoH setup, use the following website to confirm that GenAI traffic passes through the SurePath AI system.

  1. This webpage confirms whether the configuration is correct.

Did this answer your question?