I am in the planning phase for rolling out DPI-SSL on our SonicWall. I have found two conflicting suggestions on creating a custom DPI-SSL certificate and am having trouble identifying any pros/cons to each approach.

Method #1: This can be seen at 18:00 mark in this video https://youtu.be/ZxwhpHh7Los?t=1080

What is suggested is basically to export the root AD CA certificate, and then use that as the SonicWall DPI-SSL certificate.

Method # 2: https://www.sonicwall.com/support/knowledge-base/170503319041199/

Summary: Import AD CA certificate as trusted CA on SonicWall. Create CSR on SonicWall and have AD CA sign the certificate. Assign this for use with DPI-SSL.

Are there any major benefits/downsides to one or the other?

7 Spice ups

Both ways are valid. I would use the one from AD if you have it, otherwise import CA and create a new SSL if using another type of environment and SSL Cert.

I just wanted to update this with SonicWall support’s response:
" Certificate for which CSR is generated on SW (Local cert) and CA certificate, bith can be used for DPI-SSL. CA cert is more secure than local cert. "