<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: About Captive Certificate in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/about-captive-certificate/m-p/44877#M32952</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Panlst,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Since the certificate will be from the firewall, visitor's page will not have any information for the browser. When the client gets certificate it would be Unknown has signed Captive portal and that would generate browser error.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With certificate from trusted 3rd party, it might say Verisign has signed Captive portal, since visitors browser already trusts Verisign cert, there will not be any errors. Hope this helps. Thank you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 10 Nov 2014 15:55:08 GMT</pubDate>
    <dc:creator>ssharma</dc:creator>
    <dc:date>2014-11-10T15:55:08Z</dc:date>
    <item>
      <title>About Captive Certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/about-captive-certificate/m-p/44875#M32950</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To make visitors not having ssl warning for Captive portal page;&lt;/P&gt;&lt;P&gt;is there a way to do that without purchase a certificate ?(no way for importing cert to the clients)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Nov 2014 15:23:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/about-captive-certificate/m-p/44875#M32950</guid>
      <dc:creator>PanIst</dc:creator>
      <dc:date>2014-11-10T15:23:33Z</dc:date>
    </item>
    <item>
      <title>Re: About Captive Certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/about-captive-certificate/m-p/44876#M32951</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As per my knowledge, the answer will be "no". Self generated certificate will not match with &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;client's&lt;/SPAN&gt; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;( &lt;/SPAN&gt;browser) certificate ring. Hence, it will throw a &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;cert&lt;/SPAN&gt; warning. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Nov 2014 15:32:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/about-captive-certificate/m-p/44876#M32951</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-11-10T15:32:39Z</dc:date>
    </item>
    <item>
      <title>Re: About Captive Certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/about-captive-certificate/m-p/44877#M32952</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Panlst,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Since the certificate will be from the firewall, visitor's page will not have any information for the browser. When the client gets certificate it would be Unknown has signed Captive portal and that would generate browser error.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With certificate from trusted 3rd party, it might say Verisign has signed Captive portal, since visitors browser already trusts Verisign cert, there will not be any errors. Hope this helps. Thank you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Nov 2014 15:55:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/about-captive-certificate/m-p/44877#M32952</guid>
      <dc:creator>ssharma</dc:creator>
      <dc:date>2014-11-10T15:55:08Z</dc:date>
    </item>
    <item>
      <title>Re: About Captive Certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/about-captive-certificate/m-p/44878#M32953</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Panist,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That is correct, Guest user will get certificate warning as certificate is locally generated on firewall. Guest browser doesnt know certificate hence it will generate an error.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hardik Shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Nov 2014 16:00:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/about-captive-certificate/m-p/44878#M32953</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2014-11-10T16:00:18Z</dc:date>
    </item>
    <item>
      <title>Re: About Captive Certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/about-captive-certificate/m-p/44879#M32954</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Panlst,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The answer to your question is 'No' under your conditions. In general, following are the options:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. Use a certificate signed by 3rd party vendor like Verisign, GoDaddy, etc. This is best solution as this cert will be trusted by all the browsers irrespective of the device.&lt;/P&gt;&lt;P&gt;2. Use a PAN self signed certificate or domain generated sub-ordinate certificate. Install its certificate authority on the client browsers. Though technically this will work, practically it is very difficult to implement this since typically you wouldn't be knowing which device the user will be using. So not scalable.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope it helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Dileep&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Nov 2014 16:09:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/about-captive-certificate/m-p/44879#M32954</guid>
      <dc:creator>dreputi</dc:creator>
      <dc:date>2014-11-10T16:09:33Z</dc:date>
    </item>
  </channel>
</rss>

