The list of following domains need to be whitelisted in the enterprise network as they are the endpoints for downloading SSL certificates :-
- *.symantec.com
- *.thawte.com
- *.geotrust.com
- *.omniroot.com
- *.verisign.com
- *.globalsign.com
- *.godaddy.com
- *.ctldl.windowsupdate.com
- *.symcd.com
- *.symcb.com
If these domains are not accessible the user would have to uncheck
"Check for server certificate revocation" in Advanced section of Internet Options.