<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Security Certificate Error in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/security-certificate-error/m-p/40491#M29734</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We've had a few instances where we are on websites, the one I have witnessed is simply cnn.com, and then while I am browsing I'll suddenly get a certificate error well after the page is loaded that is generated by the PA-500 unit.&amp;nbsp; I did not see this on the eval unit which was running 3.1.1, our purchased unit is running 3.1.2.&amp;nbsp; Has anybody else seen anything like this?&amp;nbsp; I had a call from a staff member a few minutes ago that it happened to them while on virginiapreps.rivals.com.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for any tips.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 03 Jun 2010 13:27:45 GMT</pubDate>
    <dc:creator>kevin.shain</dc:creator>
    <dc:date>2010-06-03T13:27:45Z</dc:date>
    <item>
      <title>Security Certificate Error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-certificate-error/m-p/40491#M29734</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We've had a few instances where we are on websites, the one I have witnessed is simply cnn.com, and then while I am browsing I'll suddenly get a certificate error well after the page is loaded that is generated by the PA-500 unit.&amp;nbsp; I did not see this on the eval unit which was running 3.1.1, our purchased unit is running 3.1.2.&amp;nbsp; Has anybody else seen anything like this?&amp;nbsp; I had a call from a staff member a few minutes ago that it happened to them while on virginiapreps.rivals.com.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for any tips.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Jun 2010 13:27:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-certificate-error/m-p/40491#M29734</guid>
      <dc:creator>kevin.shain</dc:creator>
      <dc:date>2010-06-03T13:27:45Z</dc:date>
    </item>
    <item>
      <title>Re: Security Certificate Error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-certificate-error/m-p/40492#M29735</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Kevin,&lt;/P&gt;&lt;P&gt;the Paloalto device will not randomly insert a certificate error while the user is browsing.&lt;/P&gt;&lt;P&gt;However if the paloalto device is configured for ssl decryption and the user goes to an ssl site, you will get a certificate error . In this scenario you would need to import the ssl decrypt certificate from the paloalto device into the user's browser.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Stephen&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Jun 2010 20:14:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-certificate-error/m-p/40492#M29735</guid>
      <dc:creator>swhyte</dc:creator>
      <dc:date>2010-06-03T20:14:11Z</dc:date>
    </item>
    <item>
      <title>Re: Security Certificate Error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-certificate-error/m-p/40493#M29736</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have no SSL Decryption Policies set.&amp;nbsp; Is there somewhere else I need to disable this from? &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 04 Jun 2010 13:24:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-certificate-error/m-p/40493#M29736</guid>
      <dc:creator>kevin.shain</dc:creator>
      <dc:date>2010-06-04T13:24:25Z</dc:date>
    </item>
    <item>
      <title>Re: Security Certificate Error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-certificate-error/m-p/40494#M29737</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We have also problems with SSL-Sites since 3.1.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Some sites - like gmail.com - with ssl encryption won't load after login. &lt;/P&gt;&lt;P&gt;We also have no SSL-Decryption-Policy. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In a packet-trace i can see that the client sends packets to the Google serverfarm and don't get any answer. After a few time I can see TCP-Resets sent from the PaloAlto-MAC-Address. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the Traffic Logs I see the packets passing to the outside but never the server response. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have two implementations - one for the company employees and one for guests.&lt;/P&gt;&lt;P&gt;We have a PA-2050 acting as an L3-Internet-Router with IPS-Functionality.&lt;/P&gt;&lt;P&gt;Behind the PA-2050 there is one Cisco ASA5040 with a PAT configured for out employees.&lt;/P&gt;&lt;P&gt;In parallel we have implemented two additional ports of the PA-2050 for firewalling/routing/PAT where the guests are placed within a seperate LAN-Infrastructure.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the productive LAN we don't see any problems with SSL-Sites.&lt;/P&gt;&lt;P&gt;The problems are only located at the guest-environment.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Sep 2010 09:04:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-certificate-error/m-p/40494#M29737</guid>
      <dc:creator>wko</dc:creator>
      <dc:date>2010-09-16T09:04:26Z</dc:date>
    </item>
    <item>
      <title>Re: Security Certificate Error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-certificate-error/m-p/40495#M29738</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You MAY be running into a known issue. Can you issue the following command from the cli:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt;debug dataplane reset ssl-decrypt certificate-cache&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then try to go to any ssl sites that your were having problems with before. If you are now able to access the site then you are probably encountering and issue with our ssl certificate cache that is addressed in software version 3.1.5.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If not, then please call into support in order that we can take a closer look at this issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks,&lt;/P&gt;&lt;P&gt;Stephen&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Sep 2010 19:12:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-certificate-error/m-p/40495#M29738</guid>
      <dc:creator>swhyte</dc:creator>
      <dc:date>2010-09-17T19:12:43Z</dc:date>
    </item>
  </channel>
</rss>

