<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Certificates on Palo alto - Types to be installed in VM-Series in the Public Cloud</title>
    <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/certificates-on-palo-alto-types-to-be-installed/m-p/568217#M2057</link>
    <description>&lt;P&gt;you don't need the second ssl certificate as that is only required for outbound proxy inspection (and it needs to be from an internal PKI or selfsigned instead of a public one)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;for inbound inspection, you need to have the server certificate (and preferably the CA/root and intermediate, to complete the certificate path)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;you can use the server certificate on the firewall (WITH private key) to look inside the flow&lt;/P&gt;</description>
    <pubDate>Mon, 04 Dec 2023 14:07:32 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2023-12-04T14:07:32Z</dc:date>
    <item>
      <title>Certificates on Palo alto - Types to be installed</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/certificates-on-palo-alto-types-to-be-installed/m-p/568141#M2054</link>
      <description>&lt;P&gt;Dear memebers,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We are going to use palo alto vm series firewall on Azure and like to take your advice on the type of certificates to be installed. The firewalls will be public facing front end by Azure application gateway.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The FW will be protecting a web site running on the background.&amp;nbsp; If my understanding is correct, I need 2 types of certificates.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;One from&amp;nbsp;Certificates from a trusted third-party CA (Go dady/Verisign) - This is for web site&lt;/LI&gt;
&lt;LI&gt;Obtain a Certificate from an External CA - This will be from Palo alto itself for&amp;nbsp; SSL/TLS decryption&amp;nbsp;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;plz advice if my understanding is correct.&lt;/P&gt;</description>
      <pubDate>Sun, 03 Dec 2023 09:07:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/certificates-on-palo-alto-types-to-be-installed/m-p/568141#M2054</guid>
      <dc:creator>N-Open</dc:creator>
      <dc:date>2023-12-03T09:07:28Z</dc:date>
    </item>
    <item>
      <title>Re: Certificates on Palo alto - Types to be installed</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/certificates-on-palo-alto-types-to-be-installed/m-p/568217#M2057</link>
      <description>&lt;P&gt;you don't need the second ssl certificate as that is only required for outbound proxy inspection (and it needs to be from an internal PKI or selfsigned instead of a public one)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;for inbound inspection, you need to have the server certificate (and preferably the CA/root and intermediate, to complete the certificate path)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;you can use the server certificate on the firewall (WITH private key) to look inside the flow&lt;/P&gt;</description>
      <pubDate>Mon, 04 Dec 2023 14:07:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/certificates-on-palo-alto-types-to-be-installed/m-p/568217#M2057</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2023-12-04T14:07:32Z</dc:date>
    </item>
  </channel>
</rss>

