<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Website is not secure, certificate is expired. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/website-is-not-secure-certificate-is-expired/m-p/521127#M108009</link>
    <description>&lt;P&gt;Hi everyone,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Recently, I've seen an issue where if we use a computer that has its traffic routed through the PAN NGFW, we will get an error message from the website saying "Your connection is not private" with an error code:&amp;nbsp;&lt;SPAN&gt;NET::ERR_CERT_COMMON_NAME_INVALID.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;This happen to 2 different websites I've seen so far. When we looked at the certificate it looks like the certificate of the websites are expired.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;However, the weird thing is that when the traffic is not routed through the firewall, for example, using a different computer and network, we are able to access those websites just fine with valid certificate.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The URLs that we encountered this issues are:&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;zetta.net.au&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;airport.lk&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Please kindly let me know if you have experienced this issue before and how do you fix it.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 14 Nov 2022 06:04:20 GMT</pubDate>
    <dc:creator>LuckyLau</dc:creator>
    <dc:date>2022-11-14T06:04:20Z</dc:date>
    <item>
      <title>Website is not secure, certificate is expired.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/website-is-not-secure-certificate-is-expired/m-p/521127#M108009</link>
      <description>&lt;P&gt;Hi everyone,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Recently, I've seen an issue where if we use a computer that has its traffic routed through the PAN NGFW, we will get an error message from the website saying "Your connection is not private" with an error code:&amp;nbsp;&lt;SPAN&gt;NET::ERR_CERT_COMMON_NAME_INVALID.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;This happen to 2 different websites I've seen so far. When we looked at the certificate it looks like the certificate of the websites are expired.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;However, the weird thing is that when the traffic is not routed through the firewall, for example, using a different computer and network, we are able to access those websites just fine with valid certificate.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The URLs that we encountered this issues are:&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;zetta.net.au&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;airport.lk&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Please kindly let me know if you have experienced this issue before and how do you fix it.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Nov 2022 06:04:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/website-is-not-secure-certificate-is-expired/m-p/521127#M108009</guid>
      <dc:creator>LuckyLau</dc:creator>
      <dc:date>2022-11-14T06:04:20Z</dc:date>
    </item>
    <item>
      <title>Re: Website is not secure, certificate is expired.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/website-is-not-secure-certificate-is-expired/m-p/521338#M108042</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Do you have ssl decryption enabled? If the local test machine does not trust the certificate, you will get these messages.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Tue, 15 Nov 2022 22:30:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/website-is-not-secure-certificate-is-expired/m-p/521338#M108042</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2022-11-15T22:30:50Z</dc:date>
    </item>
    <item>
      <title>Re: Website is not secure, certificate is expired.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/website-is-not-secure-certificate-is-expired/m-p/521422#M108057</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/209095"&gt;@LuckyLau&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;In addition to what&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&amp;nbsp;mentioned, when you're decrypting traffic you'll find that you have to manage certificates on the device a little bit for some providers. The firewall has a default list of trusted certificate authorities, but it doesn't trust everything that your browser will as an example. You might have to actually import the issuing CA certificates and mark them as trusted.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Nov 2022 16:28:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/website-is-not-secure-certificate-is-expired/m-p/521422#M108057</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2022-11-16T16:28:55Z</dc:date>
    </item>
    <item>
      <title>Re: Website is not secure, certificate is expired.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/website-is-not-secure-certificate-is-expired/m-p/521448#M108061</link>
      <description>&lt;P&gt;Hmmm... that is kind of an interesting failure... When connecting to zetta.net.au from behind the PA you get a certificate with a wildcard CN subject of "*.highway1.com.au" that expired Nov 5 2017 (hence the COMMON_NAME_INVALID error, it would also fail for certificate expiry). When connecting from a different ISP not behind a PA you get a certificate with a CN of "&lt;A href="http://www.zetta.com.au" target="_blank"&gt;www.zetta.com.au&lt;/A&gt;" and an alternate name of "zetta.com.au", which is signed by Lets Encrypt and has an expiry of Dec 17 2022.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It looks like the server is giving out different certificates based on the client source and one of those certificates is expired/incorrect for the host. The certificate valid from/to dates should be passed thru the PA with decryption enabled, but the zetta.com.au certificate shows completely different dates. Checking another server I have that is signed by the exact same Lets Encrypt CA, both behind and separate from the PA show the exact same certificate dates and the Lets Encrypt signed cert decrypts behind the PA without issue. So it seems to not be a PA known CA authorities issue.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Nov 2022 18:25:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/website-is-not-secure-certificate-is-expired/m-p/521448#M108061</guid>
      <dc:creator>Adrian_Jensen</dc:creator>
      <dc:date>2022-11-16T18:25:37Z</dc:date>
    </item>
    <item>
      <title>Re: Website is not secure, certificate is expired.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/website-is-not-secure-certificate-is-expired/m-p/1204804#M122974</link>
      <description>&lt;P&gt;Hi, would like to know how you get the issue resolved? Thank you.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jan 2025 05:59:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/website-is-not-secure-certificate-is-expired/m-p/1204804#M122974</guid>
      <dc:creator>SS_CHEW</dc:creator>
      <dc:date>2025-01-22T05:59:10Z</dc:date>
    </item>
  </channel>
</rss>

