<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SSL decryption. What kind of the certificate l can use? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-what-kind-of-the-certificate-l-can-use/m-p/79271#M43223</link>
    <description>&lt;P&gt;Hi Guys,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you explain to me what types of the certificates l can use and where can l get them from? &amp;nbsp;For SSL decryption, we do not want to use the self-signed cert.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you,&lt;/P&gt;
&lt;P&gt;Mykhaylo&lt;/P&gt;</description>
    <pubDate>Tue, 07 Jun 2016 13:08:34 GMT</pubDate>
    <dc:creator>Transporter</dc:creator>
    <dc:date>2016-06-07T13:08:34Z</dc:date>
    <item>
      <title>SSL decryption. What kind of the certificate l can use?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-what-kind-of-the-certificate-l-can-use/m-p/79271#M43223</link>
      <description>&lt;P&gt;Hi Guys,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you explain to me what types of the certificates l can use and where can l get them from? &amp;nbsp;For SSL decryption, we do not want to use the self-signed cert.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you,&lt;/P&gt;
&lt;P&gt;Mykhaylo&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jun 2016 13:08:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-what-kind-of-the-certificate-l-can-use/m-p/79271#M43223</guid>
      <dc:creator>Transporter</dc:creator>
      <dc:date>2016-06-07T13:08:34Z</dc:date>
    </item>
    <item>
      <title>Re: SSL decryption. What kind of the certificate l can use?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-what-kind-of-the-certificate-l-can-use/m-p/79275#M43225</link>
      <description>&lt;P&gt;Hello Mykhaylo,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You will need a root certificate/subordinate certifcate. Essentially you need a certificate that will be used to&amp;nbsp;generate a new certificate based off the original certificate in the handshake, the certificate that is generated will then be signed by the certificate you choose for decryption.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It is highly unlikely you will get a certificate like this from a public authority, if you could get this kind of certificate then you could decrypt public traffic which would invalidate the use of public key infrastructure on the internet.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;hope this helps,&lt;/P&gt;
&lt;P&gt;Ben&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jun 2016 13:57:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-what-kind-of-the-certificate-l-can-use/m-p/79275#M43225</guid>
      <dc:creator>bmorris1</dc:creator>
      <dc:date>2016-06-07T13:57:55Z</dc:date>
    </item>
    <item>
      <title>Re: SSL decryption. What kind of the certificate l can use?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-what-kind-of-the-certificate-l-can-use/m-p/79277#M43226</link>
      <description>&lt;P&gt;Hi Mykhaylo,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have to use a root CA certificate for decryption. We should have both root ca certificate public key and private key.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Why we need root ca is because whenever a client initiate a ssl handshake to a server firewall will intercept that request and then firewall will send a client hello from itself to server now server will reply for that client hello with server hello and it will also give a certificate. Firewall will take all field of the certificate sent from server and generate a similar certificate sign this new certificate with root CA&amp;nbsp; cert this newly signed certificate is forwarded to actual client.&amp;nbsp; Only a root CA certificate can generate/sign a certificate.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;No CA server will give their root CA certificate private key to anyone. So we have to use a selfsigned root certificate.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps!&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jun 2016 14:03:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-what-kind-of-the-certificate-l-can-use/m-p/79277#M43226</guid>
      <dc:creator>pankaku</dc:creator>
      <dc:date>2016-06-07T14:03:30Z</dc:date>
    </item>
    <item>
      <title>Re: SSL decryption. What kind of the certificate l can use?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-what-kind-of-the-certificate-l-can-use/m-p/79290#M43233</link>
      <description>&lt;P&gt;Thanks guys&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jun 2016 14:57:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-what-kind-of-the-certificate-l-can-use/m-p/79290#M43233</guid>
      <dc:creator>Transporter</dc:creator>
      <dc:date>2016-06-07T14:57:00Z</dc:date>
    </item>
    <item>
      <title>Re: SSL decryption. What kind of the certificate l can use?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-what-kind-of-the-certificate-l-can-use/m-p/79295#M43236</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/8358"&gt;@Pankaj&lt;/a&gt;.kumar wrote:&lt;BR /&gt;
&lt;P&gt;Hi Mykhaylo,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have to use a root CA certificate for decryption. We should have both root ca certificate public key and private key.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Why we need root ca is because whenever a client initiate a ssl handshake to a server firewall will intercept that request and then firewall will send a client hello from itself to server now server will reply for that client hello with server hello and it will also give a certificate. Firewall will take all field of the certificate sent from server and generate a similar certificate sign this new certificate with root CA&amp;nbsp; cert this newly signed certificate is forwarded to actual client.&amp;nbsp; Only a root CA certificate can generate/sign a certificate.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;No CA server will give their root CA certificate private key to anyone. So we have to use a selfsigned root certificate.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps!&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You don't need to use a root CA certificate.&amp;nbsp; What I did was issue a subordinate CA certificate from our internal intermediate issuing CA and use that as the Forward Trust Certificate in PAN-OS.&amp;nbsp; This way, all of our clients already trust certificates issued by the PAN NGFW because they trust the root CA certificate at the base of the chain.&amp;nbsp; Additionally, if the private key for the Forward Trust Certificate was ever compromised, we could always revoke the certificate using our intermediate CA.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In my opinion, this is a much simpler and more secure method than making the PAN NGFW its own root CA.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jun 2016 15:39:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-what-kind-of-the-certificate-l-can-use/m-p/79295#M43236</guid>
      <dc:creator>scottsander</dc:creator>
      <dc:date>2016-06-07T15:39:57Z</dc:date>
    </item>
    <item>
      <title>Re: SSL decryption. What kind of the certificate l can use?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-what-kind-of-the-certificate-l-can-use/m-p/79334#M43244</link>
      <description>&lt;P&gt;Yes It can be a subordidnate CA cert. Main point is it should be a ca&amp;nbsp;cert.&lt;/P&gt;</description>
      <pubDate>Tue, 20 Sep 2016 22:53:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-what-kind-of-the-certificate-l-can-use/m-p/79334#M43244</guid>
      <dc:creator>pankaku</dc:creator>
      <dc:date>2016-09-20T22:53:03Z</dc:date>
    </item>
  </channel>
</rss>

