<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Intermediate certs for SSL-VPN portal in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/intermediate-certs-for-ssl-vpn-portal/m-p/26441#M19287</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I didn't notice either however I am having the same issue with my digicert certificates not being trusted on my iOS devices served up via either the Palo Alto or a set of Juniper SA's we have when connecting using safari or the Junos Pulse client. I believe this might be an iOS cert store issue. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 10 May 2011 13:46:54 GMT</pubDate>
    <dc:creator>jasonbone</dc:creator>
    <dc:date>2011-05-10T13:46:54Z</dc:date>
    <item>
      <title>Intermediate certs for SSL-VPN portal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/intermediate-certs-for-ssl-vpn-portal/m-p/26438#M19284</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am using a DigiCert certificate for the SSL VPN portal and the management interface, and it all works well with most browsers. However the certification chain requires an intermediate CA to be trusted/sent as well, and I haven't managed to get that to work on the PAN-box.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It's not a big issue as most browsers seem to be able to resolve the chain by themselves, but for example Firefox on linux and the iPad are unable to verify the chain.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have added the intermediate certificate required as a trusted CA but that didn't seem to help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any suggestions or tips are greately appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks, Tom&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Jan 2011 14:26:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/intermediate-certs-for-ssl-vpn-portal/m-p/26438#M19284</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2011-01-07T14:26:38Z</dc:date>
    </item>
    <item>
      <title>Re: Intermediate certs for SSL-VPN portal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/intermediate-certs-for-ssl-vpn-portal/m-p/26439#M19285</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What version of Firefox is running on the Linux and iPad devices?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Jan 2011 23:18:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/intermediate-certs-for-ssl-vpn-portal/m-p/26439#M19285</guid>
      <dc:creator>bpappas</dc:creator>
      <dc:date>2011-01-18T23:18:40Z</dc:date>
    </item>
    <item>
      <title>Re: Intermediate certs for SSL-VPN portal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/intermediate-certs-for-ssl-vpn-portal/m-p/26440#M19286</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="mso-ansi-language: EN-US"&gt;Hi.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="mso-ansi-language: EN-US"&gt;I have the same problem with Digi intermediate certificate.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="mso-ansi-language: EN-US"&gt;Did you fine any solution to this problem ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="mso-ansi-language: EN-US"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="mso-ansi-language: EN-US"&gt;Thanks, Roger&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 May 2011 19:13:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/intermediate-certs-for-ssl-vpn-portal/m-p/26440#M19286</guid>
      <dc:creator>rogera</dc:creator>
      <dc:date>2011-05-09T19:13:20Z</dc:date>
    </item>
    <item>
      <title>Re: Intermediate certs for SSL-VPN portal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/intermediate-certs-for-ssl-vpn-portal/m-p/26441#M19287</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I didn't notice either however I am having the same issue with my digicert certificates not being trusted on my iOS devices served up via either the Palo Alto or a set of Juniper SA's we have when connecting using safari or the Junos Pulse client. I believe this might be an iOS cert store issue. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 May 2011 13:46:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/intermediate-certs-for-ssl-vpn-portal/m-p/26441#M19287</guid>
      <dc:creator>jasonbone</dc:creator>
      <dc:date>2011-05-10T13:46:54Z</dc:date>
    </item>
    <item>
      <title>Re: Intermediate certs for SSL-VPN portal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/intermediate-certs-for-ssl-vpn-portal/m-p/26442#M19288</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Have you found a resolution to this issue? I am experiencing the same problem.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Dec 2011 02:50:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/intermediate-certs-for-ssl-vpn-portal/m-p/26442#M19288</guid>
      <dc:creator>ShaunD</dc:creator>
      <dc:date>2011-12-07T02:50:36Z</dc:date>
    </item>
    <item>
      <title>Re: Intermediate certs for SSL-VPN portal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/intermediate-certs-for-ssl-vpn-portal/m-p/26443#M19289</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Problem happens because PAN OS doesn't always import intermediate certificate (I don't know why). The fix is to edit the XML configuration file to add the intermediate certifcate, then upload back to your box and commit.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many browsers don't complain about missing intermediate cert, because many of them embed widepsread vendors in additions of root CAs (which is a pure security mess of course).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Dec 2011 12:05:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/intermediate-certs-for-ssl-vpn-portal/m-p/26443#M19289</guid>
      <dc:creator>essnet</dc:creator>
      <dc:date>2011-12-07T12:05:25Z</dc:date>
    </item>
    <item>
      <title>Re: Intermediate certs for SSL-VPN portal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/intermediate-certs-for-ssl-vpn-portal/m-p/26444#M19290</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here is an extract from XML which is missing intermediate:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;&amp;lt;entry name="Mgmt and Portal"&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;lt;common-name&amp;gt;xxxxxxxxxxxxxxxxx&amp;lt;/common-name&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;lt;ca&amp;gt;no&amp;lt;/ca&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;expires&amp;gt;Sep 2 2014&amp;lt;/expires&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;lt;expiry-epoch&amp;gt;1409649540&amp;lt;/expiry-epoch&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;lt;public-key&amp;gt;Bag Attributes&amp;nbsp;&amp;nbsp;&amp;nbsp; localKeyID: E7 87 5F A3 C3 D0 95 2E DF E3 D6 3C A6 F6 41 F8 30 D8 E2 53 &lt;/P&gt;&lt;P&gt;friendlyName: xxxxxxxxxx&lt;/P&gt;&lt;P&gt;subject=xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx&lt;/P&gt;&lt;P&gt;issuer=xxxxxxxxxxxxxxxxxxxxxxxxxxxx&lt;/P&gt;&lt;P&gt;-----BEGIN CERTIFICATE-----&lt;/P&gt;&lt;P&gt;MIIFlTCCA32gAwIBAgIEeFaJjDANBgkqhkiG9w0BAQUFADCBqTELMAkGA1UEBhMCRlIxEjAQ&lt;/P&gt;&lt;P&gt;BgNVBAgTCVZpbmNlbm5lczESMBAGA1UEBxMJVmluY2VubmVzMRAwDgYDVQQKEwdFU1N&lt;/P&gt;&lt;P&gt;JTE9SMRQwEgYDVQQLEwtNSVMgTmV0d29yazEhMB8GA1UEAxMYRVNT&lt;/P&gt;&lt;P&gt;......&lt;/P&gt;&lt;P&gt;-----END CERTIFICATE-----&lt;/P&gt;&lt;P&gt;&amp;lt;/public-key&amp;gt;&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The fix consist to insert intermediate certificate in addition of existing one inside &amp;lt;public-key&amp;gt; statement:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE jivemacro="quote"&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;&amp;lt;entry name="Mgmt and Portal"&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;lt;common-name&amp;gt;xxxxxxxxxxxxxxxxx&amp;lt;/common-name&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;lt;ca&amp;gt;no&amp;lt;/ca&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;expires&amp;gt;Sep 2 2014&amp;lt;/expires&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;lt;expiry-epoch&amp;gt;1409649540&amp;lt;/expiry-epoch&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;lt;public-key&amp;gt;Bag Attributes&amp;nbsp;&amp;nbsp;&amp;nbsp; localKeyID: E7 87 5F A3 C3 D0 95 2E DF E3 D6 3C A6 F6 41 F8 30 D8 E2 53&lt;/P&gt;&lt;P&gt;friendlyName: xxxxxxxxxx&lt;/P&gt;&lt;P&gt;subject=xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx&lt;/P&gt;&lt;P&gt;issuer=xxxxxxxxxxxxxxxxxxxxxxxxxxxx&lt;/P&gt;&lt;P&gt;-----BEGIN CERTIFICATE-----&lt;/P&gt;&lt;P&gt;MIIFlTCCA32gAwIBAgIEeFaJjDANBgkqhkiG9w0BAQUFADCBqTELMAkGA1UEBhMCRlIxEjAQ&lt;/P&gt;&lt;P&gt;BgNVBAgTCVZpbmNlbm5lczESMBAGA1UEBxMJVmluY2VubmVzMRAwDgYDVQQKEwdFU1N&lt;/P&gt;&lt;P&gt;JTE9SMRQwEgYDVQQLEwtNSVMgTmV0d29yazEhMB8GA1UEAxMYRVNT&lt;/P&gt;&lt;P&gt;......&lt;/P&gt;&lt;P&gt;-----END CERTIFICATE-----&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff0000;"&gt;-----BEGIN CERTIFICATE-----aEd5y3GY3i4aWL/LKXe70PBADPZjnDvnJ5e6QhK94uIQdBh9kC26vy89SYsO+XbGOjnZN0QvyvCia&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff0000;"&gt;U80x2DrJvbMgKego/ZHQ6B45YckeyZ97YtRd30TZI/eDfCtgtrPbm4RLCYjqPESfnx1xyQnbMyqQ7q&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff0000;"&gt;FzGetu6ouKSllYycKyErYJbAoVYpozGx59i0gYTVCJluKcx3POnozvw7ZPUzJMgBMRJdS3Va8WW&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff0000;"&gt;kLcHynh1rlcHwWPK022ouJFrMHEQ.........&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff0000;"&gt;-----END CERTIFICATE-----&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;lt;/public-key&amp;gt;&lt;/P&gt;
&lt;/PRE&gt;
&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Import back your XML file, commit and enjoy. Be aware that you will need to restart your appliance dataplane or even reboot, because PAN OS doesn't detect that there was a real change inside the public certificate chain (another bug ?), so it won't reload it during commit.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Dec 2011 12:18:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/intermediate-certs-for-ssl-vpn-portal/m-p/26444#M19290</guid>
      <dc:creator>essnet</dc:creator>
      <dc:date>2011-12-07T12:18:29Z</dc:date>
    </item>
    <item>
      <title>Re: Intermediate certs for SSL-VPN portal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/intermediate-certs-for-ssl-vpn-portal/m-p/26445#M19291</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I do not see the XML inside my configuration file that you are referencing.&amp;nbsp; I'm on PAN-OS 3.1.9, are you running something else?&amp;nbsp; The Certificates are referenced in my configuration file in the Captive Portal and SSL-VPN sections, but the actual certificates are not in this file.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Dec 2011 17:06:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/intermediate-certs-for-ssl-vpn-portal/m-p/26445#M19291</guid>
      <dc:creator>ShaunD</dc:creator>
      <dc:date>2011-12-07T17:06:15Z</dc:date>
    </item>
    <item>
      <title>Re: Intermediate certs for SSL-VPN portal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/intermediate-certs-for-ssl-vpn-portal/m-p/26446#M19292</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am using 4.0+ software only. No idea where are stored certificates on 3.x but it looks like it shares same bug.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Dec 2011 17:10:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/intermediate-certs-for-ssl-vpn-portal/m-p/26446#M19292</guid>
      <dc:creator>essnet</dc:creator>
      <dc:date>2011-12-07T17:10:22Z</dc:date>
    </item>
    <item>
      <title>Re: Intermediate certs for SSL-VPN portal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/intermediate-certs-for-ssl-vpn-portal/m-p/26447#M19293</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;SSL certificates were not included in the config XML file until 4.0.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, instead of rebooting the device or the dataplane, when importing the same certificate that you already imported, just give it a new name, then change your SSLVPN or captive portal config to use this new certificate.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Apr 2012 14:10:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/intermediate-certs-for-ssl-vpn-portal/m-p/26447#M19293</guid>
      <dc:creator>rnitz</dc:creator>
      <dc:date>2012-04-30T14:10:50Z</dc:date>
    </item>
    <item>
      <title>Re: Intermediate certs for SSL-VPN portal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/intermediate-certs-for-ssl-vpn-portal/m-p/26448#M19294</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you, essnet!&amp;nbsp; Nothing else worked for me, but manually appending the intermediate cert to the primary in XML did the trick!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I also had to reboot the devices for the change to take effect.&amp;nbsp; I would've thought after 1.5 years that would be fixed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 May 2013 20:23:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/intermediate-certs-for-ssl-vpn-portal/m-p/26448#M19294</guid>
      <dc:creator>RyanF</dc:creator>
      <dc:date>2013-05-22T20:23:17Z</dc:date>
    </item>
  </channel>
</rss>

