<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Force to Use Certificate in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/force-to-use-certificate/m-p/250365#M71217</link>
    <description>&lt;P&gt;Dear Friends !&lt;/P&gt;&lt;P&gt;as i study PAN 7.0 if there is no Certificate installed in Client PC, PAN can not read https secure sites&lt;/P&gt;&lt;P&gt;in this is if i block youtube or other social websites and client uninstall CA from its browser he/she will be able to open blocked websites&lt;/P&gt;&lt;P&gt;is there any solution to configure PAN to force user to use CA Certificate, otherwise block them from every type of internet access&lt;/P&gt;</description>
    <pubDate>Mon, 18 Feb 2019 11:45:10 GMT</pubDate>
    <dc:creator>mohammad_mozamel</dc:creator>
    <dc:date>2019-02-18T11:45:10Z</dc:date>
    <item>
      <title>Force to Use Certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/force-to-use-certificate/m-p/250365#M71217</link>
      <description>&lt;P&gt;Dear Friends !&lt;/P&gt;&lt;P&gt;as i study PAN 7.0 if there is no Certificate installed in Client PC, PAN can not read https secure sites&lt;/P&gt;&lt;P&gt;in this is if i block youtube or other social websites and client uninstall CA from its browser he/she will be able to open blocked websites&lt;/P&gt;&lt;P&gt;is there any solution to configure PAN to force user to use CA Certificate, otherwise block them from every type of internet access&lt;/P&gt;</description>
      <pubDate>Mon, 18 Feb 2019 11:45:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/force-to-use-certificate/m-p/250365#M71217</guid>
      <dc:creator>mohammad_mozamel</dc:creator>
      <dc:date>2019-02-18T11:45:10Z</dc:date>
    </item>
    <item>
      <title>Re: Force to Use Certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/force-to-use-certificate/m-p/250388#M71218</link>
      <description>&lt;P&gt;The client only needs to have a root certificate installed for ssl decryption (if you use your company Active Directory CA to sign the decryption certificate, no additional cert needs to be installed)&lt;BR /&gt;&lt;BR /&gt;Without decryption, the firewall will still be able to read the site's certificate to tey and determine the actual site&lt;BR /&gt;You can make your policy more strict so users who uninstall the root certificate will not get internet access, as this can only be the caee if your policy allows them to donthese actions&lt;BR /&gt;&lt;BR /&gt;You may also want to upgrade to PAN-Os 8.0 or 8.1 as many features have been added to improve these mechanisms&lt;/P&gt;</description>
      <pubDate>Tue, 19 Feb 2019 19:17:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/force-to-use-certificate/m-p/250388#M71218</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2019-02-19T19:17:45Z</dc:date>
    </item>
  </channel>
</rss>

