<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSL: Firewall uses untrust-forward cert. for every site in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-firewall-uses-untrust-forward-cert-for-every-site/m-p/23438#M17085</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A __default_attr="2954" __jive_macro_name="document" class="jive_macro jive_macro_document" href="https://live.paloaltonetworks.com/"&gt;&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 26 May 2013 11:45:05 GMT</pubDate>
    <dc:creator>Retired Member</dc:creator>
    <dc:date>2013-05-26T11:45:05Z</dc:date>
    <item>
      <title>SSL: Firewall uses untrust-forward cert. for every site</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-firewall-uses-untrust-forward-cert-for-every-site/m-p/23437#M17084</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I just set up SSL Decryption exactly as described in the &lt;A href="https://live.paloaltonetworks.com/docs/DOC-4214"&gt;Getting Started Guide (English)&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have one trusted-forward certificate, imported into browsers, and one untrust-orward certificate, not imported into browsers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now when I connect to SSL sites, my browsers complain about untrusted certificates, the firewall is clearly using the untrust-forward certificate. When I configure the imported trust-forward certificate to be the untrust-forward certificate (so the imported certificate is both at the same time), everything works fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Something is wrong here. Any ideas?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Sascha&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 26 May 2013 11:36:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-firewall-uses-untrust-forward-cert-for-every-site/m-p/23437#M17084</guid>
      <dc:creator>cryptochrome</dc:creator>
      <dc:date>2013-05-26T11:36:58Z</dc:date>
    </item>
    <item>
      <title>Re: SSL: Firewall uses untrust-forward cert. for every site</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-firewall-uses-untrust-forward-cert-for-every-site/m-p/23438#M17085</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A __default_attr="2954" __jive_macro_name="document" class="jive_macro jive_macro_document" href="https://live.paloaltonetworks.com/"&gt;&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 26 May 2013 11:45:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-firewall-uses-untrust-forward-cert-for-every-site/m-p/23438#M17085</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-05-26T11:45:05Z</dc:date>
    </item>
    <item>
      <title>Re: SSL: Firewall uses untrust-forward cert. for every site</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-firewall-uses-untrust-forward-cert-for-every-site/m-p/23439#M17086</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks, but I don't think this is my problem. In my case, *every* site is being signed by the untrust-forward certificate. Even large ones like Google or Facebook. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 26 May 2013 11:56:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-firewall-uses-untrust-forward-cert-for-every-site/m-p/23439#M17086</guid>
      <dc:creator>cryptochrome</dc:creator>
      <dc:date>2013-05-26T11:56:30Z</dc:date>
    </item>
    <item>
      <title>Re: SSL: Firewall uses untrust-forward cert. for every site</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-firewall-uses-untrust-forward-cert-for-every-site/m-p/23440#M17087</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I digged a little deeper and it seem the firewall is declaring each site's certificate as "untrusted" (see attached screenshot). So either the firewall is unable to check the certificates or there is some other issue. The list of default trusted CA authorities is populated with roughly 260 entries, so that looks ok. I need some help here, something is going very wrong.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Screen Shot 2013-05-26 at 16.00.10.png" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/6671_Screen Shot 2013-05-26 at 16.00.10.png" width="450" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 26 May 2013 14:08:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-firewall-uses-untrust-forward-cert-for-every-site/m-p/23440#M17087</guid>
      <dc:creator>cryptochrome</dc:creator>
      <dc:date>2013-05-26T14:08:40Z</dc:date>
    </item>
    <item>
      <title>Re: SSL: Firewall uses untrust-forward cert. for every site</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-firewall-uses-untrust-forward-cert-for-every-site/m-p/23441#M17088</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This document may help &lt;A __default_attr="5075" __jive_macro_name="document" class="jive_macro jive_macro_document" href="https://live.paloaltonetworks.com/"&gt;&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 31 May 2013 21:12:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-firewall-uses-untrust-forward-cert-for-every-site/m-p/23441#M17088</guid>
      <dc:creator>panagent</dc:creator>
      <dc:date>2013-05-31T21:12:01Z</dc:date>
    </item>
    <item>
      <title>Re: SSL: Firewall uses untrust-forward cert. for every site</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-firewall-uses-untrust-forward-cert-for-every-site/m-p/23442#M17089</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The firewall seems to be having trouble with the issuers as you have shown. The large list of CAs should indicate that it is working fine, and I have not seen this issue before. A couple questions that may help:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. What OS version is your firewall running?&lt;/P&gt;&lt;P&gt;2. Is the content up to date? The most current as of this posting is 375-1810. You can confirm it by looking under the dashboard, or Device &amp;gt; Dynamic Updates.&lt;/P&gt;&lt;P&gt;3. Is there any other SSL interception/proxy device being implemented? Another firewall or a proxy may cause this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps,&lt;/P&gt;&lt;P&gt;Greg Wesson &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 01 Jun 2013 00:14:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-firewall-uses-untrust-forward-cert-for-every-site/m-p/23442#M17089</guid>
      <dc:creator>gwesson</dc:creator>
      <dc:date>2013-06-01T00:14:16Z</dc:date>
    </item>
    <item>
      <title>Re: SSL: Firewall uses untrust-forward cert. for every site</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-firewall-uses-untrust-forward-cert-for-every-site/m-p/23443#M17090</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;please forget about it. I deleted all my certificates and re-created them from scratch, rebooted the firewall and now it is working fine. Not sure why it would use the wrong certificate, something must have got messed up. It's working fine now. Thanks for your help guys.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 01 Jun 2013 09:35:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-firewall-uses-untrust-forward-cert-for-every-site/m-p/23443#M17090</guid>
      <dc:creator>cryptochrome</dc:creator>
      <dc:date>2013-06-01T09:35:40Z</dc:date>
    </item>
  </channel>
</rss>

