<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SSL Decryption Fails: sec_error_reused_issuer_and_serial in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-fails-sec-error-reused-issuer-and-serial/m-p/33813#M24809</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In the newest PA-OS 3.1.2 seems to be a problem with the Proxy-Certificate.&lt;/P&gt;&lt;P&gt;If browsing with Firefox, you get "Errocode: sec_error_reused_issuer_and_serial" on all HTTPS-Sites, if you have implented the proxy certificate in the certificat store (and if not, you can surf without problems after click on "ignore security warning"). With Opera, SSL-Connections fails with a "white window", whether you have installed the proxy certificate in the browser certificate store or not.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 02 Jun 2010 10:54:42 GMT</pubDate>
    <dc:creator>mhuels</dc:creator>
    <dc:date>2010-06-02T10:54:42Z</dc:date>
    <item>
      <title>SSL Decryption Fails: sec_error_reused_issuer_and_serial</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-fails-sec-error-reused-issuer-and-serial/m-p/33813#M24809</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In the newest PA-OS 3.1.2 seems to be a problem with the Proxy-Certificate.&lt;/P&gt;&lt;P&gt;If browsing with Firefox, you get "Errocode: sec_error_reused_issuer_and_serial" on all HTTPS-Sites, if you have implented the proxy certificate in the certificat store (and if not, you can surf without problems after click on "ignore security warning"). With Opera, SSL-Connections fails with a "white window", whether you have installed the proxy certificate in the browser certificate store or not.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Jun 2010 10:54:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-fails-sec-error-reused-issuer-and-serial/m-p/33813#M24809</guid>
      <dc:creator>mhuels</dc:creator>
      <dc:date>2010-06-02T10:54:42Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption Fails: sec_error_reused_issuer_and_serial</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-fails-sec-error-reused-issuer-and-serial/m-p/33814#M24810</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please open a case with Support.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Jun 2010 11:13:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-fails-sec-error-reused-issuer-and-serial/m-p/33814#M24810</guid>
      <dc:creator>tabner</dc:creator>
      <dc:date>2010-06-02T11:13:55Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption Fails: sec_error_reused_issuer_and_serial</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-fails-sec-error-reused-issuer-and-serial/m-p/33815#M24811</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We did so some days before. But till now, we got no answer.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Jun 2010 16:19:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-fails-sec-error-reused-issuer-and-serial/m-p/33815#M24811</guid>
      <dc:creator>mhuels</dc:creator>
      <dc:date>2010-06-02T16:19:31Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption Fails: sec_error_reused_issuer_and_serial</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-fails-sec-error-reused-issuer-and-serial/m-p/33816#M24812</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; I believe your SE opened a case regarding this issue yesterday.&amp;nbsp; He has been working with Support so you may want to get in touch with him.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Jun 2010 20:27:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-fails-sec-error-reused-issuer-and-serial/m-p/33816#M24812</guid>
      <dc:creator>nrice</dc:creator>
      <dc:date>2010-06-02T20:27:20Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption Fails: sec_error_reused_issuer_and_serial</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-fails-sec-error-reused-issuer-and-serial/m-p/33817#M24813</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, our SE started a support case. Unfortunenately, we got no solution but only a workaround, which did not work. PA recommended to reimport the PA Certificate through the Firefox security warning dialogue. Otherwise we have to wait on version 3.1.3, which "maybe" helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 04 Jun 2010 10:00:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-fails-sec-error-reused-issuer-and-serial/m-p/33817#M24813</guid>
      <dc:creator>mhuels</dc:creator>
      <dc:date>2010-06-04T10:00:09Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption Fails: sec_error_reused_issuer_and_serial</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-fails-sec-error-reused-issuer-and-serial/m-p/33818#M24814</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;A procedrue for exporting/importing the certificate from/to Firefox can be found at the following link.&amp;nbsp; It did work in our lab.&lt;/P&gt;&lt;P&gt;(outdated link removed)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 04 Jun 2010 23:11:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-fails-sec-error-reused-issuer-and-serial/m-p/33818#M24814</guid>
      <dc:creator>nrice</dc:creator>
      <dc:date>2010-06-04T23:11:14Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption Fails: sec_error_reused_issuer_and_serial</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-fails-sec-error-reused-issuer-and-serial/m-p/33819#M24815</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This workaround does not works in our environment.&lt;/P&gt;&lt;P&gt;First we dont see a certificate hierarchy in the firefox but only the solitary certificate from the HTTPs Server.&lt;/P&gt;&lt;P&gt;Second we cannot import the server key as a CA key. Firefox says: "this is not a certificate from a certificate authority ...". Please have a look at the gif-attachement.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I assume, we have another problem with our certificate. We tried first to generate the certificate with the appliance software, just now we use an imported certificate, build with openssl.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Our two 2050 appliances works in a high availability mode.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Jun 2010 16:16:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-fails-sec-error-reused-issuer-and-serial/m-p/33819#M24815</guid>
      <dc:creator>mhuels</dc:creator>
      <dc:date>2010-06-07T16:16:52Z</dc:date>
    </item>
  </channel>
</rss>

