<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Putting PA SSL decrypt certificate in other people in chrome in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/putting-pa-ssl-decrypt-certificate-in-other-people-in-chrome/m-p/247704#M70480</link>
    <description>&lt;P&gt;There are now more than one problems that lead to your situation:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;If the root CA cert is not in the trusted root store, then it is normal, that you are able to connect to some websites when you ignore the cert warning&lt;/LI&gt;&lt;LI&gt;Websites that partly work is probably because you ignore the cert warning for the main page, but because javascript, css, images, ... are pulled from other domains you can't see the cert warning and so cannot ignore it and the connection fails&lt;/LI&gt;&lt;LI&gt;If you were connected once successfully (without decryption) to websites that have HSTS (https strict transport security) configured, then your browser will store this header locally. When you connect again to such a website and the HSTS entry did not time out, then as described in HSTS RFC the browser is not allowed to give you a possibility to ignore the warning --&amp;gt; rhe connection fails completely&lt;/LI&gt;&lt;/OL&gt;</description>
    <pubDate>Sun, 27 Jan 2019 11:36:36 GMT</pubDate>
    <dc:creator>Remo</dc:creator>
    <dc:date>2019-01-27T11:36:36Z</dc:date>
    <item>
      <title>Putting PA SSL decrypt certificate in other people in chrome</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/putting-pa-ssl-decrypt-certificate-in-other-people-in-chrome/m-p/247666#M70469</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i found that my PA cert for ssl decryption is&amp;nbsp; under other people in chrome not in trusted root on one of computers.&lt;/P&gt;&lt;P&gt;still i am able to access websites where ssl&amp;nbsp; decryption is enabled&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;any thoughts?&lt;/P&gt;</description>
      <pubDate>Sat, 26 Jan 2019 18:45:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/putting-pa-ssl-decrypt-certificate-in-other-people-in-chrome/m-p/247666#M70469</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-01-26T18:45:59Z</dc:date>
    </item>
    <item>
      <title>Re: Putting PA SSL decrypt certificate in other people in chrome</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/putting-pa-ssl-decrypt-certificate-in-other-people-in-chrome/m-p/247679#M70470</link>
      <description>&lt;P&gt;Are you able to access any website? Does a cert warning show up or does it work as expected? Or are just the websites working where you already ignored the cert warning?&lt;/P&gt;</description>
      <pubDate>Sat, 26 Jan 2019 20:45:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/putting-pa-ssl-decrypt-certificate-in-other-people-in-chrome/m-p/247679#M70470</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2019-01-26T20:45:04Z</dc:date>
    </item>
    <item>
      <title>Re: Putting PA SSL decrypt certificate in other people in chrome</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/putting-pa-ssl-decrypt-certificate-in-other-people-in-chrome/m-p/247694#M70478</link>
      <description>&lt;P&gt;i tested some websites i can not access at all&amp;nbsp; tried few times they all have below message&lt;/P&gt;&lt;P&gt;i get error message&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;privacy error&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;your connection is not private&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;cert had warning it shows for example&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;issue to linkedin.com&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;issued by 10.1.20.1 -----------PA&amp;nbsp; cert&lt;/P&gt;&lt;DIV&gt;&lt;DIV&gt;Your connection is not private&lt;P&gt;Attackers might be trying to steal your information from&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;A href="http://www.linkedin.com" target="_blank"&gt;www.linkedin.com&lt;/A&gt;&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;(for example, passwords, messages, or credit cards).&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Learn more&lt;/P&gt;&lt;DIV&gt;&lt;DIV class="error-code"&gt;NET::ERR_CERT_AUTHORITY_INVALID&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="ssl-opt-in"&gt;&lt;DIV class="checkboxes"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;SPAN&gt;Help improve Safe Browsing by sending some&amp;nbsp;system information and page content&amp;nbsp;to Google.&amp;nbsp;Privacy policy&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="nav-wrapper"&gt;ReloadHide advanced&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;***********************************&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;then website which opens up it also has cert warning not secure&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;issued to bmo,com&lt;/P&gt;&lt;P&gt;issued by 10.1.20.1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;but webpage opens up with scrambled characters.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;why some web sites does not open at all and some open up with not proper displays?&lt;/P&gt;</description>
      <pubDate>Sun, 27 Jan 2019 00:18:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/putting-pa-ssl-decrypt-certificate-in-other-people-in-chrome/m-p/247694#M70478</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-01-27T00:18:14Z</dc:date>
    </item>
    <item>
      <title>Re: Putting PA SSL decrypt certificate in other people in chrome</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/putting-pa-ssl-decrypt-certificate-in-other-people-in-chrome/m-p/247704#M70480</link>
      <description>&lt;P&gt;There are now more than one problems that lead to your situation:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;If the root CA cert is not in the trusted root store, then it is normal, that you are able to connect to some websites when you ignore the cert warning&lt;/LI&gt;&lt;LI&gt;Websites that partly work is probably because you ignore the cert warning for the main page, but because javascript, css, images, ... are pulled from other domains you can't see the cert warning and so cannot ignore it and the connection fails&lt;/LI&gt;&lt;LI&gt;If you were connected once successfully (without decryption) to websites that have HSTS (https strict transport security) configured, then your browser will store this header locally. When you connect again to such a website and the HSTS entry did not time out, then as described in HSTS RFC the browser is not allowed to give you a possibility to ignore the warning --&amp;gt; rhe connection fails completely&lt;/LI&gt;&lt;/OL&gt;</description>
      <pubDate>Sun, 27 Jan 2019 11:36:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/putting-pa-ssl-decrypt-certificate-in-other-people-in-chrome/m-p/247704#M70480</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2019-01-27T11:36:36Z</dc:date>
    </item>
    <item>
      <title>Re: Putting PA SSL decrypt certificate in other people in chrome</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/putting-pa-ssl-decrypt-certificate-in-other-people-in-chrome/m-p/247717#M70483</link>
      <description>&lt;P&gt;Thanks for reply back&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2&amp;gt;Websites that partly work is probably because you ignore the cert warning for the main page, but because javascript, css, images, ... are pulled from other domains you can't see the cert warning and so cannot ignore it and the connection fails.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For above I tested for e.g website bmo.ca i get warning&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This server could not prove that it is&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;www1.bmo.com&lt;/STRONG&gt;; its security certificate is not trusted by your computer's operating system. This may be caused by a misconfiguration or an attacker intercepting your connection.&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF6600"&gt;Proceed to ww&amp;nbsp;&amp;nbsp;w1.bmo.com (unsafe)&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;for this website i ignore the warning for main page and proceed so this works fine.&lt;/P&gt;&lt;P&gt;This part i got it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;FONT color="#FF6600"&gt;When you say&amp;nbsp;but because javascript, css, images, ... are pulled from other domains you can't see the cert warning and so cannot ignore it and the connection fails&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;FONT color="#FF6600"&gt;does this refer to websites where i do not get cert warning and there is no option for me to click on proceed ??&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;FONT color="#FF6600"&gt;3&amp;gt;&lt;/FONT&gt;&lt;/STRONG&gt;&lt;FONT color="#FF6600"&gt;&lt;FONT color="#000000"&gt;for&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;when you connect again to such a website and the HSTS entry did not time out, then as described in HSTS RFC the browser is not allowed to give you a possibility to ignore the warning --&amp;gt; rhe connection fails completely&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;FONT color="#FF6600"&gt;Do you refer here connecting again when ssl decryption is enabled?&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 27 Jan 2019 18:00:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/putting-pa-ssl-decrypt-certificate-in-other-people-in-chrome/m-p/247717#M70483</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-01-27T18:00:14Z</dc:date>
    </item>
    <item>
      <title>Re: Putting PA SSL decrypt certificate in other people in chrome</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/putting-pa-ssl-decrypt-certificate-in-other-people-in-chrome/m-p/247734#M70489</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/75039"&gt;@MP18&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;&lt;STRONG&gt;&lt;FONT color="#FF6600"&gt;does this refer to websites where i do not get cert warning and there is no option for me to click on proceed ??&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;This one applies to website that show everything a little scrambled which is because the main page can load but css and javascripts, that are required for the website to show properly, cannot load as you don't see a cert warning for these other domains.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/75039"&gt;@MP18&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;&lt;STRONG&gt;&lt;FONT color="#FF6600"&gt;Do you refer here connecting again when ssl decryption is enabled?&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Exactly&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 27 Jan 2019 19:29:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/putting-pa-ssl-decrypt-certificate-in-other-people-in-chrome/m-p/247734#M70489</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2019-01-27T19:29:19Z</dc:date>
    </item>
  </channel>
</rss>

