<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SSL Decryption for Outbound Traffic and the Block Private Key Export option in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ssl-decryption-for-outbound-traffic-and-the-block-private-key/m-p/572974#M2428</link>
    <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rmeddane_0-1705176333008.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56502i637394074A4E403E/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="rmeddane_0-1705176333008.png" alt="rmeddane_0-1705176333008.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The firewall uses a certificate with the role of CA Certificate of Authority to perform SSL Decryption for outbound traffic.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There are three methods to generate this certificate.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;STRONG&gt;Method 1&amp;nbsp;:&lt;/STRONG&gt; You can use a self-signed certificate. The firewall will generate a Certificate with the Public / Private keys automatically without involving an external CA.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL start="2"&gt;
&lt;LI&gt;&lt;STRONG&gt;Method 2&amp;nbsp;:&lt;/STRONG&gt; Using an external CA. The firewall generates a CSR Certificate Signed Request with the Public/Private keys, then you submit only the CSR / Public key, while the Private key is kept on the firewall, finally you upload the generate certificate with the embedded Public key.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL start="3"&gt;
&lt;LI&gt;&lt;STRONG&gt;Method 3&amp;nbsp;:&lt;/STRONG&gt; Using an external CA. You generate the CSR or the certifcate with the Public / Private keys. Then you upload the Certificate with the Public / Private Key.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The &lt;STRONG&gt;«&amp;nbsp;Block Private Key Export&amp;nbsp;»&lt;/STRONG&gt; option on the firewall allows the administrators to prevent rogue admins to export the private key, keeping it security on the firewall.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Let’s see with which method does the &lt;STRONG&gt;«&amp;nbsp;Block Private Key Export&amp;nbsp;»&lt;/STRONG&gt; work ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Method 1&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Generate a Self Signed Certificate, to be able to perform SSL Decryption for outbound traffic, check the &lt;STRONG&gt;Certificate Authority&lt;/STRONG&gt; option.&lt;/P&gt;
&lt;P&gt;To prevent the private key to be exported, check the &lt;STRONG&gt;Block Private Key Export&lt;/STRONG&gt; option.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rmeddane_1-1705176333011.jpeg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56500i9D45E0EA0E6310ED/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="rmeddane_1-1705176333011.jpeg" alt="rmeddane_1-1705176333011.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The self signed certificate is generated automatically.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rmeddane_2-1705176333013.jpeg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56501iFCD695730855F604/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="rmeddane_2-1705176333013.jpeg" alt="rmeddane_2-1705176333013.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Select the certificate and click on the &lt;STRONG&gt;Export Certficate&lt;/STRONG&gt; button.&lt;/P&gt;
&lt;P&gt;The firewall does not include the option to export the private key because the &lt;STRONG&gt;Block Private Key Export&lt;/STRONG&gt; option is enabled.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rmeddane_3-1705176333018.jpeg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56504i74E518C976A27A12/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="rmeddane_3-1705176333018.jpeg" alt="rmeddane_3-1705176333018.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Method 2&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Generate a Certificate Signing Request CSR using the option &lt;STRONG&gt;Signed by External Autthority (CSR) &lt;/STRONG&gt;and check the&lt;STRONG&gt; Block Private Key Export &lt;/STRONG&gt;option.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The CSR contains only the Public key, the Private key is kept in the firewall.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rmeddane_4-1705176333023.jpeg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56505i8D56265856AC2143/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="rmeddane_4-1705176333023.jpeg" alt="rmeddane_4-1705176333023.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The CSR is in the state of pending, waiting to submit it into an external CA.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Click the &lt;STRONG&gt;Export Certificate&lt;/STRONG&gt; button to export the CSR.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rmeddane_5-1705176333024.jpeg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56503iECCD0F4D966AB9A1/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="rmeddane_5-1705176333024.jpeg" alt="rmeddane_5-1705176333024.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rmeddane_6-1705176333027.jpeg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56506i22009DEEBA58EF3B/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="rmeddane_6-1705176333027.jpeg" alt="rmeddane_6-1705176333027.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Access the CA-1 server, and submit the CSR, you need to select the Certificate Template &lt;STRONG&gt;Subordinate Certificate Authority&lt;/STRONG&gt; to make this certificate as a CA so that the firewall can use it to sign the spoofed server certificate.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rmeddane_7-1705176333032.jpeg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56507iA4BD53FB75FB3E00/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="rmeddane_7-1705176333032.jpeg" alt="rmeddane_7-1705176333032.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Retrieve the generated certificate from the CA-1 server and click on the &lt;STRONG&gt;Import&lt;/STRONG&gt; button. In this scenario, the private key is kept the firewall so you dont need to use the Import Private Key option.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rmeddane_8-1705176333038.jpeg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56508i5115D288BEC1F66C/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="rmeddane_8-1705176333038.jpeg" alt="rmeddane_8-1705176333038.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Notice the icon below that indicates that the&amp;nbsp;private key cannot be exported.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rmeddane_9-1705176333040.jpeg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56509iF245A94CF7E212ED/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="rmeddane_9-1705176333040.jpeg" alt="rmeddane_9-1705176333040.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But when you try to export the certificate, the firewall displays the option to export the Private key which confirms that the &lt;STRONG&gt;Block Private Key Export&lt;/STRONG&gt; option didnt work with this method.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rmeddane_10-1705176333045.jpeg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56510iAD98D2FFA441D931/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="rmeddane_10-1705176333045.jpeg" alt="rmeddane_10-1705176333045.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Method 3&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Access the CA-2 server command line, generate a certificate with the role CA. The CA-2 server generates the certificate including the public key and the Private key. With this method, you need to import both the certificate and the Private key into the firewall.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rmeddane_11-1705176333048.jpeg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56511iE42D2A86169712AB/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="rmeddane_11-1705176333048.jpeg" alt="rmeddane_11-1705176333048.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Retrieves the Certifcate and the Private key as shown below.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rmeddane_12-1705176333048.jpeg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56512i1D7873860CBC0B3C/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="rmeddane_12-1705176333048.jpeg" alt="rmeddane_12-1705176333048.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On the firewall, click the &lt;STRONG&gt;Import&lt;/STRONG&gt; button, locate the Certificate and the Private key files.&lt;/P&gt;
&lt;P&gt;Check the &lt;STRONG&gt;Block Private Key Export&lt;/STRONG&gt; option.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rmeddane_13-1705176333051.jpeg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56513iD6A19899DBEB1E36/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="rmeddane_13-1705176333051.jpeg" alt="rmeddane_13-1705176333051.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Notice the icon below that indicates that the&amp;nbsp;private key cannot be exported. Click the &lt;STRONG&gt;Export&lt;/STRONG&gt; &lt;STRONG&gt;Certifcate&lt;/STRONG&gt; button.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rmeddane_14-1705176333058.jpeg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56514iEF3964CEBC9698A5/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="rmeddane_14-1705176333058.jpeg" alt="rmeddane_14-1705176333058.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Notice that the firewall does not allow to export the Private key because &lt;STRONG&gt;the Block Private Key Export&lt;/STRONG&gt; enabled.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rmeddane_15-1705176333062.jpeg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56515i74B2EC092FB86282/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="rmeddane_15-1705176333062.jpeg" alt="rmeddane_15-1705176333062.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sat, 13 Jan 2024 20:08:22 GMT</pubDate>
    <dc:creator>rmeddane</dc:creator>
    <dc:date>2024-01-13T20:08:22Z</dc:date>
    <item>
      <title>SSL Decryption for Outbound Traffic and the Block Private Key Export option</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ssl-decryption-for-outbound-traffic-and-the-block-private-key/m-p/572974#M2428</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rmeddane_0-1705176333008.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56502i637394074A4E403E/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="rmeddane_0-1705176333008.png" alt="rmeddane_0-1705176333008.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The firewall uses a certificate with the role of CA Certificate of Authority to perform SSL Decryption for outbound traffic.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There are three methods to generate this certificate.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;STRONG&gt;Method 1&amp;nbsp;:&lt;/STRONG&gt; You can use a self-signed certificate. The firewall will generate a Certificate with the Public / Private keys automatically without involving an external CA.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL start="2"&gt;
&lt;LI&gt;&lt;STRONG&gt;Method 2&amp;nbsp;:&lt;/STRONG&gt; Using an external CA. The firewall generates a CSR Certificate Signed Request with the Public/Private keys, then you submit only the CSR / Public key, while the Private key is kept on the firewall, finally you upload the generate certificate with the embedded Public key.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL start="3"&gt;
&lt;LI&gt;&lt;STRONG&gt;Method 3&amp;nbsp;:&lt;/STRONG&gt; Using an external CA. You generate the CSR or the certifcate with the Public / Private keys. Then you upload the Certificate with the Public / Private Key.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The &lt;STRONG&gt;«&amp;nbsp;Block Private Key Export&amp;nbsp;»&lt;/STRONG&gt; option on the firewall allows the administrators to prevent rogue admins to export the private key, keeping it security on the firewall.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Let’s see with which method does the &lt;STRONG&gt;«&amp;nbsp;Block Private Key Export&amp;nbsp;»&lt;/STRONG&gt; work ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Method 1&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Generate a Self Signed Certificate, to be able to perform SSL Decryption for outbound traffic, check the &lt;STRONG&gt;Certificate Authority&lt;/STRONG&gt; option.&lt;/P&gt;
&lt;P&gt;To prevent the private key to be exported, check the &lt;STRONG&gt;Block Private Key Export&lt;/STRONG&gt; option.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rmeddane_1-1705176333011.jpeg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56500i9D45E0EA0E6310ED/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="rmeddane_1-1705176333011.jpeg" alt="rmeddane_1-1705176333011.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The self signed certificate is generated automatically.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rmeddane_2-1705176333013.jpeg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56501iFCD695730855F604/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="rmeddane_2-1705176333013.jpeg" alt="rmeddane_2-1705176333013.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Select the certificate and click on the &lt;STRONG&gt;Export Certficate&lt;/STRONG&gt; button.&lt;/P&gt;
&lt;P&gt;The firewall does not include the option to export the private key because the &lt;STRONG&gt;Block Private Key Export&lt;/STRONG&gt; option is enabled.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rmeddane_3-1705176333018.jpeg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56504i74E518C976A27A12/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="rmeddane_3-1705176333018.jpeg" alt="rmeddane_3-1705176333018.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Method 2&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Generate a Certificate Signing Request CSR using the option &lt;STRONG&gt;Signed by External Autthority (CSR) &lt;/STRONG&gt;and check the&lt;STRONG&gt; Block Private Key Export &lt;/STRONG&gt;option.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The CSR contains only the Public key, the Private key is kept in the firewall.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rmeddane_4-1705176333023.jpeg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56505i8D56265856AC2143/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="rmeddane_4-1705176333023.jpeg" alt="rmeddane_4-1705176333023.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The CSR is in the state of pending, waiting to submit it into an external CA.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Click the &lt;STRONG&gt;Export Certificate&lt;/STRONG&gt; button to export the CSR.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rmeddane_5-1705176333024.jpeg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56503iECCD0F4D966AB9A1/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="rmeddane_5-1705176333024.jpeg" alt="rmeddane_5-1705176333024.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rmeddane_6-1705176333027.jpeg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56506i22009DEEBA58EF3B/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="rmeddane_6-1705176333027.jpeg" alt="rmeddane_6-1705176333027.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Access the CA-1 server, and submit the CSR, you need to select the Certificate Template &lt;STRONG&gt;Subordinate Certificate Authority&lt;/STRONG&gt; to make this certificate as a CA so that the firewall can use it to sign the spoofed server certificate.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rmeddane_7-1705176333032.jpeg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56507iA4BD53FB75FB3E00/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="rmeddane_7-1705176333032.jpeg" alt="rmeddane_7-1705176333032.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Retrieve the generated certificate from the CA-1 server and click on the &lt;STRONG&gt;Import&lt;/STRONG&gt; button. In this scenario, the private key is kept the firewall so you dont need to use the Import Private Key option.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rmeddane_8-1705176333038.jpeg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56508i5115D288BEC1F66C/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="rmeddane_8-1705176333038.jpeg" alt="rmeddane_8-1705176333038.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Notice the icon below that indicates that the&amp;nbsp;private key cannot be exported.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rmeddane_9-1705176333040.jpeg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56509iF245A94CF7E212ED/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="rmeddane_9-1705176333040.jpeg" alt="rmeddane_9-1705176333040.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But when you try to export the certificate, the firewall displays the option to export the Private key which confirms that the &lt;STRONG&gt;Block Private Key Export&lt;/STRONG&gt; option didnt work with this method.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rmeddane_10-1705176333045.jpeg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56510iAD98D2FFA441D931/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="rmeddane_10-1705176333045.jpeg" alt="rmeddane_10-1705176333045.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Method 3&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Access the CA-2 server command line, generate a certificate with the role CA. The CA-2 server generates the certificate including the public key and the Private key. With this method, you need to import both the certificate and the Private key into the firewall.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rmeddane_11-1705176333048.jpeg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56511iE42D2A86169712AB/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="rmeddane_11-1705176333048.jpeg" alt="rmeddane_11-1705176333048.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Retrieves the Certifcate and the Private key as shown below.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rmeddane_12-1705176333048.jpeg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56512i1D7873860CBC0B3C/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="rmeddane_12-1705176333048.jpeg" alt="rmeddane_12-1705176333048.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On the firewall, click the &lt;STRONG&gt;Import&lt;/STRONG&gt; button, locate the Certificate and the Private key files.&lt;/P&gt;
&lt;P&gt;Check the &lt;STRONG&gt;Block Private Key Export&lt;/STRONG&gt; option.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rmeddane_13-1705176333051.jpeg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56513iD6A19899DBEB1E36/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="rmeddane_13-1705176333051.jpeg" alt="rmeddane_13-1705176333051.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Notice the icon below that indicates that the&amp;nbsp;private key cannot be exported. Click the &lt;STRONG&gt;Export&lt;/STRONG&gt; &lt;STRONG&gt;Certifcate&lt;/STRONG&gt; button.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rmeddane_14-1705176333058.jpeg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56514iEF3964CEBC9698A5/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="rmeddane_14-1705176333058.jpeg" alt="rmeddane_14-1705176333058.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Notice that the firewall does not allow to export the Private key because &lt;STRONG&gt;the Block Private Key Export&lt;/STRONG&gt; enabled.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rmeddane_15-1705176333062.jpeg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56515i74B2EC092FB86282/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="rmeddane_15-1705176333062.jpeg" alt="rmeddane_15-1705176333062.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 13 Jan 2024 20:08:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/ssl-decryption-for-outbound-traffic-and-the-block-private-key/m-p/572974#M2428</guid>
      <dc:creator>rmeddane</dc:creator>
      <dc:date>2024-01-13T20:08:22Z</dc:date>
    </item>
  </channel>
</rss>

