<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Decryption: Received fatal alert CertificateUnknown from client in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/decryption-received-fatal-alert-certificateunknown-from-client/m-p/578517#M2722</link>
    <description>&lt;P&gt;Hi Satyak,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regrettably, as I go over the decryption logs again today, I'm still seeing instances of my original issue. For example, here's the error in the decryption log (I should note that the source IP address from this entry is assigned to one of our corporate laptops, and thus trusts the forward-trust certificate):&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="error.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/57876iFF628BEE51AAD81F/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="error.png" alt="error.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;If I go to the indicated URL (&lt;A href="http://r3.iencr.org/" target="_blank"&gt;http://r3.iencr.org/&lt;/A&gt;) and download the certificate, and take a look at the certification path, I see this:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="path.png" style="width: 598px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/57877iC223C59966DC9808/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="path.png" alt="path.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;If I take a look in the FW's certificate store, I see this:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="cert store.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/57878i0249063BC33796AB/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="cert store.png" alt="cert store.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So given these facts, how is it still possible to generate the 'CertificateUnknown' error? Thanks for your thoughts! Just to clarify, this is forward proxy decryption, and not GP or inbound...&lt;/P&gt;</description>
    <pubDate>Tue, 27 Feb 2024 17:16:33 GMT</pubDate>
    <dc:creator>LCMember40912</dc:creator>
    <dc:date>2024-02-27T17:16:33Z</dc:date>
    <item>
      <title>Decryption: Received fatal alert CertificateUnknown from client</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/decryption-received-fatal-alert-certificateunknown-from-client/m-p/577547#M2668</link>
      <description>&lt;P&gt;Hi Folks,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm seeing some instances of "Received fatal alert CertificateUnknown from client" errors in the decryption log when the root\issuer certs are clearly in the FW's cert store. Attached are screenshots of the error and the FW's cert store. Any ideas on what could be going wrong here?&lt;/P&gt;
&lt;P&gt;I'm seeing this on PAN OS 11.0.2-h3 &amp;amp;&amp;nbsp;&lt;SPAN&gt;10.2.7-h3.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks for your thoughts!&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Feb 2024 19:24:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/decryption-received-fatal-alert-certificateunknown-from-client/m-p/577547#M2668</guid>
      <dc:creator>LCMember40912</dc:creator>
      <dc:date>2024-02-16T19:24:38Z</dc:date>
    </item>
    <item>
      <title>Re: Decryption: Received fatal alert CertificateUnknown from client</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/decryption-received-fatal-alert-certificateunknown-from-client/m-p/578240#M2695</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;LCMember40912,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The GP certificate which you are using is missing it's root certificate.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;This is the reason you are getting the error as the Client/Server it not able to trust the certificate.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;As a Workaround please find the below methods.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Please try to import the entire certificate chain given by GoDaddy into the firewall and then Try to add the Root Certificate in the GP Portal and Change the SSL/TLS version max to 1.2.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;This should help you in resolving the issue.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Regards&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Satya Kalyan&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 24 Feb 2024 08:20:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/decryption-received-fatal-alert-certificateunknown-from-client/m-p/578240#M2695</guid>
      <dc:creator>Satyak</dc:creator>
      <dc:date>2024-02-24T08:20:44Z</dc:date>
    </item>
    <item>
      <title>Re: Decryption: Received fatal alert CertificateUnknown from client</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/decryption-received-fatal-alert-certificateunknown-from-client/m-p/578272#M2699</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/51581"&gt;@LCMember40912&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Are you configuring SSL inbound decryption in the firewall&lt;/P&gt;</description>
      <pubDate>Sun, 25 Feb 2024 15:00:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/decryption-received-fatal-alert-certificateunknown-from-client/m-p/578272#M2699</guid>
      <dc:creator>tamilvanan</dc:creator>
      <dc:date>2024-02-25T15:00:00Z</dc:date>
    </item>
    <item>
      <title>Re: Decryption: Received fatal alert CertificateUnknown from client</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/decryption-received-fatal-alert-certificateunknown-from-client/m-p/578369#M2712</link>
      <description>&lt;P&gt;Hi Satya, you are quite correct. When I exported and opened the original cert in the screenshot, it was in fact only an intermediate cert. I was able to download the root and install it. Thanks for setting me straight! &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Ian&lt;/P&gt;</description>
      <pubDate>Mon, 26 Feb 2024 16:52:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/decryption-received-fatal-alert-certificateunknown-from-client/m-p/578369#M2712</guid>
      <dc:creator>LCMember40912</dc:creator>
      <dc:date>2024-02-26T16:52:41Z</dc:date>
    </item>
    <item>
      <title>Re: Decryption: Received fatal alert CertificateUnknown from client</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/decryption-received-fatal-alert-certificateunknown-from-client/m-p/578517#M2722</link>
      <description>&lt;P&gt;Hi Satyak,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regrettably, as I go over the decryption logs again today, I'm still seeing instances of my original issue. For example, here's the error in the decryption log (I should note that the source IP address from this entry is assigned to one of our corporate laptops, and thus trusts the forward-trust certificate):&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="error.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/57876iFF628BEE51AAD81F/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="error.png" alt="error.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;If I go to the indicated URL (&lt;A href="http://r3.iencr.org/" target="_blank"&gt;http://r3.iencr.org/&lt;/A&gt;) and download the certificate, and take a look at the certification path, I see this:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="path.png" style="width: 598px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/57877iC223C59966DC9808/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="path.png" alt="path.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;If I take a look in the FW's certificate store, I see this:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="cert store.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/57878i0249063BC33796AB/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="cert store.png" alt="cert store.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So given these facts, how is it still possible to generate the 'CertificateUnknown' error? Thanks for your thoughts! Just to clarify, this is forward proxy decryption, and not GP or inbound...&lt;/P&gt;</description>
      <pubDate>Tue, 27 Feb 2024 17:16:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/decryption-received-fatal-alert-certificateunknown-from-client/m-p/578517#M2722</guid>
      <dc:creator>LCMember40912</dc:creator>
      <dc:date>2024-02-27T17:16:33Z</dc:date>
    </item>
    <item>
      <title>Re: Decryption: Received fatal alert CertificateUnknown from client</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/decryption-received-fatal-alert-certificateunknown-from-client/m-p/578529#M2723</link>
      <description>&lt;P&gt;Is this running from an application on the clients machine or are they just web-browsing to this place? Generally in my experience client cert errors are most often a result of the application doing certificate pinning thus causing ssl inspection to stop this connection.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Feb 2024 18:16:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/decryption-received-fatal-alert-certificateunknown-from-client/m-p/578529#M2723</guid>
      <dc:creator>Claw4609</dc:creator>
      <dc:date>2024-02-27T18:16:30Z</dc:date>
    </item>
    <item>
      <title>Re: Decryption: Received fatal alert CertificateUnknown from client</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/decryption-received-fatal-alert-certificateunknown-from-client/m-p/578568#M2725</link>
      <description>&lt;P&gt;"&lt;SPAN&gt;Is this running from an application on the clients machine or are they just web-browsing to this place?"&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;You know, that's a good question. I don't really know anything apart from what I see in the decryp logs. Just trying to be proactive so people don't write helpdesk messages saying they can't get to this or that site... Is there a way to tell?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Feb 2024 21:43:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/decryption-received-fatal-alert-certificateunknown-from-client/m-p/578568#M2725</guid>
      <dc:creator>LCMember40912</dc:creator>
      <dc:date>2024-02-27T21:43:00Z</dc:date>
    </item>
    <item>
      <title>Re: Decryption: Received fatal alert CertificateUnknown from client</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/decryption-received-fatal-alert-certificateunknown-from-client/m-p/595285#M3605</link>
      <description>&lt;P&gt;FYI - Instructions on how to repair incomplete certificate chains:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/decryption/troubleshoot-and-monitor-decryption/decryption-logs/repair-incomplete-certificate-chains" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/decryption/troubleshoot-and-monitor-decryption/decryption-logs/repair-incomplete-certificate-chains&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Aug 2024 22:06:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/decryption-received-fatal-alert-certificateunknown-from-client/m-p/595285#M3605</guid>
      <dc:creator>William-Wu</dc:creator>
      <dc:date>2024-08-19T22:06:47Z</dc:date>
    </item>
    <item>
      <title>Re: Decryption: Received fatal alert CertificateUnknown from client</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/decryption-received-fatal-alert-certificateunknown-from-client/m-p/595913#M3634</link>
      <description>&lt;P&gt;I've had very similar issues.&lt;BR /&gt;If you trace it back to a corporate laptop, would it be possible that a Chromium based browser is used?&lt;/P&gt;
&lt;P&gt;Been issues where legitimate traffic doesn't work as intended if SSL decrypt is being used due to this:&lt;BR /&gt;&lt;A href="https://blog.chromium.org/2023/08/protecting-chrome-traffic-with-hybrid.html" target="_blank"&gt;https://blog.chromium.org/2023/08/protecting-chrome-traffic-with-hybrid.html&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://tldr.fail/" target="_blank"&gt;https://tldr.fail/&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;PAN have a bug fix being pushed&amp;nbsp;&lt;SPAN&gt;PAN-247099&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Aug 2024 08:44:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/decryption-received-fatal-alert-certificateunknown-from-client/m-p/595913#M3634</guid>
      <dc:creator>emkla123</dc:creator>
      <dc:date>2024-08-26T08:44:59Z</dc:date>
    </item>
  </channel>
</rss>

