<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Decryption certificate in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/decryption-certificate/m-p/39499#M28982</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have a PA500 (OS 5.0.11)&lt;/P&gt;&lt;P&gt;I already configured it for SSL Decryption with a self signed certificate.&lt;/P&gt;&lt;P&gt;I need to use a Digicert Certificate. I already have a wildcard certificate with Digicert.&lt;/P&gt;&lt;P&gt;Question is: can I use my wildcard certificate for SSL Decryption?&lt;/P&gt;&lt;P&gt;How?&lt;/P&gt;&lt;P&gt;I try to import my certificate but I cannot use it for SSL Decryption&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-0 jiveImage" src="https://live.paloaltonetworks.com/legacyfs/online/14120_pastedImage_0.png" style="max-width: 1200px; max-height: 900px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 25 Jun 2014 14:58:08 GMT</pubDate>
    <dc:creator>diennea</dc:creator>
    <dc:date>2014-06-25T14:58:08Z</dc:date>
    <item>
      <title>Decryption certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/decryption-certificate/m-p/39499#M28982</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have a PA500 (OS 5.0.11)&lt;/P&gt;&lt;P&gt;I already configured it for SSL Decryption with a self signed certificate.&lt;/P&gt;&lt;P&gt;I need to use a Digicert Certificate. I already have a wildcard certificate with Digicert.&lt;/P&gt;&lt;P&gt;Question is: can I use my wildcard certificate for SSL Decryption?&lt;/P&gt;&lt;P&gt;How?&lt;/P&gt;&lt;P&gt;I try to import my certificate but I cannot use it for SSL Decryption&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-0 jiveImage" src="https://live.paloaltonetworks.com/legacyfs/online/14120_pastedImage_0.png" style="max-width: 1200px; max-height: 900px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Jun 2014 14:58:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/decryption-certificate/m-p/39499#M28982</guid>
      <dc:creator>diennea</dc:creator>
      <dc:date>2014-06-25T14:58:08Z</dc:date>
    </item>
    <item>
      <title>Re: Decryption certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/decryption-certificate/m-p/39500#M28983</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi !&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For SSL decryption you'll need a CA certificate as it will be posing as the signing certificate of the websites the users are accessing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A document that may come in handy&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-1412"&gt;How to Implement SSL Decryption&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;Tom&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Jun 2014 15:03:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/decryption-certificate/m-p/39500#M28983</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2014-06-25T15:03:02Z</dc:date>
    </item>
    <item>
      <title>Re: Decryption certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/decryption-certificate/m-p/39501#M28984</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks but in case of a Certification Authority like Verisign or Digicert I need to request a new certificate (signed by them) or I need to import a root certificate?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Jun 2014 15:26:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/decryption-certificate/m-p/39501#M28984</guid>
      <dc:creator>diennea</dc:creator>
      <dc:date>2014-06-25T15:26:12Z</dc:date>
    </item>
    <item>
      <title>Re: Decryption certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/decryption-certificate/m-p/39502#M28985</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In case of CA like verisign or digicert, you need to import chained certificate signed by the Public CA&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This document is very helpful:&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-4289"&gt;How to Install a Chained Certificate Signed by a Public CA&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Jun 2014 15:31:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/decryption-certificate/m-p/39502#M28985</guid>
      <dc:creator>Mystique</dc:creator>
      <dc:date>2014-06-25T15:31:51Z</dc:date>
    </item>
    <item>
      <title>Re: Decryption certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/decryption-certificate/m-p/39503#M28986</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I follow this guide and I create a pkcs12 chained certificate with this command:&lt;/P&gt;&lt;P&gt;openssl pkcs12 -export -in &lt;EM&gt;[certificate.pem]&lt;/EM&gt; -inkey &lt;EM&gt;[certificate.key]&lt;/EM&gt; -CAfile &lt;EM&gt;[chain.cer]&lt;/EM&gt; -caname digicert -out &lt;EM&gt;[server-chain.p12]&lt;/EM&gt; -name digicert -chain&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but when I import my certificate (IMPORTANT: it is a &lt;STRONG&gt;web server certificate&lt;/STRONG&gt;) it is not recognized as a CA.&lt;/P&gt;&lt;P&gt;I think problem is that my certificate was request for a web server.&lt;/P&gt;&lt;P&gt;If I try to install DigiCert CA root certificate it is recognized as a CA but I cannot use it for decryption.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 Jun 2014 10:26:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/decryption-certificate/m-p/39503#M28986</guid>
      <dc:creator>diennea</dc:creator>
      <dc:date>2014-06-26T10:26:34Z</dc:date>
    </item>
    <item>
      <title>Re: Decryption certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/decryption-certificate/m-p/39504#M28987</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You cannot use a certificate from a public CA like VeriSign or Digicert. A public CA will never give a subordinate (intermediate) CA certificate to someone outside their trust. With a subordinate certificate, you can create new certs that are trusted to the root, even for existing and common sites.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For SSL decryption, you need to use an internal CA certificate or generate a self-signed certificate on the firewall and use that. In both instances, you will need to distribute the public key of that certificate to all clients you wish to be decrypted.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps,&lt;/P&gt;&lt;P&gt;Greg&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 Jun 2014 16:44:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/decryption-certificate/m-p/39504#M28987</guid>
      <dc:creator>gwesson</dc:creator>
      <dc:date>2014-06-26T16:44:33Z</dc:date>
    </item>
  </channel>
</rss>

