<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to get the full CA Issuer URL when it is truncated in the decryption log in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-get-the-full-ca-issuer-url-when-it-is-truncated-in-the/m-p/512536#M106501</link>
    <description>&lt;P&gt;Hi team,&lt;BR /&gt;&lt;BR /&gt;It seems&amp;nbsp;adding a .crl or .crt at the end of the address should help. Also, when they are usually Microsoft certs adding the .crl doesn't work, however, we can test by getting the certificates from &lt;A href="https://www.microsoft.com/pki/mscorp/cps/default.htm" target="_blank"&gt;https://www.microsoft.com/pki/mscorp/cps/default.htm&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers,&lt;BR /&gt;&lt;BR /&gt;Hamid&lt;/P&gt;</description>
    <pubDate>Mon, 22 Aug 2022 13:27:40 GMT</pubDate>
    <dc:creator>Hamid.Saffarzadeh</dc:creator>
    <dc:date>2022-08-22T13:27:40Z</dc:date>
    <item>
      <title>How to get the full CA Issuer URL when it is truncated in the decryption log</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-get-the-full-ca-issuer-url-when-it-is-truncated-in-the/m-p/509902#M106138</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi guys,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;SPAN&gt;I am checking the decryption logs, to repair the certificate chain as mentioned in the guide below:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-admin/decryption/troubleshoot-and-monitor-decryption/decryption-logs/repair-incomplete-certificate-chains" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-admin/decryption/troubleshoot-and-monitor-decryption/decryption-logs/repair-incomplete-certificate-chains&lt;/A&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;The issue is some cannot provide the full URL of the missing root CA/Issuer, for instance:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;SPAN&gt;( error eq 'Received fatal alert CertificateUnknown from client. CA Issuer URL (truncated):&lt;A href="http://www.microsoft.com/pkiops/certs/Microsoft%20Azure%20TLS%2" target="_blank"&gt;http://www.microsoft.com/pkiops/certs/Microsoft%20Azure%20TLS%2&lt;/A&gt;' )&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I was wondering if there is any way to retrieve this address in full to proceed with certificate chain repair.&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;&lt;BR /&gt;Hamid Saffarzadeh&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jul 2022 12:39:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-get-the-full-ca-issuer-url-when-it-is-truncated-in-the/m-p/509902#M106138</guid>
      <dc:creator>Hamid.Saffarzadeh</dc:creator>
      <dc:date>2022-07-26T12:39:10Z</dc:date>
    </item>
    <item>
      <title>Re: How to get the full CA Issuer URL when it is truncated in the decryption log</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-get-the-full-ca-issuer-url-when-it-is-truncated-in-the/m-p/512536#M106501</link>
      <description>&lt;P&gt;Hi team,&lt;BR /&gt;&lt;BR /&gt;It seems&amp;nbsp;adding a .crl or .crt at the end of the address should help. Also, when they are usually Microsoft certs adding the .crl doesn't work, however, we can test by getting the certificates from &lt;A href="https://www.microsoft.com/pki/mscorp/cps/default.htm" target="_blank"&gt;https://www.microsoft.com/pki/mscorp/cps/default.htm&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers,&lt;BR /&gt;&lt;BR /&gt;Hamid&lt;/P&gt;</description>
      <pubDate>Mon, 22 Aug 2022 13:27:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-get-the-full-ca-issuer-url-when-it-is-truncated-in-the/m-p/512536#M106501</guid>
      <dc:creator>Hamid.Saffarzadeh</dc:creator>
      <dc:date>2022-08-22T13:27:40Z</dc:date>
    </item>
    <item>
      <title>Re: How to get the full CA Issuer URL when it is truncated in the decryption log</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-get-the-full-ca-issuer-url-when-it-is-truncated-in-the/m-p/537897#M110458</link>
      <description>&lt;P&gt;Make sure you have the Client SSL Cert in the correct location.&amp;nbsp; Internet Options&amp;nbsp; -&amp;gt; Content -&amp;gt; Certificates -&amp;gt; Import -&amp;gt; select your cert&amp;nbsp; -&amp;gt; Select Place all certificates in the following store -&amp;gt; Browser -&amp;gt; Trusted Root Certification Authorities directory.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That solved our problem.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Apr 2023 14:40:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-get-the-full-ca-issuer-url-when-it-is-truncated-in-the/m-p/537897#M110458</guid>
      <dc:creator>jplotkin</dc:creator>
      <dc:date>2023-04-06T14:40:39Z</dc:date>
    </item>
    <item>
      <title>Re: How to get the full CA Issuer URL when it is truncated in the decryption log</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-get-the-full-ca-issuer-url-when-it-is-truncated-in-the/m-p/563909#M114151</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Anyone get the solution for this issue. we are getting the same issue&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Received fatal alert CertificateUnknown from client. CA Issuer URL (truncated)&lt;SPAN&gt;:&lt;A href="http://www.microsoft.com/pkiops/certs/Microsoft%20Azure%20ECC%252" target="_blank"&gt;http://www.microsoft.com/pkiops/certs/Microsoft%20Azure%20ECC%2&lt;/A&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;We are looking for the permanent fix as solution given in below article is the workaround for which lot of manual task need to do.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/decryption/troubleshoot-and-monitor-decryption/decryption-logs/repair-incomplete-certificate-chains" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/decryption/troubleshoot-and-monitor-decryption/decryption-logs/repair-incomplete-certificate-chains&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Nov 2023 15:43:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-get-the-full-ca-issuer-url-when-it-is-truncated-in-the/m-p/563909#M114151</guid>
      <dc:creator>VirupakshaRajapur</dc:creator>
      <dc:date>2023-11-01T15:43:00Z</dc:date>
    </item>
    <item>
      <title>Re: How to get the full CA Issuer URL when it is truncated in the decryption log</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-get-the-full-ca-issuer-url-when-it-is-truncated-in-the/m-p/1220190#M123251</link>
      <description>&lt;P&gt;I found the http address for the crt chain through a packet capture.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you filter for TLS you can see it in the server hello. Just follow the TCP stream and it will show you where they are coming from.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="EddieHerrera_0-1739373113313.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/65977iB1089C362C6E290A/image-size/medium?v=v2&amp;amp;px=400" role="button" title="EddieHerrera_0-1739373113313.png" alt="EddieHerrera_0-1739373113313.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="http://www.microsoft.com/pkiops/certs/Microsoft%20Update%20Secure%20Server%20CA%202.1.crt" target="_blank"&gt;http://www.microsoft.com/pkiops/certs/Microsoft%20Update%20Secure%20Server%20CA%202.1.crt&lt;/A&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="http://www.microsoft.com/pki/certs/MicRooCerAut2011_2011_03_22.crt" target="_blank"&gt;http://www.microsoft.com/pki/certs/MicRooCerAut2011_2011_03_22.crt&lt;/A&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Hope this helps.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;EJ&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Feb 2025 15:12:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-get-the-full-ca-issuer-url-when-it-is-truncated-in-the/m-p/1220190#M123251</guid>
      <dc:creator>EddieJimenez</dc:creator>
      <dc:date>2025-02-12T15:12:38Z</dc:date>
    </item>
  </channel>
</rss>

