<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: What is Trusted CA Certificate used for? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/what-is-trusted-ca-certificate-used-for/m-p/26894#M19631</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry, I didn't understand.&lt;/P&gt;&lt;P&gt;Can you confirm that URL License is required if I want "URL Category" based SSL-D Decryption?&lt;/P&gt;&lt;P&gt;I suppose this but it isn't written in any manual...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 27 Jan 2011 13:42:44 GMT</pubDate>
    <dc:creator>migration</dc:creator>
    <dc:date>2011-01-27T13:42:44Z</dc:date>
    <item>
      <title>What is Trusted CA Certificate used for?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-is-trusted-ca-certificate-used-for/m-p/26886#M19623</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;According to the PA-3.0_Administrators_Guide.pdf:&lt;BR /&gt;&lt;BR /&gt;"&lt;BR /&gt;Trusted CA certificate—Import an additional intermediate certificate authority (CA) certificate to trust when doing SSL decryption. If the firewall encounters a certificate that is not signed by a trusted CA, then it uses its own untrusted CA to sign the certificate and generate the expected browser warning message. &lt;BR /&gt;"&lt;BR /&gt;&lt;BR /&gt;It might be because I dont have english as native language but I dont get what the above says &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;Am I correct that the above actually means that when you do ssl decryption and visit a https site where the ssl cert of this site is signed by an unknown CA (like a CA from a specific company like your own). You can then add the ca.crt of this CA who signed that server-cert to the PA-unit and it will successfully decrypt the traffic otherwise it will bring you an error that the cert of this server cannot be verified?&lt;BR /&gt;&lt;BR /&gt;If so, can I only add one such CA cert to the PA-unit (where I work we have at least two CA's one for production and one for tests and I would need to add at least two custom CA certs to the PA-unit so it will successfully perform ssl decryption without warnings or errors)?&lt;BR /&gt;&lt;BR /&gt;How do I list which additional CA certs have been added to the PA-unit (or which CA certs already exists (builtin)) or for that matter delete an incorrect CA cert?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 27 Feb 2010 08:36:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-is-trusted-ca-certificate-used-for/m-p/26886#M19623</guid>
      <dc:creator>rps</dc:creator>
      <dc:date>2010-02-27T08:36:12Z</dc:date>
    </item>
    <item>
      <title>Re: What is Trusted CA Certificate used for?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-is-trusted-ca-certificate-used-for/m-p/26887#M19624</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello RSP,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P align="left"&gt;&lt;/P&gt;&lt;P align="left"&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: SabonLTStd-Roman;"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;In order to decrypt the SSL sessions, a CA certi&lt;SPAN style="font-family: SabonLTStd-Roman;"&gt;!&lt;/SPAN&gt;cate is required. This certi&lt;SPAN style="font-family: SabonLTStd-Roman;"&gt;!&lt;/SPAN&gt;cate is used to&lt;/P&gt;&lt;P&gt;generate certi&lt;SPAN style="font-family: SabonLTStd-Roman;"&gt;!&lt;/SPAN&gt;cates for each SSL destination. By default, a self-signed certi&lt;SPAN style="font-family: SabonLTStd-Roman;"&gt;!&lt;/SPAN&gt;cate is used. Because&lt;/P&gt;&lt;P&gt;this certi&lt;SPAN style="font-family: SabonLTStd-Roman;"&gt;!&lt;/SPAN&gt;cate is not a "Trusted CA", browsers and other applications will give the users a&lt;/P&gt;&lt;P&gt;warning indicating that the identity of site they are accessing could not be veri&lt;SPAN style="font-family: SabonLTStd-Roman;"&gt;!&lt;/SPAN&gt;ed. The browsers&lt;/P&gt;&lt;P&gt;can be con&lt;SPAN style="font-family: SabonLTStd-Roman;"&gt;!&lt;/SPAN&gt;gured to trust the CA certi&lt;SPAN style="font-family: SabonLTStd-Roman;"&gt;!&lt;/SPAN&gt;cate by importing it into the browser. Alternatively, an&lt;/P&gt;&lt;P&gt;already trusted CA cert that is used in the enterprise can be installed into the device for use in the&lt;/P&gt;&lt;P&gt;SSL decryption process.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When you import certs into the Pan device you will see them listed under device tab/certificates.&lt;/P&gt;&lt;P&gt;Please read the following two documents thoroughly to get a better understanding of SSL decryption on the Palolato device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Mar 2010 23:18:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-is-trusted-ca-certificate-used-for/m-p/26887#M19624</guid>
      <dc:creator>swhyte</dc:creator>
      <dc:date>2010-03-04T23:18:49Z</dc:date>
    </item>
    <item>
      <title>Re: What is Trusted CA Certificate used for?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-is-trusted-ca-certificate-used-for/m-p/26888#M19625</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hmm, isnt what you decribe what the "SSL Decryption Certificate" (in the Certificates config) is used for?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Since you will have to import both private and public key of the CA to the PAN so it can issue its own certs for the MITM when doing ssl decryption?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;While the "Trusted CA" will only accept the *.crt part.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How are certs handled during ssl decryption if the cert (on the server which the client visits) is issued by a private CA?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is the workaround for this to uncheck "block unknown" in the crl settings?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Because I would like to block unknown certs (or certs that cannot be verified between PAN and the server) but at the same time still tell the PAN unit to trust a specific range of CA's (except for those who are builtin if any).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Mar 2010 05:31:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-is-trusted-ca-certificate-used-for/m-p/26888#M19625</guid>
      <dc:creator>rps</dc:creator>
      <dc:date>2010-03-05T05:31:29Z</dc:date>
    </item>
    <item>
      <title>Re: What is Trusted CA Certificate used for?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-is-trusted-ca-certificate-used-for/m-p/26889#M19626</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi RSP,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;with SSL decryption, if the actual certificate has been issued an authority not trusted by the Palo Alto firewal, then the decryption certifiecate will be issued using a second "untrusted" CA key. this is to insure that the user is warned if there are subsequent man in the middle attachs occurring.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also the "unknown" is referring to the categorization of the site, not whether the certificate of the server is trusted or not trusted by the Pan.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The SSL Decryption Policy uses URL&lt;/P&gt;&lt;P&gt;filtering to decide which traffic to&lt;/P&gt;&lt;P&gt;decrypt or not decrypt. User or&lt;/P&gt;&lt;P&gt;destination address can also be used for&lt;/P&gt;&lt;P&gt;the decryption decision, but in practice&lt;/P&gt;&lt;P&gt;the decision is made on the URL filtering&lt;/P&gt;&lt;P&gt;category of the destination address. The&lt;/P&gt;&lt;P&gt;destination IP address is compared since&lt;/P&gt;&lt;P&gt;the URL is not visible.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Mar 2010 17:00:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-is-trusted-ca-certificate-used-for/m-p/26889#M19626</guid>
      <dc:creator>swhyte</dc:creator>
      <dc:date>2010-03-05T17:00:01Z</dc:date>
    </item>
    <item>
      <title>Re: What is Trusted CA Certificate used for?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-is-trusted-ca-certificate-used-for/m-p/26890#M19627</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I need to understand just a things: is URL Filtering license needed to SSL-Decryption process?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Jan 2011 12:12:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-is-trusted-ca-certificate-used-for/m-p/26890#M19627</guid>
      <dc:creator>migration</dc:creator>
      <dc:date>2011-01-25T12:12:39Z</dc:date>
    </item>
    <item>
      <title>Re: What is Trusted CA Certificate used for?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-is-trusted-ca-certificate-used-for/m-p/26891#M19628</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi There,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A URL License is not required for SSL Decryption to function.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, the URL categories supplied via a URL License allow you to do a simple include/exclude of many sites.&amp;nbsp; So for example, due to privacy, you would not want to decrypt someones Internet Banking.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope this helps&lt;/P&gt;&lt;P&gt;James&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Jan 2011 12:57:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-is-trusted-ca-certificate-used-for/m-p/26891#M19628</guid>
      <dc:creator>James</dc:creator>
      <dc:date>2011-01-25T12:57:15Z</dc:date>
    </item>
    <item>
      <title>Re: What is Trusted CA Certificate used for?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-is-trusted-ca-certificate-used-for/m-p/26892#M19629</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks a lot!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, are you saying that without URL License I can't do a Category based SSL-D but only destination IP based?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I need to clarify myself this object.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Bye&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Jan 2011 10:44:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-is-trusted-ca-certificate-used-for/m-p/26892#M19629</guid>
      <dc:creator>migration</dc:creator>
      <dc:date>2011-01-27T10:44:04Z</dc:date>
    </item>
    <item>
      <title>Re: What is Trusted CA Certificate used for?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-is-trusted-ca-certificate-used-for/m-p/26893#M19630</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This will work fine&lt;/P&gt;&lt;P&gt;Happy testing &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Jan 2011 13:14:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-is-trusted-ca-certificate-used-for/m-p/26893#M19630</guid>
      <dc:creator>James</dc:creator>
      <dc:date>2011-01-27T13:14:07Z</dc:date>
    </item>
    <item>
      <title>Re: What is Trusted CA Certificate used for?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-is-trusted-ca-certificate-used-for/m-p/26894#M19631</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry, I didn't understand.&lt;/P&gt;&lt;P&gt;Can you confirm that URL License is required if I want "URL Category" based SSL-D Decryption?&lt;/P&gt;&lt;P&gt;I suppose this but it isn't written in any manual...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Jan 2011 13:42:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-is-trusted-ca-certificate-used-for/m-p/26894#M19631</guid>
      <dc:creator>migration</dc:creator>
      <dc:date>2011-01-27T13:42:44Z</dc:date>
    </item>
    <item>
      <title>Re: What is Trusted CA Certificate used for?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-is-trusted-ca-certificate-used-for/m-p/26895#M19632</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That is correct - if you want to configure the URL category as part of your SSL Decryption rule base, then you'll need the URL license.&amp;nbsp; Without this the Palo Alto Appliance will not have knowledge of URL categories.&lt;/P&gt;&lt;P&gt;Therefore, traffic maybe decrypted with the URL category set to "any" (with no URL License) and other criteria matched, like source/dest IP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;James&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Jan 2011 13:48:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-is-trusted-ca-certificate-used-for/m-p/26895#M19632</guid>
      <dc:creator>James</dc:creator>
      <dc:date>2011-01-27T13:48:30Z</dc:date>
    </item>
  </channel>
</rss>

