<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSL Decryption -  Firefox error: &amp;quot;sec_error_reused_issuer_and_serial&amp;quot; in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-firefox-error-quot-sec-error-reused-issuer-and/m-p/3299#M2462</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;
&lt;P&gt;"Do not use a trusted certificate with the option "forward trusted certificate".&lt;/P&gt;

&lt;/PRE&gt;&lt;P&gt;Sorry I didn't really understand.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You mean "Do not use a trusted certificate with the option "forward &lt;STRONG style="text-decoration: underline;"&gt;&lt;EM&gt;un&lt;/EM&gt;&lt;/STRONG&gt;trusted certificate"?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="13080" alt="" class="jiveImage" height="71" src="https://live.paloaltonetworks.com/legacyfs/online/13080_pastedImage_5.png" style="width: 1100.5px; height: 71px;" width="1101" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 24 Apr 2014 12:22:29 GMT</pubDate>
    <dc:creator>ITSama</dc:creator>
    <dc:date>2014-04-24T12:22:29Z</dc:date>
    <item>
      <title>SSL Decryption -  Firefox error: "sec_error_reused_issuer_and_serial"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-firefox-error-quot-sec-error-reused-issuer-and/m-p/3295#M2458</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;After turning on the SSL-Decryption, firefox tells me every moring after restart this error&amp;nbsp; "sec_error_reused_issuer_and_serial", after deleleting the whole history and a restart of firefox it works, but that workaround every morning couldn't be the solution.&lt;/P&gt;&lt;P&gt;Anybody some &lt;SPAN class="hps"&gt;suggestions??&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="hps"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="hps"&gt;thx&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Apr 2014 05:42:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-firefox-error-quot-sec-error-reused-issuer-and/m-p/3295#M2458</guid>
      <dc:creator>ITSama</dc:creator>
      <dc:date>2014-04-24T05:42:54Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption -  Firefox error: "sec_error_reused_issuer_and_serial"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-firefox-error-quot-sec-error-reused-issuer-and/m-p/3296#M2459</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;when you get this message? when open any https websites or open the PA-WebGui?&lt;/P&gt;&lt;P&gt;if you get it with any https websites, please check the Trusted and Untrusted Certificates. Take a look:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="ssl-certs.png" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/13067_ssl-certs.png" style="width: 620px; height: 51px;" /&gt;&lt;/P&gt;&lt;P&gt;The Certificates are generated all from PA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;gateway.example.com = DNS entry with the IP of your internet breakout&amp;nbsp; at your PA&lt;/P&gt;&lt;P&gt;pa-webgui.example.com = DNS entry with the IP of your MGT from your PA&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Export the RootCA certificate and import it in your firefox. And if you having more PAs with the same RootCA and WebGui certificates generated from you will always get the problem with FF when opening the WebGui. Try Chrome or IE.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Apr 2014 07:54:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-firefox-error-quot-sec-error-reused-issuer-and/m-p/3296#M2459</guid>
      <dc:creator>Hithead</dc:creator>
      <dc:date>2014-04-24T07:54:58Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption -  Firefox error: "sec_error_reused_issuer_and_serial"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-firefox-error-quot-sec-error-reused-issuer-and/m-p/3297#M2460</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Hithead,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i had only one certificate for all purposes signed as a Subordinate-CA from my Organisation-CA???&amp;nbsp; IE has no problems with that, only FF.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="jiveImage" src="https://live.paloaltonetworks.com/legacyfs/online/13078_pastedImage_0.png" style="max-width: 1200px; max-height: 900px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Apr 2014 11:06:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-firefox-error-quot-sec-error-reused-issuer-and/m-p/3297#M2460</guid>
      <dc:creator>ITSama</dc:creator>
      <dc:date>2014-04-24T11:06:21Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption -  Firefox error: "sec_error_reused_issuer_and_serial"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-firefox-error-quot-sec-error-reused-issuer-and/m-p/3298#M2461</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;FF has a problem with it. FF call it a "security feature" and IE ignore the&amp;nbsp; usage of the same CA on different sites. Difficult to explain.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But by the way: Do not use a trusted certificate with the option "forward trusted certificate". If a page is recognized as untrusted by the PA, the user will not be promoted with a certificate error. It will trust it. Generate a new certificate with PA, with the same values but do not choose an issuer (signed by) and select the usage "untrusted Certificate" for it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Apr 2014 11:46:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-firefox-error-quot-sec-error-reused-issuer-and/m-p/3298#M2461</guid>
      <dc:creator>Hithead</dc:creator>
      <dc:date>2014-04-24T11:46:34Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption -  Firefox error: "sec_error_reused_issuer_and_serial"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-firefox-error-quot-sec-error-reused-issuer-and/m-p/3299#M2462</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;
&lt;P&gt;"Do not use a trusted certificate with the option "forward trusted certificate".&lt;/P&gt;

&lt;/PRE&gt;&lt;P&gt;Sorry I didn't really understand.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You mean "Do not use a trusted certificate with the option "forward &lt;STRONG style="text-decoration: underline;"&gt;&lt;EM&gt;un&lt;/EM&gt;&lt;/STRONG&gt;trusted certificate"?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="13080" alt="" class="jiveImage" height="71" src="https://live.paloaltonetworks.com/legacyfs/online/13080_pastedImage_5.png" style="width: 1100.5px; height: 71px;" width="1101" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Apr 2014 12:22:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-firefox-error-quot-sec-error-reused-issuer-and/m-p/3299#M2462</guid>
      <dc:creator>ITSama</dc:creator>
      <dc:date>2014-04-24T12:22:29Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption -  Firefox error: "sec_error_reused_issuer_and_serial"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-firefox-error-quot-sec-error-reused-issuer-and/m-p/3300#M2463</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;oh, you are right &lt;span class="lia-unicode-emoji" title=":grinning_face_with_big_eyes:"&gt;😃&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I mean untrusted &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Apr 2014 12:40:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-firefox-error-quot-sec-error-reused-issuer-and/m-p/3300#M2463</guid>
      <dc:creator>Hithead</dc:creator>
      <dc:date>2014-04-24T12:40:18Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption -  Firefox error: "sec_error_reused_issuer_and_serial"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-firefox-error-quot-sec-error-reused-issuer-and/m-p/3301#M2464</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Okay :smileygrin:.&amp;nbsp; I have tested it and it looks good with the untrusted certificates.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And for the "security feature" in FF, i will look for a workaround &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But I have one more question: Do you mean it's useful to work with OCSP-Responder or CRL-Lists? Any Ideas or best practice, because there are different meanings about that?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="jiveImage" src="https://live.paloaltonetworks.com/legacyfs/online/13081_pastedImage_2.png" style="max-width: 1200px; max-height: 900px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Apr 2014 14:02:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-firefox-error-quot-sec-error-reused-issuer-and/m-p/3301#M2464</guid>
      <dc:creator>ITSama</dc:creator>
      <dc:date>2014-04-24T14:02:55Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption -  Firefox error: "sec_error_reused_issuer_and_serial"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-firefox-error-quot-sec-error-reused-issuer-and/m-p/3302#M2465</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;we don't activated that, because of a bug. But we will enable it soon again (with 6.0.2). Only crl . After enable it, you have to check the system logs, if your PA can download the crl .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BTW: read this &lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/thread/8984"&gt;https://live.paloaltonetworks.com/thread/8984&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Apr 2014 08:16:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-firefox-error-quot-sec-error-reused-issuer-and/m-p/3302#M2465</guid>
      <dc:creator>Hithead</dc:creator>
      <dc:date>2014-04-25T08:16:58Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption -  Firefox error: "sec_error_reused_issuer_and_serial"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-firefox-error-quot-sec-error-reused-issuer-and/m-p/3303#M2466</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This has been fixed in 6.0.2 which has been released yesterday.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Apr 2014 08:31:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-firefox-error-quot-sec-error-reused-issuer-and/m-p/3303#M2466</guid>
      <dc:creator>gafrol</dc:creator>
      <dc:date>2014-04-25T08:31:24Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption -  Firefox error: "sec_error_reused_issuer_and_serial"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-firefox-error-quot-sec-error-reused-issuer-and/m-p/3304#M2467</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi again,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;okay i will test the OCSP with the new PAN-OS Version soon, but now I have another problem with the selfsigned certificate for the untrusted Certificates, because I get many certificate errors because the most intermediate CA's are not in the default trusted certificate list on the PA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So what is the best way to solve the problem. It seems to be a little bit difficult to import all possible certificates for the Sub-CA's??&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Apr 2014 08:49:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-firefox-error-quot-sec-error-reused-issuer-and/m-p/3304#M2467</guid>
      <dc:creator>ITSama</dc:creator>
      <dc:date>2014-04-28T08:49:49Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption -  Firefox error: "sec_error_reused_issuer_and_serial"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-firefox-error-quot-sec-error-reused-issuer-and/m-p/3305#M2468</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;check your system and traffic logs (traffic logs from your MGT IP of PA). may you will find the some information what cannot be downloaded. Allow your PA to download the resources. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 May 2014 13:53:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-firefox-error-quot-sec-error-reused-issuer-and/m-p/3305#M2468</guid>
      <dc:creator>Hithead</dc:creator>
      <dc:date>2014-05-09T13:53:53Z</dc:date>
    </item>
  </channel>
</rss>

