<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SSL/TLS vs. Chrome [missing_subjectAltName] in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-tls-vs-chrome-missing-subjectaltname/m-p/168532#M53669</link>
    <description>&lt;P&gt;&lt;SPAN&gt;I'm trying to get rid of the warning when I open the PA GUI from Chrome. I'm getting the following warning:&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;This server could not prove that it is&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;192.168.10.4&lt;/STRONG&gt;&lt;SPAN&gt;; its security certificate is from&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;[missing_subjectAltName]&lt;/STRONG&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;First of all, IE is fine, no errors!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have generated the certificate and imported it as my trusted Root CA:&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="cert import.JPG" style="width: 500px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/10542i960E34C42E284354/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="cert import.JPG" alt="cert import.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I have also created a certificate profile (called it GUI) under "Device -&amp;gt; Certificate Managemenet- &amp;gt; SSL/TLS Service Profile", which used the ceriticate above.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Then I went to&amp;nbsp;"&lt;SPAN&gt;Device&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;-&amp;gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;Setup -&amp;gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;M&lt;/SPAN&gt;&lt;SPAN&gt;anagemenet&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;-&amp;gt; SSL/TLS Service Profile" and&amp;nbsp;chose "GUI" (the cerifcate profile above).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;However, Google Chrome does not like it. Off course if I ignore the warning, it works no problem.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Any ideas what I'm missing, or why google doesn't like me?!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 26 Jul 2017 21:28:51 GMT</pubDate>
    <dc:creator>Hwinter</dc:creator>
    <dc:date>2017-07-26T21:28:51Z</dc:date>
    <item>
      <title>SSL/TLS vs. Chrome [missing_subjectAltName]</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-tls-vs-chrome-missing-subjectaltname/m-p/168532#M53669</link>
      <description>&lt;P&gt;&lt;SPAN&gt;I'm trying to get rid of the warning when I open the PA GUI from Chrome. I'm getting the following warning:&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;This server could not prove that it is&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;192.168.10.4&lt;/STRONG&gt;&lt;SPAN&gt;; its security certificate is from&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;[missing_subjectAltName]&lt;/STRONG&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;First of all, IE is fine, no errors!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have generated the certificate and imported it as my trusted Root CA:&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="cert import.JPG" style="width: 500px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/10542i960E34C42E284354/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="cert import.JPG" alt="cert import.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I have also created a certificate profile (called it GUI) under "Device -&amp;gt; Certificate Managemenet- &amp;gt; SSL/TLS Service Profile", which used the ceriticate above.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Then I went to&amp;nbsp;"&lt;SPAN&gt;Device&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;-&amp;gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;Setup -&amp;gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;M&lt;/SPAN&gt;&lt;SPAN&gt;anagemenet&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;-&amp;gt; SSL/TLS Service Profile" and&amp;nbsp;chose "GUI" (the cerifcate profile above).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;However, Google Chrome does not like it. Off course if I ignore the warning, it works no problem.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Any ideas what I'm missing, or why google doesn't like me?!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jul 2017 21:28:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-tls-vs-chrome-missing-subjectaltname/m-p/168532#M53669</guid>
      <dc:creator>Hwinter</dc:creator>
      <dc:date>2017-07-26T21:28:51Z</dc:date>
    </item>
    <item>
      <title>Re: SSL/TLS vs. Chrome [missing_subjectAltName]</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-tls-vs-chrome-missing-subjectaltname/m-p/168542#M53670</link>
      <description>&lt;P&gt;When you generate your certificate, it needs a Subject Alternative Name field for Chrome to play nicely with it. As far as I know, Chrome is the only browser to officially deprecate the Common Name, but Safari and Opera are both based on WebKit, the guts behind Chrome, so I imagine it will be soon that they follow suit.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Internet Explorer, Edge, and Firefox don't enforce this, so they'll likely be fine for a while.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On the firewall, you can generate that by using the two available fields in the certificate generation section:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="cert-create.jpg" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/10543iA3ABA221A5072C7E/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="cert-create.jpg" alt="cert-create.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The&amp;nbsp;&lt;STRONG&gt;Host Name, IP, and Alt Email&lt;/STRONG&gt; fields are all Subject Alternative Name fields, and adding any of them is sufficient to avoid that error. I would recommend matching the CN that you created, unless you really do want to access it with a DNS name, in which case just put that DNS name in the "Host Name" field.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you're generating the cert elsewhere, you will need to figure out how to add the SAN field with that certificate provider.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Greg Wesson&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jul 2017 22:44:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-tls-vs-chrome-missing-subjectaltname/m-p/168542#M53670</guid>
      <dc:creator>gwesson</dc:creator>
      <dc:date>2017-07-26T22:44:37Z</dc:date>
    </item>
    <item>
      <title>Re: SSL/TLS vs. Chrome [missing_subjectAltName]</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-tls-vs-chrome-missing-subjectaltname/m-p/168559#M53672</link>
      <description>&lt;P&gt;Ha! That was easy! Thanks a lot. I've had this issue for months, but I just kept postponing it.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PS: since I'm using the PA as DNS Proxy, I created a static entry for the name I created (pa.local) and&amp;nbsp;as used that for CN and Hostname. Works like a charm!&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2017 01:29:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-tls-vs-chrome-missing-subjectaltname/m-p/168559#M53672</guid>
      <dc:creator>Hwinter</dc:creator>
      <dc:date>2017-07-27T01:29:38Z</dc:date>
    </item>
  </channel>
</rss>

