<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Global Protect certificate Error: Certificate 'certname' failed to load: parse tbs certificate not supported algorithm in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-certificate-error-certificate-certname-failed-to/m-p/23802#M17357</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What dose that error mean?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Im trying to get a simple certificate from an w2k8 server CA to use in the Global Protect.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Secure WebGui certificate works fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thx in adavanced.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 12 Apr 2012 18:14:51 GMT</pubDate>
    <dc:creator>PoTski</dc:creator>
    <dc:date>2012-04-12T18:14:51Z</dc:date>
    <item>
      <title>Global Protect certificate Error: Certificate 'certname' failed to load: parse tbs certificate not supported algorithm</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-certificate-error-certificate-certname-failed-to/m-p/23802#M17357</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What dose that error mean?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Im trying to get a simple certificate from an w2k8 server CA to use in the Global Protect.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Secure WebGui certificate works fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thx in adavanced.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Apr 2012 18:14:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-certificate-error-certificate-certname-failed-to/m-p/23802#M17357</guid>
      <dc:creator>PoTski</dc:creator>
      <dc:date>2012-04-12T18:14:51Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect certificate Error: Certificate 'certname' failed to load: parse tbs certificate not supported algorithm</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-certificate-error-certificate-certname-failed-to/m-p/23803#M17358</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I found the answer after alot of researching.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem is in in certificate signature algorithm.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When we set up the intermediate server we choose to use RSA512 as a signature algorithm. As it turns out the PA v4.1.5 dose not support RSA512.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you are running a windows CA and need to change the signature algorithm. See the following url.&lt;/P&gt;&lt;P&gt;&lt;A href="http://social.technet.microsoft.com/Forums/en-US/winserversecurity/thread/568ef7b7-5cad-4225-b35a-4630a57a3ac5"&gt;http://social.technet.microsoft.com/Forums/en-US/winserversecurity/thread/568ef7b7-5cad-4225-b35a-4630a57a3ac5&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;PoTski&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Apr 2012 10:42:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-certificate-error-certificate-certname-failed-to/m-p/23803#M17358</guid>
      <dc:creator>PoTski</dc:creator>
      <dc:date>2012-04-13T10:42:11Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect certificate Error: Certificate 'certname' failed to load: parse tbs certificate not supported algorithm</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-certificate-error-certificate-certname-failed-to/m-p/23804#M17359</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the update.&amp;nbsp; Was looking at using SSL inspection via our CA.&amp;nbsp; We used 512RSA to stop Google Chrome moaning about being signed unsecurely when running MD5. Have already uninstalled and re-installed our CA to get this working, don't fancy the reg hack though.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Don't suppose you know if this is fixed in 4.1.6?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Jul 2012 13:07:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-certificate-error-certificate-certname-failed-to/m-p/23804#M17359</guid>
      <dc:creator>pg_itdept</dc:creator>
      <dc:date>2012-07-05T13:07:41Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect certificate Error: Certificate 'certname' failed to load: parse tbs certificate not supported algorithm</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-certificate-error-certificate-certname-failed-to/m-p/23805#M17360</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Isnt RSA512 just really bad?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;At least use 1024 if your have performance concerns.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;FIPS 140-2 states one should use 2048 while EU-CRYPTII says something like at least 2444 bits for assymetric encryption (in reality 4096 is the next step).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A true CA should use as high encryption as possible for example 16384 where the issued certs uses 4096 or such.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Jul 2012 12:38:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-certificate-error-certificate-certname-failed-to/m-p/23805#M17360</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-07-06T12:38:24Z</dc:date>
    </item>
  </channel>
</rss>

