<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PAN and intermediate CAs in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pan-and-intermediate-cas/m-p/519973#M107792</link>
    <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/220841"&gt;@JayGolf&lt;/a&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for reply and useful info. But it still seems a bit strange; almost every (if not every) website is signed by intermediate CA. After implementing and testing decryption (with certificate checks on PA) everything worked without adding any intermediate CAs. So are some intermediate CAs already included as Trusted CAs? Of course we didn't try every possible website but we didn't notice any issues then on websites we tried.&lt;/P&gt;
&lt;P&gt;Then last week there were suddenly lots of cases of having to import Intermediate CAs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;And let's take for example google.com. It's signed by intermediate CA "&lt;SPAN&gt;GTS CA 1C3" which i never manually imported and is not among Default Trusted CAs. But i'm pretty sure the customer can access it otherwise they would report it ages ago.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;So what is the actual story with trust for Intermediate CAs?&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 02 Nov 2022 09:31:30 GMT</pubDate>
    <dc:creator>santonic</dc:creator>
    <dc:date>2022-11-02T09:31:30Z</dc:date>
    <item>
      <title>PAN and intermediate CAs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pan-and-intermediate-cas/m-p/519373#M107688</link>
      <description>&lt;P&gt;Last couple of days I've had quite a few cases where I had to manually add intermediate CAs as a Trusted Root CA in order for decryption to work (for customers blocking untrusted CAs already on firewall).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;These are quite well known intermediate CAs like:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;DigiCert TLS RSA SHA256 2020 CA1&lt;/P&gt;
&lt;P&gt;GeoTrust RSA CA 2018&lt;/P&gt;
&lt;P&gt;Entrust Certification Authority - L1K&lt;/P&gt;
&lt;P&gt;Entrust Certification Authority - L1M&lt;/P&gt;
&lt;P&gt;GEANT OV RSA CA 4&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How come PAN's trusted Root CA list is lacking so many? How is it updated? Via content updates? I have content updates schduled daily.&lt;/P&gt;
&lt;P&gt;Anyone else having issues with this? I know there was only some to add in the past. But last couple of days I really had many to add at different customers.&lt;/P&gt;
&lt;P&gt;&lt;LI-PRODUCT title="SSL Decryption" id="SSL_Decryption"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Oct 2022 11:29:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pan-and-intermediate-cas/m-p/519373#M107688</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2022-10-27T11:29:55Z</dc:date>
    </item>
    <item>
      <title>Re: PAN and intermediate CAs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pan-and-intermediate-cas/m-p/519965#M107786</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/10238"&gt;@santonic&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I found this regarding int-CAs "&lt;SPAN&gt;the firewall does not trust intermediate CAs by default because intermediate CAs are not a part of the chain of trust between the firewall and the trusted root CA. You must manually add any intermediate CAs that you want the firewall to trust, along with any additional trusted enterprise CAs that your organization requires" from &lt;A href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-web-interface-help/device/device-certificate-management-certificates/manage-default-trusted-certificate-authorities" target="_self"&gt;Manage Default Trusted Certificate Authoritie&lt;/A&gt;s.&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV class="banner"&gt;
&lt;DIV class="banner-inner"&gt;
&lt;H1&gt;&amp;nbsp;&lt;/H1&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class="content"&gt;
&lt;DIV class="content-inner"&gt;
&lt;DIV class="book-detail-pagination"&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Wed, 02 Nov 2022 07:41:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pan-and-intermediate-cas/m-p/519965#M107786</guid>
      <dc:creator>JayGolf</dc:creator>
      <dc:date>2022-11-02T07:41:55Z</dc:date>
    </item>
    <item>
      <title>Re: PAN and intermediate CAs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pan-and-intermediate-cas/m-p/519973#M107792</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/220841"&gt;@JayGolf&lt;/a&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for reply and useful info. But it still seems a bit strange; almost every (if not every) website is signed by intermediate CA. After implementing and testing decryption (with certificate checks on PA) everything worked without adding any intermediate CAs. So are some intermediate CAs already included as Trusted CAs? Of course we didn't try every possible website but we didn't notice any issues then on websites we tried.&lt;/P&gt;
&lt;P&gt;Then last week there were suddenly lots of cases of having to import Intermediate CAs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;And let's take for example google.com. It's signed by intermediate CA "&lt;SPAN&gt;GTS CA 1C3" which i never manually imported and is not among Default Trusted CAs. But i'm pretty sure the customer can access it otherwise they would report it ages ago.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;So what is the actual story with trust for Intermediate CAs?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Nov 2022 09:31:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pan-and-intermediate-cas/m-p/519973#M107792</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2022-11-02T09:31:30Z</dc:date>
    </item>
  </channel>
</rss>

