<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Decryption certificate validation issue in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/decryption-certificate-validation-issue/m-p/276998#M75402</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your help, It works after adding certificate and marking it as trusted.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;BR /&gt;Venky&lt;/P&gt;</description>
    <pubDate>Wed, 17 Jul 2019 10:41:03 GMT</pubDate>
    <dc:creator>Venkatesan_radhakrishnan</dc:creator>
    <dc:date>2019-07-17T10:41:03Z</dc:date>
    <item>
      <title>Decryption certificate validation issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/decryption-certificate-validation-issue/m-p/276646#M75367</link>
      <description>&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm experiencing issue where one of the site is not accessible when the decryption profile is enable with no decryption for SSL forward proxy. After disabling the block untrusted issue I'm able to access the&amp;nbsp; site.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm facing this issue in PA 850 Platform PANOS 8.1.8. We have upgraded the PANOS from 8.1.7 to 8.1.8.&lt;/P&gt;&lt;P&gt;Also would like to add the certificate are in default trust certificate store.&lt;/P&gt;&lt;P&gt;site is &lt;A href="https://www.axa-portal.com" target="_blank"&gt;https://www.axa-portal.com&lt;/A&gt;, Have anyone experience this behaviour.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Venky&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jul 2019 17:58:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/decryption-certificate-validation-issue/m-p/276646#M75367</guid>
      <dc:creator>Venkatesan_radhakrishnan</dc:creator>
      <dc:date>2019-07-15T17:58:03Z</dc:date>
    </item>
    <item>
      <title>Re: Decryption certificate validation issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/decryption-certificate-validation-issue/m-p/276668#M75369</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/97701"&gt;@Venkatesan_radhakrishnan&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;The intermediary cert in that chain is not trusted by default on the firewall; you will need to manually add it and mark it as a trusted certificate to get the website to function with a decryption policy attached.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jul 2019 20:13:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/decryption-certificate-validation-issue/m-p/276668#M75369</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-07-15T20:13:51Z</dc:date>
    </item>
    <item>
      <title>Re: Decryption certificate validation issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/decryption-certificate-validation-issue/m-p/276720#M75373</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your reply, I have tried to replicate this issue in my lab. I'm not seeing the same issue.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My lab firewall doesn't have intermediate certificate trusted in default trust store but the website works fine.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also I'm seeing this error DECRYPT_CERT_VALIDATION only after upgrading from PANOS 8.1.7 to 8.1.8.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jul 2019 06:01:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/decryption-certificate-validation-issue/m-p/276720#M75373</guid>
      <dc:creator>Venkatesan_radhakrishnan</dc:creator>
      <dc:date>2019-07-16T06:01:48Z</dc:date>
    </item>
    <item>
      <title>Re: Decryption certificate validation issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/decryption-certificate-validation-issue/m-p/276998#M75402</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your help, It works after adding certificate and marking it as trusted.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;BR /&gt;Venky&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jul 2019 10:41:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/decryption-certificate-validation-issue/m-p/276998#M75402</guid>
      <dc:creator>Venkatesan_radhakrishnan</dc:creator>
      <dc:date>2019-07-17T10:41:03Z</dc:date>
    </item>
    <item>
      <title>Re: Decryption certificate validation issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/decryption-certificate-validation-issue/m-p/277085#M75411</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there a better way to proceed than manually adding certs that are missing in the chain?&amp;nbsp; Or is it just kind of stuck the way it is?&amp;nbsp; I'm guessing once these certs expire, you either find out the hard way, or monitor the certs in your store to keep an eye on anything getting close to expiration?&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jul 2019 17:03:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/decryption-certificate-validation-issue/m-p/277085#M75411</guid>
      <dc:creator>Sec101</dc:creator>
      <dc:date>2019-07-17T17:03:23Z</dc:date>
    </item>
    <item>
      <title>Re: Decryption certificate validation issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/decryption-certificate-validation-issue/m-p/277086#M75412</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/59122"&gt;@Sec101&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;If there is I don't know about it, I believe that you're just kind&amp;nbsp; of&amp;nbsp; stuck managing the cert as you would if you had imported your own. The benefit is that usually the big public Certificate authorities will start using a different intermediarry instead of renewing the cert, so you essentially just have to add the new certificate and then remove any that actually expire.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jul 2019 17:08:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/decryption-certificate-validation-issue/m-p/277086#M75412</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-07-17T17:08:32Z</dc:date>
    </item>
    <item>
      <title>Re: Decryption certificate validation issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/decryption-certificate-validation-issue/m-p/277088#M75414</link>
      <description>&lt;P&gt;Ah. I see.&amp;nbsp; Thank you very much for the insight.&amp;nbsp; Good to know!&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jul 2019 17:12:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/decryption-certificate-validation-issue/m-p/277088#M75414</guid>
      <dc:creator>Sec101</dc:creator>
      <dc:date>2019-07-17T17:12:13Z</dc:date>
    </item>
  </channel>
</rss>

