<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Decryption failed in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/decryption-failed/m-p/591990#M3410</link>
    <description>&lt;P&gt;Hi guys ,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;PA820 . OS Version 10.2.9-h1&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am try using the decryption function to see more application information&lt;BR /&gt;I generated the CA certificate from PA and imported it locally.&lt;/P&gt;
&lt;P&gt;From the decryption log, I saw many errors with various URLs.&lt;BR /&gt;Can anyone help explain how to eliminate this?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;error eq 'Received fatal alert CertificateUnknown from client. CA Issuer URL (truncated):&lt;A href="http://cacerts.digicert.com/DigiCertGlobalG2TLSRSASHA2562020CA1" target="_blank" rel="noopener"&gt;http://cacerts.digicert.com/DigiCertGlobalG2TLSRSASHA2562020CA1&lt;/A&gt;' &lt;BR /&gt;URL: &lt;A href="http://aia.entrust.net/l1k-chain256.cer" target="_blank" rel="noopener"&gt;http://aia.entrust.net/l1k-chain256.cer&lt;/A&gt;'&lt;/P&gt;</description>
    <pubDate>Mon, 15 Jul 2024 08:58:33 GMT</pubDate>
    <dc:creator>HY_Cheng</dc:creator>
    <dc:date>2024-07-15T08:58:33Z</dc:date>
    <item>
      <title>Decryption failed</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/decryption-failed/m-p/591990#M3410</link>
      <description>&lt;P&gt;Hi guys ,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;PA820 . OS Version 10.2.9-h1&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am try using the decryption function to see more application information&lt;BR /&gt;I generated the CA certificate from PA and imported it locally.&lt;/P&gt;
&lt;P&gt;From the decryption log, I saw many errors with various URLs.&lt;BR /&gt;Can anyone help explain how to eliminate this?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;error eq 'Received fatal alert CertificateUnknown from client. CA Issuer URL (truncated):&lt;A href="http://cacerts.digicert.com/DigiCertGlobalG2TLSRSASHA2562020CA1" target="_blank" rel="noopener"&gt;http://cacerts.digicert.com/DigiCertGlobalG2TLSRSASHA2562020CA1&lt;/A&gt;' &lt;BR /&gt;URL: &lt;A href="http://aia.entrust.net/l1k-chain256.cer" target="_blank" rel="noopener"&gt;http://aia.entrust.net/l1k-chain256.cer&lt;/A&gt;'&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jul 2024 08:58:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/decryption-failed/m-p/591990#M3410</guid>
      <dc:creator>HY_Cheng</dc:creator>
      <dc:date>2024-07-15T08:58:33Z</dc:date>
    </item>
    <item>
      <title>Re: Decryption failed</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/decryption-failed/m-p/591993#M3411</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/319731"&gt;@HY_Cheng&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It seems like you're dealing with a classic incomplete chain issue.&lt;/P&gt;
&lt;P&gt;This often occurs with SSL/TLS certificates when the server doesn't provide the full certificate chain, excluding the root certificate.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/decryption/troubleshoot-and-monitor-decryption/decryption-logs/repair-incomplete-certificate-chains" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/decryption/troubleshoot-and-monitor-decryption/decryption-logs/repair-incomplete-certificate-chains&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jul 2024 09:14:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/decryption-failed/m-p/591993#M3411</guid>
      <dc:creator>CosminM</dc:creator>
      <dc:date>2024-07-15T09:14:39Z</dc:date>
    </item>
    <item>
      <title>Re: Decryption failed</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/decryption-failed/m-p/592198#M3419</link>
      <description>&lt;P&gt;What exactly did you do when you generated the CA certificate from PA and imported in locally?&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jul 2024 16:12:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/decryption-failed/m-p/592198#M3419</guid>
      <dc:creator>rmfalconer</dc:creator>
      <dc:date>2024-07-16T16:12:48Z</dc:date>
    </item>
    <item>
      <title>Re: Decryption failed</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/decryption-failed/m-p/592506#M3444</link>
      <description>&lt;P&gt;I followed the file settings, and the text did not mention the need for a complete certificate chain.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Only use self-signed CAs and choose to forward trust certificates&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;From the traffic log, I can see that the appplication can be identified, but I still see a similar error in the decryption log. Is it necessary to complete the credential chain for a specific connection to eliminate this problem?&lt;BR /&gt;Any ideas?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you so much&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase-paloaltonetworks-com.translate.goog/KCSArticleDetail?id=kA10g000000ClmyCAC&amp;amp;_x_tr_sl=auto&amp;amp;_x_tr_tl=zh-TW&amp;amp;_x_tr_hl=zh-TW" target="_blank"&gt;https://knowledgebase-paloaltonetworks-com.translate.goog/KCSArticleDetail?id=kA10g000000ClmyCAC&amp;amp;_x_tr_sl=auto&amp;amp;_x_tr_tl=zh-TW&amp;amp;_x_tr_hl=zh-TW&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jul 2024 01:41:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/decryption-failed/m-p/592506#M3444</guid>
      <dc:creator>HY_Cheng</dc:creator>
      <dc:date>2024-07-19T01:41:43Z</dc:date>
    </item>
    <item>
      <title>Re: Decryption failed</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/decryption-failed/m-p/592507#M3445</link>
      <description>&lt;P&gt;I followed the documentation settings, generated a self-signed CA and chose to forward the trust certificate&lt;BR /&gt;Import the local trusted root certificate authority and set the porfile/policy&lt;BR /&gt;Try to connect to check the traffic&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase-paloaltonetworks-com.translate.goog/KCSArticleDetail?id=kA10g000000ClmyCAC&amp;amp;_x_tr_sl=auto&amp;amp;_x_tr_tl=zh-TW&amp;amp;_x_tr_hl=zh-TW" target="_blank"&gt;https://knowledgebase-paloaltonetworks-com.translate.goog/KCSArticleDetail?id=kA10g000000ClmyCAC&amp;amp;_x_tr_sl=auto&amp;amp;_x_tr_tl=zh-TW&amp;amp;_x_tr_hl=zh-TW&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jul 2024 01:44:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/decryption-failed/m-p/592507#M3445</guid>
      <dc:creator>HY_Cheng</dc:creator>
      <dc:date>2024-07-19T01:44:33Z</dc:date>
    </item>
    <item>
      <title>Re: Decryption failed</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/decryption-failed/m-p/592789#M3472</link>
      <description>&lt;P&gt;What type of client are you using? Are they Windows machines? If so, when you browse the Trusted Root Certification Authorities store, do you see it there?&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jul 2024 13:06:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/decryption-failed/m-p/592789#M3472</guid>
      <dc:creator>rmfalconer</dc:creator>
      <dc:date>2024-07-23T13:06:32Z</dc:date>
    </item>
  </channel>
</rss>

