<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSL Decryption - warnings during commit in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-warnings-during-commit/m-p/33692#M24731</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I found the following Bug 47565 which is fixed in release 5.0.3. &lt;/P&gt;&lt;P&gt;The release notes state the following &lt;/P&gt;&lt;P&gt;After upgrading to PAN-OS 5.0.x, newly imported certificates that were part of a certificate chain were being stripped of their intermediate certificates, causing the browser to prompt users with a certificate warning.&lt;/P&gt;&lt;P&gt;You might be running into this issue. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 29 Aug 2013 17:30:14 GMT</pubDate>
    <dc:creator>mbutt</dc:creator>
    <dc:date>2013-08-29T17:30:14Z</dc:date>
    <item>
      <title>SSL Decryption - warnings during commit</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-warnings-during-commit/m-p/33689#M24728</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;BR /&gt;I had setup GlobalProtect with a third party certificate that I chained together, and it works fine with no errors.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then, I began testing SSL Decryption yesterday (with an initial goal of decrypting SSL for Facebook so that I could block Facebook games).&amp;nbsp; Upon configuring the Decryption Policy, when going to commit, I receive these warnings:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Warning: certificate chain not correctly formed in certificate GlobalProtect-ServerWarning: certificate chain not correctly formed in certificate GlobalProtect-ServerWarning: vsys1 decryption: forward decrypt untrust cert is not configured, forward decrypt trust cert will be used instead.&lt;/P&gt;&lt;P class="commit_common"&gt;(Module: device)&lt;/P&gt;&lt;P class="commit_common"&gt;Configuration committed successfully&lt;/P&gt;&lt;P class="commit_common"&gt;&lt;/P&gt;&lt;P class="commit_common"&gt;My questions are:&lt;/P&gt;&lt;P class="commit_common"&gt;Why is it now telling me that my chain isn't configured correctly for the cert I'm using with GlobalProtect? &lt;/P&gt;&lt;P class="commit_common"&gt;&lt;/P&gt;&lt;P class="commit_common"&gt;The cert I'm using for SSL Decryption I have only enabled the option of "Forward Trust Certificate", which I am assuming is why I'm seeing the warning about "Forward decrypt untrust cert is not configured, forward decrypt trust cert will be used instead"...but should I enable "Forward Untrust Certificate" on this cert as well?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 May 2013 14:04:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-warnings-during-commit/m-p/33689#M24728</guid>
      <dc:creator>uscit</dc:creator>
      <dc:date>2013-05-07T14:04:00Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption - warnings during commit</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-warnings-during-commit/m-p/33690#M24729</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Well, it appeared that I actually did have the chain wrong on my GP SSL cert (a Godaddy one).&amp;nbsp; I corrected that, and now I don't get an error in the PAN when committing...however if I use openssl or sslToolbox to validate the chain, it's throwing in an extra cert that I did not put in the chain.&amp;nbsp; Openssl says it is a "self-signed certificate in the certificate chain", and this is from sslToolbox below:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Certificate Chain Information&lt;/P&gt;&lt;DIV id="cicResults"&gt;&lt;DIV class="csrInfoRow cf"&gt;&lt;DIV class="property"&gt;Server Name&lt;/DIV&gt;&lt;DIV class="attribute" id="certCNInfo"&gt;&amp;lt;gp portal&amp;gt; was checked using port number 443&lt;DIV class="certRecordField cf"&gt;&lt;DIV class="certFieldValue"&gt;The following issuer is not supported by the certificate installation checker.&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="csrInfoRow cf"&gt;&lt;DIV class="property"&gt;Chain Installation&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV class="certRecord certNum"&gt;&lt;SPAN class="recordTitle"&gt;Certificate 1&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="certRecordField cf"&gt;&lt;DIV class="certFieldName"&gt;Organization&lt;/DIV&gt;&lt;DIV class="certFieldValue"&gt;The Go Daddy Group, Inc.&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="certRecordField cf"&gt;&lt;DIV class="certFieldName"&gt;OU&lt;/DIV&gt;&lt;DIV class="certFieldValue"&gt;Go Daddy Class 2 Certification Authority&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="certRecordField cf"&gt;&lt;DIV class="certFieldName"&gt;Country&lt;/DIV&gt;&lt;DIV class="certFieldValue"&gt;US&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="certRecordField cf"&gt;&lt;DIV class="certFieldName"&gt;Valid From&lt;/DIV&gt;&lt;DIV class="certFieldValue"&gt;Tue Jun 29 13:06:20 EDT 2004&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="certRecordField cf"&gt;&lt;DIV class="certFieldName"&gt;Valid To&lt;/DIV&gt;&lt;DIV class="certFieldValue"&gt;Thu Jun 29 13:06:20 EDT 2034&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="certRecordField cf"&gt;&lt;DIV class="certFieldName"&gt;Serial Number&lt;/DIV&gt;&lt;DIV class="certFieldValue"&gt;0&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="certRecordField cf"&gt;&lt;DIV class="certFieldName"&gt;Signature Algorithm&lt;/DIV&gt;&lt;DIV class="certFieldValue"&gt;SHA1withRSA&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="certFieldValue"&gt; &lt;/DIV&gt;&lt;DIV class="certFieldValue"&gt;I then looked in the PA-500's "Default Trusted Certificate Authorities" and indeed there is one called "The Go Daddy Group, Inc., Go Daddy Class 2 Certification Author".&amp;nbsp; I don't remember seeing this in there before, and I had looked for GoDaddy in this default trusted list?&lt;/DIV&gt;&lt;DIV class="certFieldValue"&gt; &lt;/DIV&gt;&lt;DIV class="certFieldValue"&gt;And for the warning about the untrust cert, I saw the other thread that said to ignore this error.&amp;nbsp; I don't have an untrust cert...if I want to set one up to get rid of the warning, is it any different than the one I use for forward trust?&amp;nbsp; Can I just use that one for both?&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 May 2013 20:33:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-warnings-during-commit/m-p/33690#M24729</guid>
      <dc:creator>uscit</dc:creator>
      <dc:date>2013-05-08T20:33:39Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption - warnings during commit</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-warnings-during-commit/m-p/33691#M24730</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;look here for the same issue - &lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/thread/8554"&gt;https://live.paloaltonetworks.com/thread/8554&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I created "Forward untrust certificate" and commit with no errors. First i use same certificate for both and there was no difference. Good luck &lt;img id="smileywink" class="emoticon emoticon-smileywink" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-wink.png" alt="Smiley Wink" title="Smiley Wink" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Aug 2013 13:36:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-warnings-during-commit/m-p/33691#M24730</guid>
      <dc:creator>Interface</dc:creator>
      <dc:date>2013-08-28T13:36:13Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption - warnings during commit</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-warnings-during-commit/m-p/33692#M24731</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I found the following Bug 47565 which is fixed in release 5.0.3. &lt;/P&gt;&lt;P&gt;The release notes state the following &lt;/P&gt;&lt;P&gt;After upgrading to PAN-OS 5.0.x, newly imported certificates that were part of a certificate chain were being stripped of their intermediate certificates, causing the browser to prompt users with a certificate warning.&lt;/P&gt;&lt;P&gt;You might be running into this issue. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Aug 2013 17:30:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-warnings-during-commit/m-p/33692#M24731</guid>
      <dc:creator>mbutt</dc:creator>
      <dc:date>2013-08-29T17:30:14Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption - warnings during commit</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-warnings-during-commit/m-p/33693#M24732</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The point of the untrust cert is that when PA device fails to setup a proper ssl between itself and the server when using ssl termination there is no way to notify the client about this. So by choosing the untrust towards the client the client will know its bad if the client continue this session.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My advice would be to use two different certs, one for trusted and one for untrusted and place that trusted cert as trusted CA in your browser and the other untrusted cert as untrusted / blacklisted CA in your browser.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Aug 2013 21:08:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-warnings-during-commit/m-p/33693#M24732</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2013-08-30T21:08:03Z</dc:date>
    </item>
  </channel>
</rss>

