<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSL Decryption in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption/m-p/51302#M37736</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Looks good so far&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you need to import the forward_trust and the root_ca into Mac OS-X.&lt;/P&gt;&lt;P&gt;Also: is the forward_trust signed by the root_ca?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you send a screenshot of the https certificate chain when calling the facebook site?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Andre&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 30 Jul 2012 11:08:54 GMT</pubDate>
    <dc:creator>u13550</dc:creator>
    <dc:date>2012-07-30T11:08:54Z</dc:date>
    <item>
      <title>SSL Decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption/m-p/51297#M37731</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi All, I have an issue with SSL decryption and using the inbuilt CA. What appears to happen is that various parts of SSL websites don't trust the CA on the palo alto and as a consequence sites do not load fully and report various certificate issues.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is what https facebook looks like:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="3551" alt="Screen Shot 2012-07-24 at 8.59.24 AM.png" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/3551_Screen Shot 2012-07-24 at 8.59.24 AM.png" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The corresponding browser complaints:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="3552" alt="Screen Shot 2012-07-25 at 3.27.39 PM.png" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/3552_Screen Shot 2012-07-25 at 3.27.39 PM.png" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm running the very latest OS 4.1.6 but I was running 4.1.3 and this problem was evident then as well. I've tried uploading a trusted certificate from rapidssl and I don't get the option to select that is a valid certificate for a forward SSL proxy which is understandable as I don't have a key.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So I'm obviously doing something wrong - whats the accepted procedure to get this up and running?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance for your help&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Jul 2012 00:06:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption/m-p/51297#M37731</guid>
      <dc:creator>mgillette</dc:creator>
      <dc:date>2012-07-30T00:06:56Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption/m-p/51298#M37732</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi mgillette&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the pictures one can't see the presented certificates, but I think I had a sminilar problem and couldn't find a proper document, so I created my own.&lt;/P&gt;&lt;P&gt;The config guide attached works for me, maybe it works for you as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Andre&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Jul 2012 05:45:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption/m-p/51298#M37732</guid>
      <dc:creator>u13550</dc:creator>
      <dc:date>2012-07-30T05:45:54Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption/m-p/51299#M37733</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Andre,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Firstly thanks for the config guide, but unfortunately it doesn't work for me in my scenario. We don't use AD or windows so I can't push out certificates using GPO. We are linux/Mac based and rely on users clicking the right option when their browser prompts them to accept a certificate. In the facebook case above the browser does not load the s-static.ak.fbcdn.net certificate. I need to manually load this into the browser on my test machine for https facebook to work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have tried other SSL sites, (gmail,hotmail,yahoo) these exhibit the same issue where the site doesn't trust the CA on the palo alto and doesn't load some certificates. This causes various parts of these sites to break.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Jul 2012 07:51:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption/m-p/51299#M37733</guid>
      <dc:creator>mgillette</dc:creator>
      <dc:date>2012-07-30T07:51:56Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption/m-p/51300#M37734</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't run WIndows either, pure Mac based environment &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, you have to import the forward-trust CA certificate into the client browsers, there is no way around it. If you do so, all runs smoothly even on a Mac.&lt;/P&gt;&lt;P&gt;If you go with two vert CAs (like in my guide), import both CAs into the clients browser&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And don't forget to use a forward-untrust vert (do NOT import it). Doing so should allow you to see the certificate chain of both working and not working SSL Sites.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What I don't get: You say the Website does'n trust the Palo Alto CA? What do you mean by this? The PA behaves like a normal client to the original server, so it doesn't use any (of it's own) certificates.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Andre&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Jul 2012 08:00:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption/m-p/51300#M37734</guid>
      <dc:creator>u13550</dc:creator>
      <dc:date>2012-07-30T08:00:12Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption/m-p/51301#M37735</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok so here's what I've done. Downloaded the forward_trust CA and imported that into the keychain on an OS X machine. Fire up safari and go to ssl facebook. The browser complains that the identity of www.facebook.com can't be identified and asks me what to do. I click continue. Nothing appears to have changed from my first post and the safari activity window reports that the certificate for s-static.ak.fbcdn.net is invalid because the certificate issuer can't be identified.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Various other parts of SSL websites also break in this manner - hotmail,yahoo and gmail all report at some point that a certificate is invalid.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is the screenshot of the certificates page&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="3557" alt="Screen Shot 2012-07-30 at 9.35.54 PM.png" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/3557_Screen Shot 2012-07-30 at 9.35.54 PM.png" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And a screenshot of the decryption settings&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="3558" alt="Screen Shot 2012-07-30 at 9.36.59 PM.png" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/3558_Screen Shot 2012-07-30 at 9.36.59 PM.png" width="450" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Jul 2012 09:44:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption/m-p/51301#M37735</guid>
      <dc:creator>mgillette</dc:creator>
      <dc:date>2012-07-30T09:44:11Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption/m-p/51302#M37736</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Looks good so far&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you need to import the forward_trust and the root_ca into Mac OS-X.&lt;/P&gt;&lt;P&gt;Also: is the forward_trust signed by the root_ca?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you send a screenshot of the https certificate chain when calling the facebook site?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Andre&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Jul 2012 11:08:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption/m-p/51302#M37736</guid>
      <dc:creator>u13550</dc:creator>
      <dc:date>2012-07-30T11:08:54Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption/m-p/51303#M37737</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;were you ever able to resolve this issue? I am having the exact same problem&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 26 May 2013 14:17:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption/m-p/51303#M37737</guid>
      <dc:creator>cryptochrome</dc:creator>
      <dc:date>2013-05-26T14:17:15Z</dc:date>
    </item>
  </channel>
</rss>

