<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GesoTrust Intermediate Certificate in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/gesotrust-intermediate-certificate/m-p/144522#M48871</link>
    <description>&lt;P&gt;I am a bit confused about your setup/requirements but generally, Palo (when doing decryption) will forward trust and untrust certs to the client. This video helped me to understand same as community:-) Do you have that server available on Internet, if yes this website will help you to check server&amp;nbsp;ssl&amp;nbsp;cert and much more:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.ssllabs.com/ssltest/" target="_blank"&gt;https://www.ssllabs.com/ssltest/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.youtube.com/watch?v=7o3Pjhs1qxM" target="_blank"&gt;https://www.youtube.com/watch?v=7o3Pjhs1qxM&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 23 Feb 2017 11:40:32 GMT</pubDate>
    <dc:creator>TranceforLife</dc:creator>
    <dc:date>2017-02-23T11:40:32Z</dc:date>
    <item>
      <title>GesoTrust Intermediate Certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gesotrust-intermediate-certificate/m-p/144031#M48806</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We're&amp;nbsp;having some issues with the Intermidiate certificate that we're using in one of our servers when trying to connect to it passing trough your firewall (installed in our client's system).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Our certificate provider is GeoTrust Inc. and I've been reading that there may be some problems with your firewall when using it.&lt;/P&gt;&lt;P&gt;Since only 2 users from our client will be connecting to this server; is there a way to generate this certificates manually and install them on their computers?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any help will be greatly appreciated because I'm a little out of my depth here.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind Regards, Guillermo.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Feb 2017 11:27:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gesotrust-intermediate-certificate/m-p/144031#M48806</guid>
      <dc:creator>gsanchez_evendor</dc:creator>
      <dc:date>2017-02-21T11:27:38Z</dc:date>
    </item>
    <item>
      <title>Re: GesoTrust Intermediate Certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gesotrust-intermediate-certificate/m-p/144088#M48815</link>
      <description>&lt;P&gt;What type of connection is the PA brokering for your server?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is the PA performing decryption on your traffic?&lt;/P&gt;</description>
      <pubDate>Tue, 21 Feb 2017 14:12:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gesotrust-intermediate-certificate/m-p/144088#M48815</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2017-02-21T14:12:35Z</dc:date>
    </item>
    <item>
      <title>Re: GesoTrust Intermediate Certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gesotrust-intermediate-certificate/m-p/144091#M48818</link>
      <description>&lt;P&gt;If no decryption implemented Palo wouldn't&amp;nbsp;care about the SSL traffic and the cert used by clien/server as&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9524"&gt;@pulukas&lt;/a&gt;&amp;nbsp;mentioned. If you do have a decryption then this post might help you:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/General-Topics/SSL-Decryption-issue-wrong-certificate/m-p/141302" target="_blank"&gt;https://live.paloaltonetworks.com/t5/General-Topics/SSL-Decryption-issue-wrong-certificate/m-p/141302&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Feb 2017 14:57:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gesotrust-intermediate-certificate/m-p/144091#M48818</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-02-21T14:57:02Z</dc:date>
    </item>
    <item>
      <title>Re: GesoTrust Intermediate Certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gesotrust-intermediate-certificate/m-p/144101#M48821</link>
      <description>&lt;P&gt;I just forwarded those 2 questions to our client.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As soon as I get a reply, I'll Post here.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you so much for your help!&lt;/P&gt;</description>
      <pubDate>Tue, 21 Feb 2017 14:53:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gesotrust-intermediate-certificate/m-p/144101#M48821</guid>
      <dc:creator>gsanchez_evendor</dc:creator>
      <dc:date>2017-02-21T14:53:04Z</dc:date>
    </item>
    <item>
      <title>Re: GesoTrust Intermediate Certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gesotrust-intermediate-certificate/m-p/144102#M48822</link>
      <description>&lt;P&gt;Than you for the link!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I still don't know about the decryption (waiting on response from client), but I'm gonna check it out just in case.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Than so much you for the response !&lt;/P&gt;</description>
      <pubDate>Tue, 21 Feb 2017 14:55:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gesotrust-intermediate-certificate/m-p/144102#M48822</guid>
      <dc:creator>gsanchez_evendor</dc:creator>
      <dc:date>2017-02-21T14:55:01Z</dc:date>
    </item>
    <item>
      <title>Re: GesoTrust Intermediate Certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gesotrust-intermediate-certificate/m-p/144506#M48868</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I just got an answer, apparently PA is performing ssl decryption for my&amp;nbsp;client. PA manages the firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've also been told that whitelisting this certificate "wouldn't be a good idea" so that's not an option to me.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas on how to proceed?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Feb 2017 09:26:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gesotrust-intermediate-certificate/m-p/144506#M48868</guid>
      <dc:creator>gsanchez_evendor</dc:creator>
      <dc:date>2017-02-23T09:26:12Z</dc:date>
    </item>
    <item>
      <title>Re: GesoTrust Intermediate Certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gesotrust-intermediate-certificate/m-p/144522#M48871</link>
      <description>&lt;P&gt;I am a bit confused about your setup/requirements but generally, Palo (when doing decryption) will forward trust and untrust certs to the client. This video helped me to understand same as community:-) Do you have that server available on Internet, if yes this website will help you to check server&amp;nbsp;ssl&amp;nbsp;cert and much more:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.ssllabs.com/ssltest/" target="_blank"&gt;https://www.ssllabs.com/ssltest/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.youtube.com/watch?v=7o3Pjhs1qxM" target="_blank"&gt;https://www.youtube.com/watch?v=7o3Pjhs1qxM&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Feb 2017 11:40:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gesotrust-intermediate-certificate/m-p/144522#M48871</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-02-23T11:40:32Z</dc:date>
    </item>
    <item>
      <title>Re: GesoTrust Intermediate Certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gesotrust-intermediate-certificate/m-p/144567#M48877</link>
      <description>&lt;P&gt;Thank you so much!!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I checked our server with the website you linked and it came up with tons of warning messages.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;TLS 1.2 -&amp;gt; NO&lt;/P&gt;&lt;P&gt;TLS 1.1 -&amp;gt; NO&lt;/P&gt;&lt;P&gt;TLS 1.0 -&amp;gt; Yes&lt;/P&gt;&lt;P&gt;SSL 3 INSERCURE -&amp;gt; Yes &amp;nbsp;--&amp;gt; I Think this may be it&lt;/P&gt;&lt;P&gt;SSL 2 -&amp;gt; NO&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'll forward the full report to our server provider to see what can be done.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you so much for your help.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Feb 2017 15:22:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gesotrust-intermediate-certificate/m-p/144567#M48877</guid>
      <dc:creator>gsanchez_evendor</dc:creator>
      <dc:date>2017-02-23T15:22:53Z</dc:date>
    </item>
    <item>
      <title>Re: GesoTrust Intermediate Certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gesotrust-intermediate-certificate/m-p/144569#M48879</link>
      <description>&lt;P&gt;Looks like you need to fix the server certificate and/or exclude it from the decryption.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Feb 2017 15:27:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gesotrust-intermediate-certificate/m-p/144569#M48879</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-02-23T15:27:35Z</dc:date>
    </item>
  </channel>
</rss>

