<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Auto update of trusted root CA in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/auto-update-of-trusted-root-ca/m-p/201885#M59616</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Our PANs are not updating the list of trusted root CA certificates which is causing issues with services such as Microsoft Skype for Business and other applications as we have SSL decryption enabled. Using PAN-OS 8.0.7&lt;BR /&gt;&lt;BR /&gt;For example, Microsoft uses certificates signed by DigiCert Baltimore Root. I've checked on Panorama, our DC PANs and our site PANs and none of them have this root CA installed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The enterprise CA &amp;amp; sub-ordinate CA certificates are working fine.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;The issue is with common public trusted CA providers such as DigiCert root CAs not being trusted on the PANs. When these are not trusted by the PAN, SSL decryption breaks for the end user.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Can you please advise as to how we can have these root CA certificates updated automatically?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
    <pubDate>Fri, 23 Feb 2018 04:44:17 GMT</pubDate>
    <dc:creator>Farzana</dc:creator>
    <dc:date>2018-02-23T04:44:17Z</dc:date>
    <item>
      <title>Auto update of trusted root CA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/auto-update-of-trusted-root-ca/m-p/201885#M59616</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Our PANs are not updating the list of trusted root CA certificates which is causing issues with services such as Microsoft Skype for Business and other applications as we have SSL decryption enabled. Using PAN-OS 8.0.7&lt;BR /&gt;&lt;BR /&gt;For example, Microsoft uses certificates signed by DigiCert Baltimore Root. I've checked on Panorama, our DC PANs and our site PANs and none of them have this root CA installed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The enterprise CA &amp;amp; sub-ordinate CA certificates are working fine.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;The issue is with common public trusted CA providers such as DigiCert root CAs not being trusted on the PANs. When these are not trusted by the PAN, SSL decryption breaks for the end user.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Can you please advise as to how we can have these root CA certificates updated automatically?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Feb 2018 04:44:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/auto-update-of-trusted-root-ca/m-p/201885#M59616</guid>
      <dc:creator>Farzana</dc:creator>
      <dc:date>2018-02-23T04:44:17Z</dc:date>
    </item>
    <item>
      <title>Re: Auto update of trusted root CA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/auto-update-of-trusted-root-ca/m-p/202118#M59664</link>
      <description>&lt;P&gt;I'm pretty sure the list of default root CAs only update when you upgrade PAN OS. I don't think they are rolled into any updates.&lt;/P&gt;&lt;P&gt;I'm running 8.0.6 and I have Baltimore_CyberTrust_Root included.&lt;/P&gt;</description>
      <pubDate>Sat, 24 Feb 2018 01:17:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/auto-update-of-trusted-root-ca/m-p/202118#M59664</guid>
      <dc:creator>rmfalconer</dc:creator>
      <dc:date>2018-02-24T01:17:17Z</dc:date>
    </item>
    <item>
      <title>Re: Auto update of trusted root CA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/auto-update-of-trusted-root-ca/m-p/280960#M75895</link>
      <description>&lt;P&gt;I had this issue as well with BitBucket and some other sites I was on code 8.0.7 and upgraded to 8.0.16 and the issue was resolved.&amp;nbsp; I got communication from a Sr DE that there is a refreash feature for the&amp;nbsp;certificate trust list CTL of root CAs in the 8.1 code&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-new-features/networking-features/refresh-of-default-trusted-cas#" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-new-features/networking-features/refresh-of-default-trusted-cas#&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;-Manny&lt;/P&gt;</description>
      <pubDate>Fri, 02 Aug 2019 21:48:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/auto-update-of-trusted-root-ca/m-p/280960#M75895</guid>
      <dc:creator>semzurita</dc:creator>
      <dc:date>2019-08-02T21:48:15Z</dc:date>
    </item>
  </channel>
</rss>

