<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: External CA Certificate Options Greyed Out in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/external-ca-certificate-options-greyed-out/m-p/76451#M42322</link>
    <description>&lt;P&gt;Ah that's a shame.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm sure I can use an External CA for SSL Forward Proxy, I just needed to mark the certifcate as the Trusted Root CA, as well as Forward Trust and Untrust. This wasn't done and should work otherwise..?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/61/pan-os/pan-os/decryption/configure-ssl-forward-proxy" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/61/pan-os/pan-os/decryption/configure-ssl-forward-proxy&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regarding the screenshots, I had tried to edit the subordinate certificates which you can't change as they're generated off of the back of the Trusted Root cert.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Thanks&amp;nbsp;&lt;BR /&gt;Jack&lt;/P&gt;</description>
    <pubDate>Thu, 14 Apr 2016 21:57:33 GMT</pubDate>
    <dc:creator>Jack_Howells</dc:creator>
    <dc:date>2016-04-14T21:57:33Z</dc:date>
    <item>
      <title>External CA Certificate Options Greyed Out</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/external-ca-certificate-options-greyed-out/m-p/76406#M42305</link>
      <description>&lt;P&gt;Hi guys,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've followed the documentation on how to generate a CSR (&lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Generate-a-CSR-Certificate-Signing-Request-and-Import-the/ta-p/53593)" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Generate-a-CSR-Certificate-Signing-Request-and-Import-the/ta-p/53593)&lt;/A&gt; but when importing the certificate I'm only able to select one option, as shown below.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://ip1.i.lithium.com/0ac89fb7fd15b782445c0b6fa03f274c81b0faff/68747470733a2f2f73797374656d2e6e657473756974652e636f6d2f636f72652f6d656469612f6d656469612e6e6c3f69643d3536333939313126633d37373335393426683d3365353730323138316564613866396334323664267768656e63653d" border="0" /&gt;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://ip1.i.lithium.com/109f6350090857344dbdb4eca950aba1d1c12a9d/68747470733a2f2f73797374656d2e6e657473756974652e636f6d2f636f72652f6d656469612f6d656469612e6e6c3f69643d3536333939313026633d37373335393426683d6535643438623761383864643563346565326633267768656e63653d" border="0" width="1028" height="144" /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Could you please help explain why they're greyed out?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Apr 2016 10:44:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/external-ca-certificate-options-greyed-out/m-p/76406#M42305</guid>
      <dc:creator>Jack_Howells</dc:creator>
      <dc:date>2016-04-14T10:44:33Z</dc:date>
    </item>
    <item>
      <title>Re: External CA Certificate Options Greyed Out</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/external-ca-certificate-options-greyed-out/m-p/76407#M42306</link>
      <description>&lt;P&gt;Edit:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm trying to use this External CA for SSL Forward Proxy.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Apr 2016 10:45:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/external-ca-certificate-options-greyed-out/m-p/76407#M42306</guid>
      <dc:creator>Jack_Howells</dc:creator>
      <dc:date>2016-04-14T10:45:07Z</dc:date>
    </item>
    <item>
      <title>Re: External CA Certificate Options Greyed Out</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/external-ca-certificate-options-greyed-out/m-p/76431#M42316</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Your images didn't come through for some reason, but in general the reason for this is because the CSR wasn't signed with the CA option (ca=true). If it's not a CA cert, it cannot be used for forward decryption.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You will be unable to get a CA cert from a public authority (like Symmatec or GoDaddy). No public CA will give a private party a certificate that can be used to issue new, trusted certificates.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You'll need to use an internal CA, or create a self-signed CA cert on the firewall and distribute that to your users.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;Greg&lt;/P&gt;</description>
      <pubDate>Thu, 14 Apr 2016 17:16:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/external-ca-certificate-options-greyed-out/m-p/76431#M42316</guid>
      <dc:creator>gwesson</dc:creator>
      <dc:date>2016-04-14T17:16:19Z</dc:date>
    </item>
    <item>
      <title>Re: External CA Certificate Options Greyed Out</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/external-ca-certificate-options-greyed-out/m-p/76451#M42322</link>
      <description>&lt;P&gt;Ah that's a shame.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm sure I can use an External CA for SSL Forward Proxy, I just needed to mark the certifcate as the Trusted Root CA, as well as Forward Trust and Untrust. This wasn't done and should work otherwise..?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/61/pan-os/pan-os/decryption/configure-ssl-forward-proxy" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/61/pan-os/pan-os/decryption/configure-ssl-forward-proxy&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regarding the screenshots, I had tried to edit the subordinate certificates which you can't change as they're generated off of the back of the Trusted Root cert.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Thanks&amp;nbsp;&lt;BR /&gt;Jack&lt;/P&gt;</description>
      <pubDate>Thu, 14 Apr 2016 21:57:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/external-ca-certificate-options-greyed-out/m-p/76451#M42322</guid>
      <dc:creator>Jack_Howells</dc:creator>
      <dc:date>2016-04-14T21:57:33Z</dc:date>
    </item>
    <item>
      <title>Re: External CA Certificate Options Greyed Out</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/external-ca-certificate-options-greyed-out/m-p/76468#M42325</link>
      <description>&lt;P&gt;For firewall to be able to sign certificates on the fly for forward proxy to work you need CA or intermediate CA certificate.&lt;/P&gt;
&lt;P&gt;Public CA's will not allow you to be their intermediate because this would completely brake SSL model (you could decrypt anyones SSL traffic).&lt;/P&gt;
&lt;P&gt;For that reason you either generate CA and push it out with Group Policy or generate CA certificate and sign it with your domain CA (then root will be domain CA and fw cert will be intemediate).&lt;/P&gt;
&lt;P&gt;If you take second path then you don't have to push fw cert to anyware as your domain computers already trust domain root CA.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Apr 2016 10:01:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/external-ca-certificate-options-greyed-out/m-p/76468#M42325</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2016-04-15T10:01:08Z</dc:date>
    </item>
  </channel>
</rss>

