<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to remove DigiNotar CA SSL Root Authority in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-remove-diginotar-ca-ssl-root-authority/m-p/25430#M18541</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;i do not find a hint how to remove any SSL Root Authority in my PAN. How can i announce me the trusted SSL Authorities? Is it possible to remove a single CA like "DigiNotar&amp;nbsp; Root CA".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;mfg&lt;/P&gt;&lt;P&gt;Manfred&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 05 Sep 2011 11:06:53 GMT</pubDate>
    <dc:creator>mhuels</dc:creator>
    <dc:date>2011-09-05T11:06:53Z</dc:date>
    <item>
      <title>How to remove DigiNotar CA SSL Root Authority</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-remove-diginotar-ca-ssl-root-authority/m-p/25430#M18541</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;i do not find a hint how to remove any SSL Root Authority in my PAN. How can i announce me the trusted SSL Authorities? Is it possible to remove a single CA like "DigiNotar&amp;nbsp; Root CA".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;mfg&lt;/P&gt;&lt;P&gt;Manfred&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 05 Sep 2011 11:06:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-remove-diginotar-ca-ssl-root-authority/m-p/25430#M18541</guid>
      <dc:creator>mhuels</dc:creator>
      <dc:date>2011-09-05T11:06:53Z</dc:date>
    </item>
    <item>
      <title>Re: How to remove DigiNotar CA SSL Root Authority</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-remove-diginotar-ca-ssl-root-authority/m-p/25431#M18542</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;+1 !&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 05 Sep 2011 12:26:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-remove-diginotar-ca-ssl-root-authority/m-p/25431#M18542</guid>
      <dc:creator>lardsa</dc:creator>
      <dc:date>2011-09-05T12:26:54Z</dc:date>
    </item>
    <item>
      <title>Re: How to remove DigiNotar CA SSL Root Authority</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-remove-diginotar-ca-ssl-root-authority/m-p/25432#M18543</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ditto...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Sep 2011 17:26:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-remove-diginotar-ca-ssl-root-authority/m-p/25432#M18543</guid>
      <dc:creator>migration</dc:creator>
      <dc:date>2011-09-07T17:26:57Z</dc:date>
    </item>
    <item>
      <title>Re: How to remove DigiNotar CA SSL Root Authority</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-remove-diginotar-ca-ssl-root-authority/m-p/25433#M18544</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would like to know too! &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Sep 2011 22:23:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-remove-diginotar-ca-ssl-root-authority/m-p/25433#M18544</guid>
      <dc:creator>Kendric</dc:creator>
      <dc:date>2011-09-07T22:23:51Z</dc:date>
    </item>
    <item>
      <title>Re: How to remove DigiNotar CA SSL Root Authority</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-remove-diginotar-ca-ssl-root-authority/m-p/25434#M18545</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I wouldn't expect the PAN to have a list of authorized certificate authorities on the device.&lt;/P&gt;&lt;P&gt;This should be updated by each browser and host O/S.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Sep 2011 22:29:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-remove-diginotar-ca-ssl-root-authority/m-p/25434#M18545</guid>
      <dc:creator>camkim_MDEA</dc:creator>
      <dc:date>2011-09-07T22:29:34Z</dc:date>
    </item>
    <item>
      <title>Re: How to remove DigiNotar CA SSL Root Authority</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-remove-diginotar-ca-ssl-root-authority/m-p/25435#M18546</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The PAN needs to know what certificates to trust and which not to trust in order to determine when to present the trust cert to a client or the untrust cert to the client for SSL decryption. The PAN device must have an untrust and a trust list on device to do this.&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Sep 2011 22:32:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-remove-diginotar-ca-ssl-root-authority/m-p/25435#M18546</guid>
      <dc:creator>Kendric</dc:creator>
      <dc:date>2011-09-07T22:32:51Z</dc:date>
    </item>
    <item>
      <title>Re: How to remove DigiNotar CA SSL Root Authority</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-remove-diginotar-ca-ssl-root-authority/m-p/25436#M18547</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ah, learn something new every day.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;They realeased update 265 to alert on certs with the DigiNotar Root Authority, but its not clear if that removes from the device as well or if a different update is required for the device.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Sep 2011 02:20:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-remove-diginotar-ca-ssl-root-authority/m-p/25436#M18547</guid>
      <dc:creator>camkim_MDEA</dc:creator>
      <dc:date>2011-09-08T02:20:41Z</dc:date>
    </item>
    <item>
      <title>Re: How to remove DigiNotar CA SSL Root Authority</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-remove-diginotar-ca-ssl-root-authority/m-p/25437#M18548</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;@camkim:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;please note this information included in the release notes for this emergency content update:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"&lt;SPAN style="font-size: 12.0pt; font-family: &amp;amp;quot;Times New Roman&amp;amp;quot;,&amp;amp;quot;serif&amp;amp;quot;; mso-fareast-font-family: &amp;amp;quot;Times New Roman&amp;amp;quot;; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA;"&gt;In addition, for users of SSL decryption, the new release removes DigiNotar from the device's trusted CA list"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12.0pt; font-family: &amp;amp;quot;Times New Roman&amp;amp;quot;,&amp;amp;quot;serif&amp;amp;quot;; mso-fareast-font-family: &amp;amp;quot;Times New Roman&amp;amp;quot;; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA;"&gt;I advise all users to read the release notes for each release of content and PAN-OS so that you know what has been addressed by each update you apply to your device(s).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12.0pt; font-family: &amp;amp;quot;Times New Roman&amp;amp;quot;,&amp;amp;quot;serif&amp;amp;quot;; mso-fareast-font-family: &amp;amp;quot;Times New Roman&amp;amp;quot;; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA;"&gt;Thanks,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12.0pt; font-family: &amp;amp;quot;Times New Roman&amp;amp;quot;,&amp;amp;quot;serif&amp;amp;quot;; mso-fareast-font-family: &amp;amp;quot;Times New Roman&amp;amp;quot;; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA;"&gt;Benjamin&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Sep 2011 02:25:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-remove-diginotar-ca-ssl-root-authority/m-p/25437#M18548</guid>
      <dc:creator>bpappas</dc:creator>
      <dc:date>2011-09-08T02:25:54Z</dc:date>
    </item>
    <item>
      <title>Re: How to remove DigiNotar CA SSL Root Authority</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-remove-diginotar-ca-ssl-root-authority/m-p/25438#M18549</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;My 2 cents is that PA should let us list &amp;amp; manage root CAs from GUI.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Sep 2011 08:36:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-remove-diginotar-ca-ssl-root-authority/m-p/25438#M18549</guid>
      <dc:creator>lardsa</dc:creator>
      <dc:date>2011-09-08T08:36:38Z</dc:date>
    </item>
    <item>
      <title>Re: How to remove DigiNotar CA SSL Root Authority</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-remove-diginotar-ca-ssl-root-authority/m-p/25439#M18550</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;I advise all users to read the release notes for each release of content and PAN-OS so that you know what has been addressed by each update you apply to your device(s).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;Thanks,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;Benjamin&lt;/SPAN&gt;&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hi Benjamin,&lt;/P&gt;&lt;P&gt;is it a secret, where to find the trusted certificate store on a palo alto system? Why don't you tell the customers simply the method to control the certificate store by themselves?&lt;/P&gt;&lt;P&gt;kindly regards&lt;/P&gt;&lt;P&gt;Manfred&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Sep 2011 10:11:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-remove-diginotar-ca-ssl-root-authority/m-p/25439#M18550</guid>
      <dc:creator>mhuels</dc:creator>
      <dc:date>2011-09-08T10:11:22Z</dc:date>
    </item>
    <item>
      <title>Re: How to remove DigiNotar CA SSL Root Authority</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-remove-diginotar-ca-ssl-root-authority/m-p/25440#M18551</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;They realeased update 265 to alert on certs with the DigiNotar Root Authority, but its not clear if that removes from the device as well or if a different update is required for the device.&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;Also other CAs are concerned apparently.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(german website) &lt;A href="http://www.heise.de/open/meldung/DigiNotar-Hack-GlobalSign-stellt-vorerst-keine-Zertifikate-mehr-aus-1338162.html"&gt;http://www.heise.de/open/meldung/DigiNotar-Hack-GlobalSign-stellt-vorerst-keine-Zertifikate-mehr-aus-1338162.html&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Sep 2011 10:18:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-remove-diginotar-ca-ssl-root-authority/m-p/25440#M18551</guid>
      <dc:creator>mhuels</dc:creator>
      <dc:date>2011-09-08T10:18:50Z</dc:date>
    </item>
    <item>
      <title>Re: How to remove DigiNotar CA SSL Root Authority</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-remove-diginotar-ca-ssl-root-authority/m-p/25441#M18552</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You need to restart your dataplane after the content update before the change can take effect. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Sep 2011 15:37:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-remove-diginotar-ca-ssl-root-authority/m-p/25441#M18552</guid>
      <dc:creator>jleung</dc:creator>
      <dc:date>2011-09-08T15:37:45Z</dc:date>
    </item>
    <item>
      <title>Re: How to remove DigiNotar CA SSL Root Authority</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-remove-diginotar-ca-ssl-root-authority/m-p/25442#M18553</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;@Manfred:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The trusted certificate store on Palo Alto Networks devices is not currently configurable or viewable.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you wish to see the features of the product modified to allow user configuration of the certificate store please talk to your sales team to submit a feature request on your behalf.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Benjamin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Sep 2011 21:01:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-remove-diginotar-ca-ssl-root-authority/m-p/25442#M18553</guid>
      <dc:creator>bpappas</dc:creator>
      <dc:date>2011-09-08T21:01:41Z</dc:date>
    </item>
    <item>
      <title>Re: How to remove DigiNotar CA SSL Root Authority</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-remove-diginotar-ca-ssl-root-authority/m-p/25443#M18554</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Should a dataplane restart be done after every content update or this update special because of the SSL cert issue?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Sep 2011 23:01:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-remove-diginotar-ca-ssl-root-authority/m-p/25443#M18554</guid>
      <dc:creator>dread</dc:creator>
      <dc:date>2011-09-08T23:01:41Z</dc:date>
    </item>
    <item>
      <title>Re: How to remove DigiNotar CA SSL Root Authority</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-remove-diginotar-ca-ssl-root-authority/m-p/25444#M18555</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;@dread:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;this content update is an exception. Most content updates do not require a restart of the dataplane or the device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;benjamin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Sep 2011 23:03:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-remove-diginotar-ca-ssl-root-authority/m-p/25444#M18555</guid>
      <dc:creator>bpappas</dc:creator>
      <dc:date>2011-09-08T23:03:46Z</dc:date>
    </item>
    <item>
      <title>Re: How to remove DigiNotar CA SSL Root Authority</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-remove-diginotar-ca-ssl-root-authority/m-p/25445#M18556</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Benjamin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;since restarting our firewall (running 3.1.10), we see, for example by surfing on &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://balie.culemborg.nl/"&gt;https://balie.culemborg.nl/&lt;/A&gt;&lt;SPAN&gt;, a "drop-all-packets" in the threat log. But in fact, the firewall does not drop the traffic nor shows any error or warning in the decrypted certificate. So we have the bizarre situation having error hints in browsers without PA firewall (as all browsers have removed the diginotar CA), but no warnings in browsers which are secured by a PA firewall (because all browsers accepts the PA certificate, which is used to re-encrypt the SSL traffic).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;Manfred&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Sep 2011 08:58:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-remove-diginotar-ca-ssl-root-authority/m-p/25445#M18556</guid>
      <dc:creator>mhuels</dc:creator>
      <dc:date>2011-09-29T08:58:18Z</dc:date>
    </item>
    <item>
      <title>Re: How to remove DigiNotar CA SSL Root Authority</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-remove-diginotar-ca-ssl-root-authority/m-p/25446#M18557</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;@mhuels:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have you configured the CRL/OCSP options on the Device tab -&amp;gt; Server CRL / OCSP Settings screen?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Benjamin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Oct 2011 03:24:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-remove-diginotar-ca-ssl-root-authority/m-p/25446#M18557</guid>
      <dc:creator>bpappas</dc:creator>
      <dc:date>2011-10-06T03:24:17Z</dc:date>
    </item>
    <item>
      <title>Re: How to remove DigiNotar CA SSL Root Authority</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-remove-diginotar-ca-ssl-root-authority/m-p/25447#M18558</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;bpappas schrieb:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;@mhuels:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have you configured the CRL/OCSP options on the Device tab -&amp;gt; Server CRL / OCSP Settings screen?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Benjamin&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;Hi Benjamin,&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;up to now, we did not have configured anything in the CRL/OCSP tab. Since 5 minutes, we have enabled the checking of revocation lists via CRL and OCSP. Testing on &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://188.203.119.3"&gt;https://188.203.119.3&lt;/A&gt;&lt;SPAN&gt;, the firewall blocks the ssl traffic (the browsers shows a timeout). Although it would be nicer not to drop but to bring out a security warning or an invalid certificate, this behaviour is tolerable for us. There are not so much diginotar certificates anymore ...&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Thanks for your hint.&lt;/P&gt;&lt;P&gt;Manfred&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Oct 2011 09:14:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-remove-diginotar-ca-ssl-root-authority/m-p/25447#M18558</guid>
      <dc:creator>mhuels</dc:creator>
      <dc:date>2011-10-06T09:14:17Z</dc:date>
    </item>
  </channel>
</rss>

