<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Installing an Intermediate CA in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/installing-an-intermediate-ca/m-p/28208#M20601</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That did it!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just one thing for clarification for anyone else finding this thread.&amp;nbsp; When you chain the certs, they all go into &amp;lt;public-key&amp;gt;.&amp;nbsp; The don't get their own XML headers.&amp;nbsp; Not sure who'd do that (*uhm...*) but just in case.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 17 Jan 2013 16:03:01 GMT</pubDate>
    <dc:creator>CafNetMatt</dc:creator>
    <dc:date>2013-01-17T16:03:01Z</dc:date>
    <item>
      <title>Installing an Intermediate CA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/installing-an-intermediate-ca/m-p/28200#M20593</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm getting the following error when I perform a commit on a PA-3020.&amp;nbsp; PAN-OS 5.0.1.&amp;nbsp; I know I'm doing something wrong.&amp;nbsp; I'm new to installing certs so feel free to point and laugh.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I had a certificate signed by GoDaddy for use by Global Protect.&amp;nbsp; It came signed by an Intermediate CA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've created a chained certificate to make sure the Intermediate cert goes to the client so no errors occur.&amp;nbsp; The chained cert is installed, shows its signed by the GoDaddy root and when I use GP I do not get any certificate errors.&amp;nbsp; So that part is good.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The chained certificate has the Public Key issued by GoDaddy at the top, the Intermediate cert "Issued To" cert and I imported the private key generated when the CSR was made (CSR created using a Winders server &amp;amp; IIS).&amp;nbsp; I didn't know what to do with the "Issued By" portion of the Intermediate cert &amp;amp; the chaining document I found in the PAN forums didn't mention it so it didn't get used in the chained cert.&amp;nbsp; If this is wrong let me know.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem is I get an error on the PAN every time I commit:&amp;nbsp; "vsys1:&amp;nbsp; Warning:&amp;nbsp; can't find complete cert chain for &amp;lt;imported_cert_name&amp;gt;".&amp;nbsp; I think the problem is that I did not import the Intermediate certificate before importing the chained certificate.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here's my ignorant question:&amp;nbsp; How do I import the Intermediate cert?&amp;nbsp; The intermediate cert has two certs in it:&amp;nbsp; The "Issued To" cert and the "Issued By" cert.&amp;nbsp; When I import the PEM, is the "Issued By" considered the private key (checking 'Import Private Key')?&amp;nbsp; Or, do I just leave both "Issued To" &amp;amp; "Issued By" certs together in the PEM file &amp;amp; import it without checking 'Import Private Key'?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've gone through pretty much all the PAN docs I can find and I get the impression that this bit of knowledge is considered "a given" that the user knows how to do it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Again, feel free to laugh; it's how I learn.&amp;nbsp; Appreciate the help in filling this knowledge gap.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Jan 2013 16:07:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/installing-an-intermediate-ca/m-p/28200#M20593</guid>
      <dc:creator>CafNetMatt</dc:creator>
      <dc:date>2013-01-15T16:07:11Z</dc:date>
    </item>
    <item>
      <title>Re: Installing an Intermediate CA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/installing-an-intermediate-ca/m-p/28201#M20594</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi...Maybe this post will help &lt;A __default_attr="3288" __jive_macro_name="message" class="jive_macro jive_macro_message" href="https://live.paloaltonetworks.com/"&gt;&lt;/A&gt;.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Jan 2013 22:28:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/installing-an-intermediate-ca/m-p/28201#M20594</guid>
      <dc:creator>rmonvon</dc:creator>
      <dc:date>2013-01-15T22:28:48Z</dc:date>
    </item>
    <item>
      <title>Re: Installing an Intermediate CA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/installing-an-intermediate-ca/m-p/28202#M20595</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This document walks you through the process of chaining the certificates:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A __default_attr="4289" __jive_macro_name="document" class="jive_macro jive_macro_document" href="https://live.paloaltonetworks.com/"&gt;&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Jan 2013 00:14:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/installing-an-intermediate-ca/m-p/28202#M20595</guid>
      <dc:creator>zarina</dc:creator>
      <dc:date>2013-01-16T00:14:28Z</dc:date>
    </item>
    <item>
      <title>Re: Installing an Intermediate CA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/installing-an-intermediate-ca/m-p/28203#M20596</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Read that post and I just did it.&amp;nbsp; This was a slightly different instruction from the document on chaining or at least the suggestion was clearer.&amp;nbsp; I took everything in the bundle from GoDaddy and pasted it to the bottom of the server cert.&amp;nbsp; It imports fine, shows the issuer being Go Daddy Secure Certification Authority but once I link it to the GP Gateway and GP Portal and commit, I get the same error.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Jan 2013 05:28:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/installing-an-intermediate-ca/m-p/28203#M20596</guid>
      <dc:creator>CafNetMatt</dc:creator>
      <dc:date>2013-01-16T05:28:11Z</dc:date>
    </item>
    <item>
      <title>Re: Installing an Intermediate CA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/installing-an-intermediate-ca/m-p/28204#M20597</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That's the document I originally went off of.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I understand this correctly, if you chain the certificates then you do not need to import the Intermediate CA to the PA separately.&amp;nbsp; Correct?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Jan 2013 05:30:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/installing-an-intermediate-ca/m-p/28204#M20597</guid>
      <dc:creator>CafNetMatt</dc:creator>
      <dc:date>2013-01-16T05:30:18Z</dc:date>
    </item>
    <item>
      <title>Re: Installing an Intermediate CA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/installing-an-intermediate-ca/m-p/28205#M20598</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;From my workstation, I issued 'openssl s_client -showcerts -connect client.url.com:443&lt;/P&gt;&lt;P&gt;The interesting thing is I don't get a certificate error on my machine when I connect and never had (meaning I didn't tell GP to install an invalid certificate).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is the output:&lt;/P&gt;&lt;P&gt;CONNECTED(00000003)&lt;/P&gt;&lt;P&gt;depth=0 /O=client.url.com/OU=Domain Control Validated/CN=client.url.com&lt;/P&gt;&lt;P&gt;verify error:num=20:unable to get local issuer certificate&lt;/P&gt;&lt;P&gt;verify return:1&lt;/P&gt;&lt;P&gt;depth=0 /O=client.url.com/OU=Domain Control Validated/CN=client.url.com&lt;/P&gt;&lt;P&gt;verify error:num=27:certificate not trusted&lt;/P&gt;&lt;P&gt;verify return:1&lt;/P&gt;&lt;P&gt;depth=0 /O=client.url.com/OU=Domain Control Validated/CN=client.url.com&lt;/P&gt;&lt;P&gt;verify error:num=21:unable to verify the first certificate&lt;/P&gt;&lt;P&gt;verify return:1&lt;/P&gt;&lt;P&gt;---&lt;/P&gt;&lt;P&gt;Certificate chain&lt;/P&gt;&lt;P&gt;0 s:/O=client.url.com/OU=Domain Control Validated/CN=client.url.com&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp; i:/C=US/ST=Arizona/L=Scottsdale/O=GoDaddy.com, Inc./OU=&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://certificates.godaddy.com/repository/CN=Go"&gt;http://certificates.godaddy.com/repository/CN=Go&lt;/A&gt;&lt;SPAN&gt; Daddy Secure Certifi7&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;-----BEGIN CERTIFICATE-----&lt;/P&gt;&lt;P&gt;&amp;lt;blah, blah, blah&amp;gt;&lt;/P&gt;&lt;P&gt;-----END CERTIFICATE-----&lt;/P&gt;&lt;P&gt;---&lt;/P&gt;&lt;P&gt;Server certificate&lt;/P&gt;&lt;P&gt;subject=/O=client.url.com/OU=Domain Control Validated/CN=client.url.com&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;issuer=/C=US/ST=Arizona/L=Scottsdale/O=GoDaddy.com, Inc./OU=&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://certificates.godaddy.com/repository/CN=Go"&gt;http://certificates.godaddy.com/repository/CN=Go&lt;/A&gt;&lt;SPAN&gt; Daddy Secure Certi7&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;---&lt;/P&gt;&lt;P&gt;No client certificate CA names sent&lt;/P&gt;&lt;P&gt;---&lt;/P&gt;&lt;P&gt;SSL handshake has read 1541 bytes and written 456 bytes&lt;/P&gt;&lt;P&gt;---&lt;/P&gt;&lt;P&gt;New, TLSv1/SSLv3, Cipher is AES256-SHA&lt;/P&gt;&lt;P&gt;Server public key is 2048 bit&lt;/P&gt;&lt;P&gt;Secure Renegotiation IS NOT supported&lt;/P&gt;&lt;P&gt;Compression: NONE&lt;/P&gt;&lt;P&gt;Expansion: NONE&lt;/P&gt;&lt;P&gt;SSL-Session:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Protocol&amp;nbsp; : TLSv1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Cipher&amp;nbsp;&amp;nbsp;&amp;nbsp; : AES256-SHA&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Session-ID: 79F6EAE72AE214E143C7BF7D4A84D64334154BD419F6E73701547B6E6B079240&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Session-ID-ctx:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Master-Key: 06FCC6E59888670B44C2451B831246D9D2FFEFA0AAB3541C7DAC4A45F9AFE4727F9E57647AD0624671FC076C07DE6194&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Key-Arg&amp;nbsp;&amp;nbsp; : None&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Start Time: 1358315077&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Timeout&amp;nbsp;&amp;nbsp; : 300 (sec)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Verify return code: 21 (unable to verify the first certificate)&lt;/P&gt;&lt;P&gt;---&lt;/P&gt;&lt;P&gt;read:errno=0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Finally, I checked the keychain on my Mac and the server certificate is showing valid.&amp;nbsp; So, I'm kinda stumped.&amp;nbsp; I've seen another post where someone was having an issue with a GoDaddy certificate and not with a cert from another issuer.&amp;nbsp; I've used namecheap without an issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks everyone for the help.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Jan 2013 05:52:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/installing-an-intermediate-ca/m-p/28205#M20598</guid>
      <dc:creator>CafNetMatt</dc:creator>
      <dc:date>2013-01-16T05:52:05Z</dc:date>
    </item>
    <item>
      <title>Re: Installing an Intermediate CA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/installing-an-intermediate-ca/m-p/28206#M20599</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I've gone to the GoDaddy cert repository and downloaded the Intermediate and Root certs and verified them against the certs I was given.&amp;nbsp; They all match so I don't see why I'm receiving this commit error.&amp;nbsp; The server&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Following the instructions from the link in rmonvon's posting, the chained cert includes the server cert, the intermediate cert and the root cert.&amp;nbsp; I've also tried:&lt;/P&gt;&lt;P&gt;1) chaining the intermediate cert:&amp;nbsp; same error on commit&lt;/P&gt;&lt;P&gt;2) just using the server cert by itself&lt;/P&gt;&lt;P&gt;3) importing the intermediate cert then the server cert separately:&amp;nbsp; This shows the server cert being authorized by the intermediate cert.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The only thing I haven't done is export the GoDaddy root CA from the PAN.&amp;nbsp; It won't let me so i can't compare that certificate to the one in the gd_bundle.crt.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Jan 2013 21:50:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/installing-an-intermediate-ca/m-p/28206#M20599</guid>
      <dc:creator>CafNetMatt</dc:creator>
      <dc:date>2013-01-16T21:50:00Z</dc:date>
    </item>
    <item>
      <title>Re: Installing an Intermediate CA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/installing-an-intermediate-ca/m-p/28207#M20600</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have noticed an similar/same issue on 5.0. I think there is a bug in 5.0. Seems like the GUI filters out everything after the server certificate when doing an import.&lt;/P&gt;&lt;P&gt;I have already created a case with support #&lt;SPAN style="color: #333333; font-family: Arial, Helvetica, sans-serif; font-size: 11px; background-color: #ffffff;"&gt;00112405&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The workaround for me to "fix" the problem is to manually edit the configuration file. Export -&amp;gt; Edit in textpad/xml editor or similar and then paste the server certificate with Intermediate certificate.&lt;/P&gt;&lt;P&gt;After importing the changed configuration file and then commit the problem is solved and if you look at the configuration file the certificate with all intermediates are included:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jo Christian&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; font-family: Arial, Helvetica, sans-serif; font-size: 11px; background-color: #ecf3ea;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Jan 2013 12:20:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/installing-an-intermediate-ca/m-p/28207#M20600</guid>
      <dc:creator>jochristian</dc:creator>
      <dc:date>2013-01-17T12:20:30Z</dc:date>
    </item>
    <item>
      <title>Re: Installing an Intermediate CA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/installing-an-intermediate-ca/m-p/28208#M20601</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That did it!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just one thing for clarification for anyone else finding this thread.&amp;nbsp; When you chain the certs, they all go into &amp;lt;public-key&amp;gt;.&amp;nbsp; The don't get their own XML headers.&amp;nbsp; Not sure who'd do that (*uhm...*) but just in case.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Jan 2013 16:03:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/installing-an-intermediate-ca/m-p/28208#M20601</guid>
      <dc:creator>CafNetMatt</dc:creator>
      <dc:date>2013-01-17T16:03:01Z</dc:date>
    </item>
    <item>
      <title>Re: Installing an Intermediate CA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/installing-an-intermediate-ca/m-p/28209#M20602</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just checked the release notes for 5.0.2.&amp;nbsp; Looks like this didn't make it in.&amp;nbsp; This problem was probably just too new.&amp;nbsp; Next release hopefully.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Jan 2013 21:08:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/installing-an-intermediate-ca/m-p/28209#M20602</guid>
      <dc:creator>CafNetMatt</dc:creator>
      <dc:date>2013-01-17T21:08:51Z</dc:date>
    </item>
    <item>
      <title>Re: Installing an Intermediate CA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/installing-an-intermediate-ca/m-p/28210#M20603</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes that is correct. This is a case that is still ongoing, I opened it last week.&lt;/P&gt;&lt;P&gt;But what you could do is to open a case yourself or contact your SE and refer to the problem that you had and my case &lt;SPAN style="line-height: 1.5em; color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;#&lt;/SPAN&gt;&lt;SPAN style="line-height: 1.5em; font-size: 11px; font-family: Arial, Helvetica, sans-serif; color: #333333; background-color: #ffffff;"&gt;00112405.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jo Christian&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Jan 2013 10:54:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/installing-an-intermediate-ca/m-p/28210#M20603</guid>
      <dc:creator>jochristian</dc:creator>
      <dc:date>2013-01-18T10:54:39Z</dc:date>
    </item>
  </channel>
</rss>

