<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SSL decryption - Connection is not Private in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-connection-is-not-private/m-p/460452#M102074</link>
    <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;I am configuring SSL decryption on Palo Alto using a self-signed CA. I have created two certificates, one for forward trust and second for forward untrust. I have installed the forward trust certificate into the trusted root CA of the machine.&lt;/P&gt;&lt;P&gt;The issue is that I keep getting Your connection is not private message for all the sites that I am trying to access and looks like Palo is not trusting them and only issuing Untrust cert.&lt;/P&gt;&lt;P&gt;Is there anything I am missing?&lt;/P&gt;&lt;P&gt;Appreciate your response.&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;</description>
    <pubDate>Sun, 23 Jan 2022 23:01:09 GMT</pubDate>
    <dc:creator>Zain_Chaudhry</dc:creator>
    <dc:date>2022-01-23T23:01:09Z</dc:date>
    <item>
      <title>SSL decryption - Connection is not Private</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-connection-is-not-private/m-p/460452#M102074</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;I am configuring SSL decryption on Palo Alto using a self-signed CA. I have created two certificates, one for forward trust and second for forward untrust. I have installed the forward trust certificate into the trusted root CA of the machine.&lt;/P&gt;&lt;P&gt;The issue is that I keep getting Your connection is not private message for all the sites that I am trying to access and looks like Palo is not trusting them and only issuing Untrust cert.&lt;/P&gt;&lt;P&gt;Is there anything I am missing?&lt;/P&gt;&lt;P&gt;Appreciate your response.&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Sun, 23 Jan 2022 23:01:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-connection-is-not-private/m-p/460452#M102074</guid>
      <dc:creator>Zain_Chaudhry</dc:creator>
      <dc:date>2022-01-23T23:01:09Z</dc:date>
    </item>
    <item>
      <title>Re: SSL decryption - Connection is not Private</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-connection-is-not-private/m-p/461380#M102164</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/134673"&gt;@Zain_Chaudhry&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Should work.&lt;/P&gt;
&lt;P&gt;Are you by any chance using a browser that has it's own certificate store (firefox for example) ? In that case, install the certificate in the browser certificate store.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope it helps,&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV id="ConnectiveDocSignExtentionInstalled" data-extension-version="1.0.4"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Thu, 27 Jan 2022 12:56:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-connection-is-not-private/m-p/461380#M102164</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2022-01-27T12:56:42Z</dc:date>
    </item>
    <item>
      <title>Re: SSL decryption - Connection is not Private</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-connection-is-not-private/m-p/461462#M102171</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/134673"&gt;@Zain_Chaudhry&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;In addition to what&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11943"&gt;@kiwi&lt;/a&gt;&amp;nbsp;mentioned, is it actually every site and does the firewall itself trust the root certificate of the website in question. Some countries I've had customers operating in actually have a root CA that you need to add into the firewall and add it as a trusted root CA as they perform their own inspection. You could also be visiting sites that are simply issued by root CAs not trusted by the firewall, and you'll likewise need to import the root CA and mark it as a trusted Root CA so the firewall actually trusts the certificate being presented by the website in question.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jan 2022 16:02:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-connection-is-not-private/m-p/461462#M102171</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2022-01-27T16:02:03Z</dc:date>
    </item>
  </channel>
</rss>

