<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Commit error - vsys1 decryption: forward decrypt untrust cert is not configured in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/commit-error-vsys1-decryption-forward-decrypt-untrust-cert-is/m-p/6976#M5143</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;Here is a doc which explains on how the different Decryptions (Inbound, outbound, forward proxy) is done on the firewall and general guidlines on how to configure it&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt; &lt;A _jive_internal="true" data-containerid="2027" data-containertype="14" data-objectid="1412" data-objecttype="102" href="https://live.paloaltonetworks.com/docs/DOC-1412" style="font-style: inherit; font-family: inherit; color: #006595;"&gt;https://live.paloaltonetworks.com/docs/DOC-1412&lt;/A&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;Here are few other useful docs for SSL decryption&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/docs/DOC-2008"&gt;https://live.paloaltonetworks.com/docs/DOC-2008&lt;/A&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/docs/DOC-2006"&gt;https://live.paloaltonetworks.com/docs/DOC-2006&lt;/A&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;Hope this helps.&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;Thanks&lt;BR /&gt;Numan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 27 Aug 2013 23:07:25 GMT</pubDate>
    <dc:creator>mbutt</dc:creator>
    <dc:date>2013-08-27T23:07:25Z</dc:date>
    <item>
      <title>Commit error - vsys1 decryption: forward decrypt untrust cert is not configured</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/commit-error-vsys1-decryption-forward-decrypt-untrust-cert-is/m-p/6973#M5140</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This commit error: "Warning: vsys1 decryption: forward decrypt untrust cert is not configured, forward decrypt trust cert will be used instead." Means, that i must generate "Forward untrust certificate" or what?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Aug 2013 13:52:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/commit-error-vsys1-decryption-forward-decrypt-untrust-cert-is/m-p/6973#M5140</guid>
      <dc:creator>Interface</dc:creator>
      <dc:date>2013-08-27T13:52:06Z</dc:date>
    </item>
    <item>
      <title>Re: Commit error - vsys1 decryption: forward decrypt untrust cert is not configured</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/commit-error-vsys1-decryption-forward-decrypt-untrust-cert-is/m-p/6974#M5141</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;IMG alt="cert.PNG.png" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/7920_cert.PNG.png" style="width: 620px; height: 35px;" /&gt;&lt;/P&gt;&lt;P&gt;Yes, you need to generate/import a CA cert on the PA and designate it as "Forward untrust cert" if you configure outbound SSL proxy as shown in the screenshot.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Aug 2013 13:54:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/commit-error-vsys1-decryption-forward-decrypt-untrust-cert-is/m-p/6974#M5141</guid>
      <dc:creator>goku123</dc:creator>
      <dc:date>2013-08-27T13:54:46Z</dc:date>
    </item>
    <item>
      <title>Re: Commit error - vsys1 decryption: forward decrypt untrust cert is not configured</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/commit-error-vsys1-decryption-forward-decrypt-untrust-cert-is/m-p/6975#M5142</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Good Morning,&lt;/P&gt;&lt;P&gt;Its recommended that the users are presented with a forward untrust certificate, if the server certificate of the web site that the user browses for isnt part of the Trusted CA certificates in the firewall. This is to let the customer know that the website in question is not trusted or safe. Usually the PANFW has most of the CA certificates under its list, and for the ones that are not present, the PANFW considers them as being unsafe.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When configured with the forwared untrust certificate, the user can come to know that the website in question not a safe website&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Aug 2013 13:56:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/commit-error-vsys1-decryption-forward-decrypt-untrust-cert-is/m-p/6975#M5142</guid>
      <dc:creator>kprakash</dc:creator>
      <dc:date>2013-08-27T13:56:36Z</dc:date>
    </item>
    <item>
      <title>Re: Commit error - vsys1 decryption: forward decrypt untrust cert is not configured</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/commit-error-vsys1-decryption-forward-decrypt-untrust-cert-is/m-p/6976#M5143</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;Here is a doc which explains on how the different Decryptions (Inbound, outbound, forward proxy) is done on the firewall and general guidlines on how to configure it&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt; &lt;A _jive_internal="true" data-containerid="2027" data-containertype="14" data-objectid="1412" data-objecttype="102" href="https://live.paloaltonetworks.com/docs/DOC-1412" style="font-style: inherit; font-family: inherit; color: #006595;"&gt;https://live.paloaltonetworks.com/docs/DOC-1412&lt;/A&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;Here are few other useful docs for SSL decryption&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/docs/DOC-2008"&gt;https://live.paloaltonetworks.com/docs/DOC-2008&lt;/A&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/docs/DOC-2006"&gt;https://live.paloaltonetworks.com/docs/DOC-2006&lt;/A&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;Hope this helps.&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;Thanks&lt;BR /&gt;Numan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Aug 2013 23:07:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/commit-error-vsys1-decryption-forward-decrypt-untrust-cert-is/m-p/6976#M5143</guid>
      <dc:creator>mbutt</dc:creator>
      <dc:date>2013-08-27T23:07:25Z</dc:date>
    </item>
  </channel>
</rss>

