<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: can i use ssl decryption cert for web gui in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/can-i-use-ssl-decryption-cert-for-web-gui/m-p/249200#M70873</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/75039"&gt;@MP18&lt;/a&gt;&amp;nbsp;,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;certicate error can be because of&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Not issued by trusted CA&lt;/LI&gt;&lt;LI&gt;Issued to someone else ( cn mismatch)&lt;/LI&gt;&lt;LI&gt;expired...etc&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;About decryption certificate,&lt;/P&gt;&lt;P&gt;please note that you wil get certificate error if the certificate was note issued by a trusted root CA by your browser/PC.&lt;/P&gt;&lt;P&gt;As no CAs will be providing a certificate with CA flag ( capable of signing certificate) because of security reasons, you will be generating this in PA, which means it is self signed, so it is not trusted by any browser/machine otherthan this PA unless you manually import this cert in PC/browsers trusterd authority.&lt;/P&gt;&lt;P&gt;so when you use this cert for web GUI, it is expected that you will get the error. you can just use it&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you want a trusted certificate for your web access to avoid warning, you can get it from any of trusted CA, need put one of fqdn/ip in common name field, add other one alternative name. import in palo alto, use it for web access. this is cost involved..&lt;/P&gt;</description>
    <pubDate>Thu, 07 Feb 2019 13:52:56 GMT</pubDate>
    <dc:creator>Abdul_Razaq</dc:creator>
    <dc:date>2019-02-07T13:52:56Z</dc:date>
    <item>
      <title>can i use ssl decryption cert for web gui</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-i-use-ssl-decryption-cert-for-web-gui/m-p/249063#M70849</link>
      <description>&lt;P&gt;we have ssl decryption enabled and using our own CA as Internal Root Certificate.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For webgui we get cert warning can i use same cert for Web gui to PA?&lt;/P&gt;</description>
      <pubDate>Wed, 06 Feb 2019 20:11:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-i-use-ssl-decryption-cert-for-web-gui/m-p/249063#M70849</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-02-06T20:11:06Z</dc:date>
    </item>
    <item>
      <title>Re: can i use ssl decryption cert for web gui</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-i-use-ssl-decryption-cert-for-web-gui/m-p/249088#M70851</link>
      <description>&lt;P&gt;The cert you use for the gui will cause warnings for the same reason that any cert does. If the cert used for the gui is issued by an authority that your endpoint trusts, has the correct name and isn't expired, it shouldn't cause a warning.&lt;/P&gt;&lt;P&gt;For the gui, I create a cert with the firewall fqdn as the subject with&amp;nbsp;SAN entries for the fqdn, firewall name and IP address. This tends to catch how we connect to the gui and eliminates errors.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Feb 2019 22:07:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-i-use-ssl-decryption-cert-for-web-gui/m-p/249088#M70851</guid>
      <dc:creator>rmfalconer</dc:creator>
      <dc:date>2019-02-06T22:07:32Z</dc:date>
    </item>
    <item>
      <title>Re: can i use ssl decryption cert for web gui</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-i-use-ssl-decryption-cert-for-web-gui/m-p/249090#M70852</link>
      <description>&lt;P&gt;i already have Trusted Root CA that all pc trusts.&lt;/P&gt;&lt;P&gt;SSL decrypt cert&amp;nbsp; is created from the root as intermediate.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So ok to use that for gui?&lt;/P&gt;</description>
      <pubDate>Wed, 06 Feb 2019 22:10:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-i-use-ssl-decryption-cert-for-web-gui/m-p/249090#M70852</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-02-06T22:10:15Z</dc:date>
    </item>
    <item>
      <title>Re: can i use ssl decryption cert for web gui</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-i-use-ssl-decryption-cert-for-web-gui/m-p/249093#M70855</link>
      <description>&lt;P&gt;You can use any certificate for the gui, just select it in the TLS profile you use for the web management. But if you re-use a cert that was meant for something else, you may still get warnings.&lt;/P&gt;&lt;P&gt;If the current cert has a subject of firewall.company.com and you access the gui with 10.1.1.1, you'll still get a warning from the browser since the address doesn't match the info on the cert.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Feb 2019 22:44:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-i-use-ssl-decryption-cert-for-web-gui/m-p/249093#M70855</guid>
      <dc:creator>rmfalconer</dc:creator>
      <dc:date>2019-02-06T22:44:10Z</dc:date>
    </item>
    <item>
      <title>Re: can i use ssl decryption cert for web gui</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-i-use-ssl-decryption-cert-for-web-gui/m-p/249158#M70862</link>
      <description>&lt;P&gt;Yea..you can use it for GUI as well,&lt;/P&gt;&lt;P&gt;the certificate you are using for forward proxy should be a CA certificate ( certificate signing should be selected under key usage while generating certificate). once you select this certificate as forward trust/untrust, this certificate will be used for proxying accordingly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The certificate used for web GUI need not to sign any other certificates, it just need to be end entity, even you can use a CA certificate as well for this purpose.&lt;/P&gt;&lt;P&gt;Just create a ssl/tls profile and call this certificate under. use this profile in management configuration.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Feb 2019 08:32:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-i-use-ssl-decryption-cert-for-web-gui/m-p/249158#M70862</guid>
      <dc:creator>Abdul_Razaq</dc:creator>
      <dc:date>2019-02-07T08:32:16Z</dc:date>
    </item>
    <item>
      <title>Re: can i use ssl decryption cert for web gui</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-i-use-ssl-decryption-cert-for-web-gui/m-p/249190#M70869</link>
      <description>&lt;P&gt;I tried to use my current ssl decrtypt cert also as web gui&lt;/P&gt;&lt;P&gt;then i login to PA it still gives me warning message not trusted?&lt;/P&gt;</description>
      <pubDate>Thu, 07 Feb 2019 12:54:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-i-use-ssl-decryption-cert-for-web-gui/m-p/249190#M70869</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-02-07T12:54:25Z</dc:date>
    </item>
    <item>
      <title>Re: can i use ssl decryption cert for web gui</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-i-use-ssl-decryption-cert-for-web-gui/m-p/249200#M70873</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/75039"&gt;@MP18&lt;/a&gt;&amp;nbsp;,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;certicate error can be because of&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Not issued by trusted CA&lt;/LI&gt;&lt;LI&gt;Issued to someone else ( cn mismatch)&lt;/LI&gt;&lt;LI&gt;expired...etc&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;About decryption certificate,&lt;/P&gt;&lt;P&gt;please note that you wil get certificate error if the certificate was note issued by a trusted root CA by your browser/PC.&lt;/P&gt;&lt;P&gt;As no CAs will be providing a certificate with CA flag ( capable of signing certificate) because of security reasons, you will be generating this in PA, which means it is self signed, so it is not trusted by any browser/machine otherthan this PA unless you manually import this cert in PC/browsers trusterd authority.&lt;/P&gt;&lt;P&gt;so when you use this cert for web GUI, it is expected that you will get the error. you can just use it&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you want a trusted certificate for your web access to avoid warning, you can get it from any of trusted CA, need put one of fqdn/ip in common name field, add other one alternative name. import in palo alto, use it for web access. this is cost involved..&lt;/P&gt;</description>
      <pubDate>Thu, 07 Feb 2019 13:52:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-i-use-ssl-decryption-cert-for-web-gui/m-p/249200#M70873</guid>
      <dc:creator>Abdul_Razaq</dc:creator>
      <dc:date>2019-02-07T13:52:56Z</dc:date>
    </item>
    <item>
      <title>Re: can i use ssl decryption cert for web gui</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-i-use-ssl-decryption-cert-for-web-gui/m-p/249271#M70886</link>
      <description>&lt;P&gt;What are the common name and the SAN entries for the certificate? Do any of those match the URL of the web GUI?&lt;/P&gt;</description>
      <pubDate>Thu, 07 Feb 2019 16:57:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-i-use-ssl-decryption-cert-for-web-gui/m-p/249271#M70886</guid>
      <dc:creator>rmfalconer</dc:creator>
      <dc:date>2019-02-07T16:57:33Z</dc:date>
    </item>
    <item>
      <title>Re: can i use ssl decryption cert for web gui</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-i-use-ssl-decryption-cert-for-web-gui/m-p/249328#M70899</link>
      <description>&lt;P&gt;No common name does not match the webgui for the firewall.&lt;/P&gt;&lt;P&gt;SSL decryption has different common name&lt;/P&gt;</description>
      <pubDate>Thu, 07 Feb 2019 19:54:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-i-use-ssl-decryption-cert-for-web-gui/m-p/249328#M70899</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-02-07T19:54:54Z</dc:date>
    </item>
    <item>
      <title>Re: can i use ssl decryption cert for web gui</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-i-use-ssl-decryption-cert-for-web-gui/m-p/249332#M70901</link>
      <description>&lt;P&gt;Then the warning is expected. As I said previously, the browser will give a warning if the proper name or IP address is not the CN or included as a SAN entry.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Feb 2019 20:38:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-i-use-ssl-decryption-cert-for-web-gui/m-p/249332#M70901</guid>
      <dc:creator>rmfalconer</dc:creator>
      <dc:date>2019-02-07T20:38:40Z</dc:date>
    </item>
    <item>
      <title>Re: can i use ssl decryption cert for web gui</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-i-use-ssl-decryption-cert-for-web-gui/m-p/249385#M70919</link>
      <description>&lt;P&gt;Many Thanks for help&lt;/P&gt;</description>
      <pubDate>Fri, 08 Feb 2019 03:38:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-i-use-ssl-decryption-cert-for-web-gui/m-p/249385#M70919</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-02-08T03:38:04Z</dc:date>
    </item>
  </channel>
</rss>

