<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSL Offloading 'Forward Trust' grayed out in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-offloading-forward-trust-grayed-out/m-p/44203#M32451</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I already have a local Microsoft Root CA in our Network.&lt;/P&gt;&lt;P&gt;Does this mean that I have to make my device PA as Sub-CA to this Root CA ??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If so, are there any documentation on how to make my PA a sub CA to my local Root CA ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;RZ&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 06 Jul 2014 07:47:36 GMT</pubDate>
    <dc:creator>rz185016</dc:creator>
    <dc:date>2014-07-06T07:47:36Z</dc:date>
    <item>
      <title>SSL Offloading 'Forward Trust' grayed out</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-offloading-forward-trust-grayed-out/m-p/44200#M32448</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have created a certificate from my local CA and also have imported the CSR from PA to the local CA, created the &lt;/P&gt;&lt;P&gt;identity certificate, all is well, but it seems I am not able to "Check Box" the "Forward Trust Certificate" on the&amp;nbsp; PA.&lt;IMG alt="Device Certificate.jpg" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/14297_Device Certificate.jpg" style="font-size: 10pt; line-height: 1.5em; height: 101px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Forward trust certificate.jpg" class="image-1 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/14298_Forward trust certificate.jpg" style="height: auto;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This it seems is a necessary step while configuring SSL offloading.&lt;/P&gt;&lt;P&gt;Any clues on what needs to be done ....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please see attached.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tauseef&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 06 Jul 2014 04:35:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-offloading-forward-trust-grayed-out/m-p/44200#M32448</guid>
      <dc:creator>rz185016</dc:creator>
      <dc:date>2014-07-06T04:35:57Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Offloading 'Forward Trust' grayed out</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-offloading-forward-trust-grayed-out/m-p/44201#M32449</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi RZ,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If certificate is selfsigned Root Certificate then option for "Forward Trust Certificate" &amp;amp; "Foreard Untrust Certificate" are Enabled. For selfsigned Root Certificate refer following image.&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Root_Cert.png" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/14299_Root_Cert.png" style="height: auto;" /&gt;&lt;/P&gt;&lt;P&gt;In your case you may not have checked option for Root Certificate. Apart from "self signed Root Cert", Suboardinate Root Certificate is supported for requested option.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Fore more information on SSL certificate refer bellow link. Go through Page 14 for certificate request.&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-1937"&gt;PAN SSL Certificates&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hardik Shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 06 Jul 2014 06:13:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-offloading-forward-trust-grayed-out/m-p/44201#M32449</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2014-07-06T06:13:28Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Offloading 'Forward Trust' grayed out</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-offloading-forward-trust-grayed-out/m-p/44202#M32450</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If certificate is not "self signed root CA" or "Subordinate Root CA" than it can not generate new certificate.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thats why non-Root CA cert doesnt work in decryption.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 06 Jul 2014 06:20:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-offloading-forward-trust-grayed-out/m-p/44202#M32450</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2014-07-06T06:20:20Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Offloading 'Forward Trust' grayed out</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-offloading-forward-trust-grayed-out/m-p/44203#M32451</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I already have a local Microsoft Root CA in our Network.&lt;/P&gt;&lt;P&gt;Does this mean that I have to make my device PA as Sub-CA to this Root CA ??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If so, are there any documentation on how to make my PA a sub CA to my local Root CA ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;RZ&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 06 Jul 2014 07:47:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-offloading-forward-trust-grayed-out/m-p/44203#M32451</guid>
      <dc:creator>rz185016</dc:creator>
      <dc:date>2014-07-06T07:47:36Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Offloading 'Forward Trust' grayed out</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-offloading-forward-trust-grayed-out/m-p/44204#M32452</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Also,&lt;/P&gt;&lt;P&gt;What way can I monitor or have an historical view of "SSL Decrypted" statistics.... ?&lt;/P&gt;&lt;P&gt;How can I know how many sessions are currently decrypted for which users and so on ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please advise&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 06 Jul 2014 08:37:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-offloading-forward-trust-grayed-out/m-p/44204#M32452</guid>
      <dc:creator>rz185016</dc:creator>
      <dc:date>2014-07-06T08:37:24Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Offloading 'Forward Trust' grayed out</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-offloading-forward-trust-grayed-out/m-p/44205#M32453</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN class="j-post-author"&gt;&lt;STRONG&gt;&lt;A _jive_internal="true" class="jiveTT-hover-user jive-username-link" data-avatarid="-1" data-externalid="" data-presence="null" data-userid="14265" data-username="rz185016" href="https://live.paloaltonetworks.com/people/rz185016"&gt;rz185016&lt;/A&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;See the instructions in this document to use your MS CA with SSL decryption.&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-3486"&gt;How to Implement Certificates Issued from Microsoft Certificate Services&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can check the general statistics using:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&amp;gt;debug sslmgr statistics&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 06 Jul 2014 10:05:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-offloading-forward-trust-grayed-out/m-p/44205#M32453</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2014-07-06T10:05:08Z</dc:date>
    </item>
  </channel>
</rss>

