<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSL Decryption issue (wrong certificate) in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-issue-wrong-certificate/m-p/141347#M48393</link>
    <description>&lt;P&gt;@Retired Member&amp;nbsp;ok with firefox l am not even able to open this website. Chrome also is not complaining:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Chrome.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/7652i60B0885AC913BB89/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Chrome.PNG" alt="Chrome.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I am new to SSL so if you can let me know what is actually happening with the server cert l will&amp;nbsp;appreciate:0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thx,&lt;/P&gt;&lt;P&gt;Myky&lt;/P&gt;</description>
    <pubDate>Mon, 06 Feb 2017 19:28:36 GMT</pubDate>
    <dc:creator>TranceforLife</dc:creator>
    <dc:date>2017-02-06T19:28:36Z</dc:date>
    <item>
      <title>SSL Decryption issue (wrong certificate)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-issue-wrong-certificate/m-p/141302#M48382</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Having SSL Decryption issue with one of the websites at the moment (&lt;A href="https://wiki.freeradius.org/Home" target="_blank"&gt;https://wiki.freeradius.org/Home&lt;/A&gt;)&lt;/P&gt;&lt;P&gt;So testing without decryption and checking certs chain:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PA1.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/7642i29B1544C319D4CA8/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="PA1.PNG" alt="PA1.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can see root CA on Palo:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PA2.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/7643i0E53B504169B5B29/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="PA2.PNG" alt="PA2.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So all looks good. Implementing SSL Decryption (test version only) with two certs generated on PA one for forward trust another is for forward untrust:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="CERTS.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/7644i1182B62CE4990A62/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="CERTS.PNG" alt="CERTS.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Doing a test with some websites reviewing a forward trust cert. As an example bbc.co.uk:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="BBC.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/7645iCFD0AB8429E88D52/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="BBC.PNG" alt="BBC.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;l didn't&amp;nbsp;import cert to the test PC as want to confirm first everything is working fine.&lt;/P&gt;&lt;P&gt;Done another test with the&amp;nbsp;websites which allow&amp;nbsp;decryption all looks good correct cert is forwarded. But for the website&amp;nbsp;&lt;SPAN&gt;&lt;A href="https://wiki.freeradius.org/Home" target="_blank"&gt;https://wiki.freeradius.org/Home&lt;/A&gt; getting the wrong cert which is forward untrust:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PA3.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/7647i04941071F004210A/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="PA3.PNG" alt="PA3.PNG" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Don't know why. Cache is cleared, and the new cert is recreated for untrust but still the same.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;PA-5050 Active/Active PAN-OS 7.1.5&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Am l missing something simple?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Myky&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Feb 2017 19:05:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-issue-wrong-certificate/m-p/141302#M48382</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-02-06T19:05:25Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption issue (wrong certificate)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-issue-wrong-certificate/m-p/141338#M48388</link>
      <description>&lt;P&gt;Check the results there is your answer:&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.ssllabs.com/ssltest/analyze.html?d=wiki.freeradius.org&amp;amp;hideResults=on" target="_blank"&gt;https://www.ssllabs.com/ssltest/analyze.html?d=wiki.freeradius.org&amp;amp;hideResults=on&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Feb 2017 19:09:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-issue-wrong-certificate/m-p/141338#M48388</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2017-02-06T19:09:29Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption issue (wrong certificate)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-issue-wrong-certificate/m-p/141341#M48389</link>
      <description>&lt;P&gt;I'm not certain, but this might be caused by an incomplete certificate chain (per ssllabs.com):&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="cert.png" style="width: 500px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/7650i12964AAA1792E75B/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="cert.png" alt="cert.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The traffic log complains about cert-validation as well:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="traffic.png" style="width: 500px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/7651i7864363C2904FB5E/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="traffic.png" alt="traffic.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.ssllabs.com/ssltest/analyze.html?d=wiki.freeradius.org" target="_blank"&gt;https://www.ssllabs.com/ssltest/analyze.html?d=wiki.freeradius.org&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Feb 2017 19:12:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-issue-wrong-certificate/m-p/141341#M48389</guid>
      <dc:creator>jvalentine</dc:creator>
      <dc:date>2017-02-06T19:12:02Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption issue (wrong certificate)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-issue-wrong-certificate/m-p/141343#M48391</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/22017"&gt;@jvalentine&lt;/a&gt;&amp;nbsp;@Retired Member&amp;nbsp;thanks all. Looks like&amp;nbsp;l missing something simple. Why the&amp;nbsp;web-browser is not complaining without ssl&amp;nbsp;decryption in place?&lt;/P&gt;</description>
      <pubDate>Mon, 06 Feb 2017 19:17:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-issue-wrong-certificate/m-p/141343#M48391</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-02-06T19:17:14Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption issue (wrong certificate)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-issue-wrong-certificate/m-p/141344#M48392</link>
      <description>&lt;P&gt;Its because you use IE.&lt;/P&gt;&lt;P&gt;IE wil try to dowload the missing certificates in the chain.&lt;/P&gt;&lt;P&gt;Try firefox and&amp;nbsp;it will complain.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Feb 2017 19:20:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-issue-wrong-certificate/m-p/141344#M48392</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2017-02-06T19:20:01Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption issue (wrong certificate)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-issue-wrong-certificate/m-p/141347#M48393</link>
      <description>&lt;P&gt;@Retired Member&amp;nbsp;ok with firefox l am not even able to open this website. Chrome also is not complaining:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Chrome.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/7652i60B0885AC913BB89/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Chrome.PNG" alt="Chrome.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I am new to SSL so if you can let me know what is actually happening with the server cert l will&amp;nbsp;appreciate:0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thx,&lt;/P&gt;&lt;P&gt;Myky&lt;/P&gt;</description>
      <pubDate>Mon, 06 Feb 2017 19:28:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-issue-wrong-certificate/m-p/141347#M48393</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-02-06T19:28:36Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption issue (wrong certificate)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-issue-wrong-certificate/m-p/141350#M48395</link>
      <description>&lt;P&gt;Its not a problem of the PA or your decryption settings.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The website certificate is incorrect configured, the intermediate certificates are missing.&lt;/P&gt;&lt;P&gt;Thats why the PA sends the "not trusted" certificate to your browser.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Feb 2017 19:40:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-issue-wrong-certificate/m-p/141350#M48395</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2017-02-06T19:40:56Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption issue (wrong certificate)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-issue-wrong-certificate/m-p/141358#M48396</link>
      <description>&lt;P&gt;Hi&amp;nbsp;@Retired Member&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ok cool as you said before IE and Chrome will ignore this, right? As long as it has a root CA.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thx,&lt;/P&gt;&lt;P&gt;Myky&lt;/P&gt;</description>
      <pubDate>Mon, 06 Feb 2017 19:36:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-issue-wrong-certificate/m-p/141358#M48396</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-02-06T19:36:50Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption issue (wrong certificate)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-issue-wrong-certificate/m-p/141360#M48397</link>
      <description>&lt;P&gt;Yes, &amp;nbsp;Chrome(uses the windows&amp;nbsp;cert store)&amp;nbsp;and IE will try to download the intermediate certs as long as they have a valid root CA in their certificate store.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Feb 2017 19:40:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-issue-wrong-certificate/m-p/141360#M48397</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2017-02-06T19:40:34Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption issue (wrong certificate)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-issue-wrong-certificate/m-p/141362#M48399</link>
      <description>&lt;P&gt;Cool l have learned&amp;nbsp;something new today. Thanks/ Last thing Do you have any good&amp;nbsp;article explaining this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thx,&lt;/P&gt;&lt;P&gt;Myky&lt;/P&gt;</description>
      <pubDate>Mon, 06 Feb 2017 19:53:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-issue-wrong-certificate/m-p/141362#M48399</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-02-06T19:53:37Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption issue (wrong certificate)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-issue-wrong-certificate/m-p/141375#M48404</link>
      <description>&lt;P&gt;Your welcome.&lt;/P&gt;&lt;P&gt;I don't have documentation on this issue specific.&amp;nbsp; (&amp;nbsp;its all in my head &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt; )&lt;/P&gt;</description>
      <pubDate>Mon, 06 Feb 2017 20:06:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-issue-wrong-certificate/m-p/141375#M48404</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2017-02-06T20:06:44Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption issue (wrong certificate)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-issue-wrong-certificate/m-p/141542#M48419</link>
      <description>&lt;P&gt;To fix the issue for this particular website l did import a&amp;nbsp;COMODORSADomainValidationSecureServerCA.crt&amp;nbsp;to the box:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/How-to-Import-the-Intermediate-CA-on-the-Firewall/ta-p/52196" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/How-to-Import-the-Intermediate-CA-on-the-Firewall/ta-p/52196&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Feb 2017 13:26:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-issue-wrong-certificate/m-p/141542#M48419</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-02-07T13:26:10Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption issue (wrong certificate)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-issue-wrong-certificate/m-p/141546#M48420</link>
      <description>&lt;P&gt;In my opinion is importing the intermediate certificate in this situation wrong.&lt;/P&gt;&lt;P&gt;The behaviour was as expected and correct.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;With this "fix", you are covering a warning that the site is misconfigured.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Feb 2017 13:53:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-issue-wrong-certificate/m-p/141546#M48420</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2017-02-07T13:53:09Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption issue (wrong certificate)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-issue-wrong-certificate/m-p/141569#M48424</link>
      <description>&lt;P&gt;I do agree with you as really&amp;nbsp;it is a &amp;nbsp;"masquerading" of the problem.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Feb 2017 14:03:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-issue-wrong-certificate/m-p/141569#M48424</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-02-07T14:03:22Z</dc:date>
    </item>
  </channel>
</rss>

