<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can't define Forward Trust certificate in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/can-t-define-forward-trust-certificate/m-p/551330#M1593</link>
    <description>&lt;P&gt;open the certificate with a notepad, you may have to only keep the actual cert.&lt;/P&gt;</description>
    <pubDate>Thu, 27 Jul 2023 11:29:51 GMT</pubDate>
    <dc:creator>ozheng</dc:creator>
    <dc:date>2023-07-27T11:29:51Z</dc:date>
    <item>
      <title>Can't define Forward Trust certificate</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/can-t-define-forward-trust-certificate/m-p/551309#M1589</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have a new firewall, PA-460 model. The panos version is 10.2.4-h2.&lt;/P&gt;
&lt;P&gt;I have a problem for define the Forward Trust certificate for the decryption.&lt;/P&gt;
&lt;P&gt;The certificate i want to declare for Forward trust is a root certificate of our domain.&lt;/P&gt;
&lt;P&gt;I import the certificate with is private key in pkcs12.&lt;/P&gt;
&lt;P&gt;When i check the case "Forward Trust&amp;nbsp; Certificate" or "Trusted Root CA", i can validate the commit but when i push the commit, i have this error :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Partial changes to commit: changes to configuration by administrators: admin&lt;BR /&gt;Changes to shared configuration&lt;BR /&gt;Error: Certificate failed to load: invalid certificate chain&lt;BR /&gt;Error preparing global objects&lt;BR /&gt;failed to handle CONFIG_UPDATE_START&lt;BR /&gt;(Module: device)&lt;BR /&gt;client device phase 1 failure&lt;BR /&gt;Commit failed&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;i have a vm for test, and the problem is the same, i tried to import the certificate in pem, and update to panos 10.2.4-h3 but same error.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Someone have an idea to fix this problem ?&lt;/P&gt;
&lt;P&gt;I can't active decryption for now.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2023 10:20:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/can-t-define-forward-trust-certificate/m-p/551309#M1589</guid>
      <dc:creator>CHARRIER</dc:creator>
      <dc:date>2023-07-27T10:20:58Z</dc:date>
    </item>
    <item>
      <title>Re: Can't define Forward Trust certificate</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/can-t-define-forward-trust-certificate/m-p/551327#M1590</link>
      <description>&lt;P&gt;Hello Charrier,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Have you tried to reimport the certificate in PEM format?&lt;/P&gt;
&lt;P&gt;You need to play with openssl to convert it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Olivier&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2023 11:20:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/can-t-define-forward-trust-certificate/m-p/551327#M1590</guid>
      <dc:creator>ozheng</dc:creator>
      <dc:date>2023-07-27T11:20:51Z</dc:date>
    </item>
    <item>
      <title>Re: Can't define Forward Trust certificate</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/can-t-define-forward-trust-certificate/m-p/551328#M1591</link>
      <description>&lt;P&gt;Yes i tried, i convert the certificate pkcs12 in 2 pem file, one with certificate, and one with key and reimport it. but same error.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2023 11:26:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/can-t-define-forward-trust-certificate/m-p/551328#M1591</guid>
      <dc:creator>CHARRIER</dc:creator>
      <dc:date>2023-07-27T11:26:25Z</dc:date>
    </item>
    <item>
      <title>Re: Can't define Forward Trust certificate</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/can-t-define-forward-trust-certificate/m-p/551330#M1593</link>
      <description>&lt;P&gt;open the certificate with a notepad, you may have to only keep the actual cert.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2023 11:29:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/can-t-define-forward-trust-certificate/m-p/551330#M1593</guid>
      <dc:creator>ozheng</dc:creator>
      <dc:date>2023-07-27T11:29:51Z</dc:date>
    </item>
    <item>
      <title>Re: Can't define Forward Trust certificate</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/can-t-define-forward-trust-certificate/m-p/551338#M1594</link>
      <description>&lt;P&gt;Thanks for the advice, I open the pem file in notepad, and i saw 2 certificate in this file.&lt;/P&gt;
&lt;P&gt;When i import this file in palo, his show me only 1 certificate but 2 was in the file, that's why i have the invalid certification chain.&lt;/P&gt;
&lt;P&gt;When i export the root ca since the certification authority, this export 2 root ca certificate.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I split the file in 2 pem file, make the same things for the keys.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Then i see the difference when i upload in the palo. 2 differents expires date.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Then i can declare one Forward Trust Certificate and active decryption.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2023 13:10:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/can-t-define-forward-trust-certificate/m-p/551338#M1594</guid>
      <dc:creator>CHARRIER</dc:creator>
      <dc:date>2023-07-27T13:10:46Z</dc:date>
    </item>
    <item>
      <title>Re: Can't define Forward Trust certificate</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/can-t-define-forward-trust-certificate/m-p/551403#M1597</link>
      <description>&lt;P&gt;Hello Charrier,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Good your issue is resolved.&lt;/P&gt;
&lt;P&gt;If you have some time, I invite you to read/listen the &lt;A href="https://live.paloaltonetworks.com/t5/pancast/pancast-episode-9-should-you-have-ssl-decryption-enabled/ta-p/526755" target="_self"&gt;PANCast Episode 9&lt;/A&gt; about SSL Decryption.&lt;/P&gt;
&lt;P&gt;Maybe it can help you to complete your setup too.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Olivier&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2023 16:27:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/can-t-define-forward-trust-certificate/m-p/551403#M1597</guid>
      <dc:creator>ozheng</dc:creator>
      <dc:date>2023-07-27T16:27:05Z</dc:date>
    </item>
  </channel>
</rss>

