<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Need assistance with Certs and Firewall in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/need-assistance-with-certs-and-firewall/m-p/181970#M56115</link>
    <description>&lt;P&gt;This article was much more helpful.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/How-to-Implement-Certificates-Issued-from-Microsoft-Certificate/ta-p/56757" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/How-to-Implement-Certificates-Issued-from-Microsoft-Certificate/ta-p/56757&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 16 Oct 2017 00:42:19 GMT</pubDate>
    <dc:creator>s.williams1</dc:creator>
    <dc:date>2017-10-16T00:42:19Z</dc:date>
    <item>
      <title>Need assistance with Certs and Firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/need-assistance-with-certs-and-firewall/m-p/181898#M56098</link>
      <description>&lt;P&gt;I has been years since I have done anything with Microsoft CA so I am really struggling.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is the problem:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When enabling URL filtering and I am blocking a certain site that has HTTP and HTTPS, the HTTP page will present the block page, but the HTTPS does not.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am not doing any SSL Decrypt, I want to in the future but that is requiring certs too. Need to work one thing at a time.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So here is the article I am trying to follow:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Serve-a-URL-Response-Page-Over-an-HTTPS-Session-Without/ta-p/55998" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Serve-a-URL-Response-Page-Over-an-HTTPS-Session-Without/ta-p/55998&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;EM&gt;A certificate to be used for Forward Trust on the Palo Alto Networks device. where it is one of the following:&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;EM&gt;A self-signed/self-generated certificate with which the box for "Certificate Authority" has been checked&amp;nbsp;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&lt;STRONG&gt;Note:&lt;/STRONG&gt;&amp;nbsp;if using a self-signed/sef-generated certificate it will be necessary to import this certificate into the client machine's certificate store to avoid unwanted browser certificate errors&lt;/EM&gt;&lt;/LI&gt;&lt;LI&gt;&lt;EM&gt;An intermediate CA certificate installed on the Palo Alto Networks device which was generated by an organization's internal CA.&lt;/EM&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The first option requires me to give my self signed cert to the Systems team and have deploy it out via GP to all clients, that could take a while. So I want the second option. My environment doesnt have an intermediate CA, just a Root CA, so I should be able to import that since all clients already have this cert.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What I can find is how to get the root CA cert on the palo alto. Do I need to do a CSR, I am unsure how to get the root cert with cert and key. I can export it out of my local domain machine, but there is not a key so its useless. So when working with Palo Alto in a MS CA enviroment are there more in depth articles on to perform some of these tasks?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 14 Oct 2017 19:54:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/need-assistance-with-certs-and-firewall/m-p/181898#M56098</guid>
      <dc:creator>s.williams1</dc:creator>
      <dc:date>2017-10-14T19:54:52Z</dc:date>
    </item>
    <item>
      <title>Re: Need assistance with Certs and Firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/need-assistance-with-certs-and-firewall/m-p/181906#M56099</link>
      <description>&lt;P&gt;Update -&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have figured out how to get a sub ca cert in my PA, with some help of Microsoft articles on how to create a template and then generate a CSR within the PA. So for a test I assinged that cert to my WEB GUI authentication to test. When accessing the firewall within Microsoft IE it works flawlessly, no cert errors on HTTPS. Chrome and firefox not so much, obvioulsy when its a MS PKI its going to work just fine in IE, but how do I get this to work within Chrome and Firefox? I cannot go around to all user browsers and install this cert, its not realistic.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 15 Oct 2017 02:18:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/need-assistance-with-certs-and-firewall/m-p/181906#M56099</guid>
      <dc:creator>s.williams1</dc:creator>
      <dc:date>2017-10-15T02:18:05Z</dc:date>
    </item>
    <item>
      <title>Re: Need assistance with Certs and Firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/need-assistance-with-certs-and-firewall/m-p/181908#M56101</link>
      <description>&lt;P&gt;Decrypt is in place, but keep getting this error in the browser:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;NET::ERR_CERT_WEAK_SIGNATURE_ALGORITHM&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;So if I just type "google.com" it redirects it to https and thats the error I get, I cannot not continue. So looking into the error:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class="security-explanation security-explanation-insecure"&gt;&lt;DIV class="security-explanation-text"&gt;&lt;DIV class="security-explanation-title"&gt;Certificate error&lt;/DIV&gt;&lt;DIV&gt;There are issues with the site's certificate chain (net::ERR_CERT_WEAK_SIGNATURE_ALGORITHM).&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="security-explanation security-explanation-neutral"&gt;&lt;DIV class="security-property security-property-neutral"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="security-explanation-text"&gt;&lt;DIV class="security-explanation-title"&gt;SHA-1 certificate&lt;/DIV&gt;&lt;DIV&gt;The certificate chain for this site contains a certificate signed using SHA-1.&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;So it would appear that while my Palo Alto cert is SHA256 hash algorithm, my Root CA is SHA1 &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;And from what I can read SHA1 is not supported with chrome, and I assume most modern browsers. So I assume then when the traffic is being Proxied via the firewall cert and it starts to verify the chain and sees SHA1 it breaks.&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;ANy work arounds to this?&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Sun, 15 Oct 2017 03:09:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/need-assistance-with-certs-and-firewall/m-p/181908#M56101</guid>
      <dc:creator>s.williams1</dc:creator>
      <dc:date>2017-10-15T03:09:52Z</dc:date>
    </item>
    <item>
      <title>Re: Need assistance with Certs and Firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/need-assistance-with-certs-and-firewall/m-p/181942#M56105</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/71957"&gt;@s.williams1&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are you sure that your CA cert is a SHA256 cert on the firewall? Or did you sign your CA cert with an intermediate CA instead of the root?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Chrome should not complain about SHA1 as root cert (at least not now). Chrome only gives you this error when there is a SHA1 CA which is not the root.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Remo&lt;/P&gt;</description>
      <pubDate>Sun, 15 Oct 2017 12:17:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/need-assistance-with-certs-and-firewall/m-p/181942#M56105</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2017-10-15T12:17:43Z</dc:date>
    </item>
    <item>
      <title>Re: Need assistance with Certs and Firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/need-assistance-with-certs-and-firewall/m-p/181948#M56107</link>
      <description>&lt;P&gt;My environment doesnt have an intermediate CA.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I followed this article here:&lt;/P&gt;&lt;P&gt;&lt;A href="https://digitalscepter.com/blog/entry/ssl-decryption-implementation" target="_blank"&gt;https://digitalscepter.com/blog/entry/ssl-decryption-implementation&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I went to my CA server, copied the "subordinate CA template" and renamed it to something with Palo Alto in it. Deployed the template to the CA.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Took the CSR from the generated cert on the palo alto and pasted it into the web enrollment part of the CA and selected the template, downloaded that CA and imported into the Firewall. It is valid.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What am I missing?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 15 Oct 2017 13:55:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/need-assistance-with-certs-and-firewall/m-p/181948#M56107</guid>
      <dc:creator>s.williams1</dc:creator>
      <dc:date>2017-10-15T13:55:03Z</dc:date>
    </item>
    <item>
      <title>Re: Need assistance with Certs and Firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/need-assistance-with-certs-and-firewall/m-p/181970#M56115</link>
      <description>&lt;P&gt;This article was much more helpful.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/How-to-Implement-Certificates-Issued-from-Microsoft-Certificate/ta-p/56757" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/How-to-Implement-Certificates-Issued-from-Microsoft-Certificate/ta-p/56757&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Oct 2017 00:42:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/need-assistance-with-certs-and-firewall/m-p/181970#M56115</guid>
      <dc:creator>s.williams1</dc:creator>
      <dc:date>2017-10-16T00:42:19Z</dc:date>
    </item>
  </channel>
</rss>

