<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Enabling forward trust certificate in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/enabling-forward-trust-certificate/m-p/26940#M19677</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi all, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm hoping someone can assist. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can't enable the Forward Trust option for a cert that I generate using either a self-signed CA or 3rd party CA.&amp;nbsp; The check is either greyed out or it's an option but doesn't keep the check after I hit OK. Any idea on how to get this working?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 05 Feb 2015 17:09:18 GMT</pubDate>
    <dc:creator>Dmaurice-nci</dc:creator>
    <dc:date>2015-02-05T17:09:18Z</dc:date>
    <item>
      <title>Enabling forward trust certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/enabling-forward-trust-certificate/m-p/26940#M19677</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi all, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm hoping someone can assist. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can't enable the Forward Trust option for a cert that I generate using either a self-signed CA or 3rd party CA.&amp;nbsp; The check is either greyed out or it's an option but doesn't keep the check after I hit OK. Any idea on how to get this working?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Feb 2015 17:09:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/enabling-forward-trust-certificate/m-p/26940#M19677</guid>
      <dc:creator>Dmaurice-nci</dc:creator>
      <dc:date>2015-02-05T17:09:18Z</dc:date>
    </item>
    <item>
      <title>Re: Enabling forward trust certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/enabling-forward-trust-certificate/m-p/26941#M19678</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please look into this discussion threat, it might help you: &lt;A href="https://live.paloaltonetworks.com/message/45688"&gt;Re: Can not check Forward Trust Certificate&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Feb 2015 17:50:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/enabling-forward-trust-certificate/m-p/26941#M19678</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2015-02-05T17:50:01Z</dc:date>
    </item>
    <item>
      <title>Re: Enabling forward trust certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/enabling-forward-trust-certificate/m-p/26942#M19679</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;For 3rd Party CA, it will allow you to do that. That option would be greyed out.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For self sign CA, you will need to follow following steps :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Under Device -&amp;gt; Certificate Management -&amp;gt; Certificates click Generate Certificate, give it appropriate Name and common Name then click on Certificate Authority&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="cert1.JPG" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/18177_cert1.JPG" style="height: 395px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Click OK.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Once the certificate is created, you should see both CA and Key option checked. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="cert2.JPG" class="image-1 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/18178_cert2.JPG" style="height: 94px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Verify that is the case. Then click on certificate, you should have Both Forward Trust and Forward Untrust option to check. Hope this helps. Thank you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Feb 2015 18:15:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/enabling-forward-trust-certificate/m-p/26942#M19679</guid>
      <dc:creator>ssharma</dc:creator>
      <dc:date>2015-02-05T18:15:11Z</dc:date>
    </item>
    <item>
      <title>Re: Enabling forward trust certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/enabling-forward-trust-certificate/m-p/26943#M19680</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks hulk. I've tried these suggestions already and no luck. Even when I use a self-signed CA, I don't have the ability to enable Forward Trust Certificate...the box is greyed out. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Feb 2015 18:26:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/enabling-forward-trust-certificate/m-p/26943#M19680</guid>
      <dc:creator>Dmaurice-nci</dc:creator>
      <dc:date>2015-02-05T18:26:59Z</dc:date>
    </item>
    <item>
      <title>Re: Enabling forward trust certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/enabling-forward-trust-certificate/m-p/26944#M19681</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks ssharma. I've tried these steps and still no luck. I'm on the phone with PAN support now. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Feb 2015 18:39:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/enabling-forward-trust-certificate/m-p/26944#M19681</guid>
      <dc:creator>Dmaurice-nci</dc:creator>
      <dc:date>2015-02-05T18:39:58Z</dc:date>
    </item>
    <item>
      <title>Re: Enabling forward trust certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/enabling-forward-trust-certificate/m-p/26945#M19682</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi guys, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've found out what the problem was. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When using multiple virtual systems, if the Location drop-down menu under Device Certificates is set to "Shared", I am able to reproduce the problem where I can check the checkbox for Forward Trust Certificate, click OK, but then the check disappears. When I select a specific virtual system, I can see that the Forward Trust Certificate is checked and I can also remove the check. So the key is to be in an actual virtual context when enabling or disabling the Forward Trust Certificate option, rather than be in the shared context.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The WebUI is misleading because under the shared context, the Forward Trust Certificate checkbox displays as an option and can be checked, but since the check disappears after clicking OK, it gives the impression that the feature is not enabled. The logs even show that the option was set successfully in the config logs. The WebUI should be updated to let the user know that the option should only be enabled under the appropriate virtual context. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PA support also didn't know about this behaviour and they mentioned that they'll be writing a KB article to document it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Feb 2015 19:25:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/enabling-forward-trust-certificate/m-p/26945#M19682</guid>
      <dc:creator>Dmaurice-nci</dc:creator>
      <dc:date>2015-02-05T19:25:36Z</dc:date>
    </item>
  </channel>
</rss>

