<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SSL certificate has expired end date after PA decryption in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-certificate-has-expired-end-date-after-pa-decryption/m-p/1254969#M126507</link>
    <description>&lt;P&gt;Running into a weird problem with SSL decryption and a vendor's internet certificate that has broken after going through the PaloAlto. An external vendor updated their internet-facing certificate this afternoon and internal users immediately started receiving certificate expired errors. Externally the certificate appears fine, but internally the certificate now has a negative lifespan (expired before the cert was issued). Has anyone seen this before?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The cert was issued by Let's Encrypt. Checking externally the cert, it looks good. As far as I can tell the new cert is not revoked. When externally checking the cert I get a lifetime of:&lt;/P&gt;
&lt;P&gt;260528202420Z -- 260826202419Z&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;However, in the PA ssl-decrypt certificate-cache, and presented to the internal client, it now has a lifetime of:&lt;/P&gt;
&lt;P&gt;260528202451Z -- 2&lt;STRONG&gt;5&lt;/STRONG&gt;0915160000Z&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;...meaning it expired Aug 15 2025, 8 months before it was issued. The certificate-cache CRL status also shows expired, but I am unable to replicate this externally.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have cleared the decrypt cache and retried with the same effect. It seems like this is a PA bug that is breaking certificates? I have recently upgraded to 10.2.16-h8 to fix the various recent CVEs, but not seeing anything in the known issues notes that seems to relate to this.&lt;/P&gt;</description>
    <pubDate>Fri, 29 May 2026 00:21:52 GMT</pubDate>
    <dc:creator>Adrian_Jensen</dc:creator>
    <dc:date>2026-05-29T00:21:52Z</dc:date>
    <item>
      <title>SSL certificate has expired end date after PA decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-certificate-has-expired-end-date-after-pa-decryption/m-p/1254969#M126507</link>
      <description>&lt;P&gt;Running into a weird problem with SSL decryption and a vendor's internet certificate that has broken after going through the PaloAlto. An external vendor updated their internet-facing certificate this afternoon and internal users immediately started receiving certificate expired errors. Externally the certificate appears fine, but internally the certificate now has a negative lifespan (expired before the cert was issued). Has anyone seen this before?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The cert was issued by Let's Encrypt. Checking externally the cert, it looks good. As far as I can tell the new cert is not revoked. When externally checking the cert I get a lifetime of:&lt;/P&gt;
&lt;P&gt;260528202420Z -- 260826202419Z&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;However, in the PA ssl-decrypt certificate-cache, and presented to the internal client, it now has a lifetime of:&lt;/P&gt;
&lt;P&gt;260528202451Z -- 2&lt;STRONG&gt;5&lt;/STRONG&gt;0915160000Z&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;...meaning it expired Aug 15 2025, 8 months before it was issued. The certificate-cache CRL status also shows expired, but I am unable to replicate this externally.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have cleared the decrypt cache and retried with the same effect. It seems like this is a PA bug that is breaking certificates? I have recently upgraded to 10.2.16-h8 to fix the various recent CVEs, but not seeing anything in the known issues notes that seems to relate to this.&lt;/P&gt;</description>
      <pubDate>Fri, 29 May 2026 00:21:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-certificate-has-expired-end-date-after-pa-decryption/m-p/1254969#M126507</guid>
      <dc:creator>Adrian_Jensen</dc:creator>
      <dc:date>2026-05-29T00:21:52Z</dc:date>
    </item>
  </channel>
</rss>

