<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Is it possible to use wildcard certificate as forward trust certificate? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-use-wildcard-certificate-as-forward-trust/m-p/288371#M76831</link>
    <description>&lt;P&gt;You can not user the wildcard certificate nor the other ones for forward trust.&lt;/P&gt;</description>
    <pubDate>Fri, 13 Sep 2019 14:09:06 GMT</pubDate>
    <dc:creator>tommyschoemans</dc:creator>
    <dc:date>2019-09-13T14:09:06Z</dc:date>
    <item>
      <title>Is it possible to use wildcard certificate as forward trust certificate?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-use-wildcard-certificate-as-forward-trust/m-p/288179#M76809</link>
      <description>&lt;P&gt;I have a wildcard certificate that already works for global protect portal and gateway.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="cert-palo.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21363i395F8A50D008A476/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="cert-palo.png" alt="cert-palo.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I would like to make this trusted certificate to be used for SSL decryption (forward-proxy mode) but I can't make any of those certificate to be Forward Trust Certificate because the checkbox is greyed out.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_45.jpg" style="width: 176px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21364i0DDC82C4F583A0C1/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Screenshot_45.jpg" alt="Screenshot_45.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;So, is it possible to use wildcard certificate as forward trust certificate? if yes, how to do that?&lt;BR /&gt;&lt;BR /&gt;Thanks in advance&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Sep 2019 22:43:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-use-wildcard-certificate-as-forward-trust/m-p/288179#M76809</guid>
      <dc:creator>nugroho</dc:creator>
      <dc:date>2019-09-12T22:43:20Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to use wildcard certificate as forward trust certificate?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-use-wildcard-certificate-as-forward-trust/m-p/288200#M76811</link>
      <description>&lt;P&gt;Hey,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It needs to be a certificate of the type CA, then you should be able to use it as a forward trust certificate.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;kr,&lt;/P&gt;&lt;P&gt;Tommy&lt;/P&gt;</description>
      <pubDate>Fri, 13 Sep 2019 05:51:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-use-wildcard-certificate-as-forward-trust/m-p/288200#M76811</guid>
      <dc:creator>tommyschoemans</dc:creator>
      <dc:date>2019-09-13T05:51:37Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to use wildcard certificate as forward trust certificate?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-use-wildcard-certificate-as-forward-trust/m-p/288203#M76813</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/38037"&gt;@tommyschoemans&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I couldn't quite understand what do you mean by type CA (I'm not really familiar with certificates). Is there any info that I not included in question that I should provide to determine whether is it possible or not using my current certificate as&amp;nbsp;forward trust certificate?&lt;BR /&gt;In case you mean that it is possible with my certificate to set it as forward trust certificate, how could I do that? because as I state in the question, I can't set it because it is greyed out and I don't know the reason why is it greyed out.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Sep 2019 06:22:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-use-wildcard-certificate-as-forward-trust/m-p/288203#M76813</guid>
      <dc:creator>nugroho</dc:creator>
      <dc:date>2019-09-13T06:22:41Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to use wildcard certificate as forward trust certificate?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-use-wildcard-certificate-as-forward-trust/m-p/288213#M76815</link>
      <description>&lt;P&gt;The reason for it being greyed out is because the certificate is not a CA one ( CA column not checked ). A CA or intermediate CA can sign certificates. Your wildcard certificate is signed by Cert Comodo Int1 and this is signed by cert Comodo Int2, etc...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In order to do SSL inspection you need to have a certificate that can sign certificates on behalf of the intercepted webiste to present to the end-users. So you just need to create yourself a root or intermediate CA ( preferably ) to use as a forward trtust certificate. Easiest is if you have a Microsoft AD you can use the MS PKI and create one here. The certificate will already be trusted by your AD members. Otherwise just use openSSL and have the CA certificate imported in the windows certificate store and if using Firefox certificate store.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;kr,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tommy&lt;/P&gt;</description>
      <pubDate>Fri, 13 Sep 2019 07:12:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-use-wildcard-certificate-as-forward-trust/m-p/288213#M76815</guid>
      <dc:creator>tommyschoemans</dc:creator>
      <dc:date>2019-09-13T07:12:39Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to use wildcard certificate as forward trust certificate?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-use-wildcard-certificate-as-forward-trust/m-p/288354#M76826</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/38037"&gt;@tommyschoemans&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I see, please confirm this, so I can't use my current certificates (Cert COMODO Root, COMODO Int1, COMODO Int2 or wildcard which is signed by COMODO) to use as forward trust certificate, right?&lt;/P&gt;&lt;P&gt;I will close my questions (accept solutions) once this confirmed.&lt;BR /&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Sep 2019 13:18:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-use-wildcard-certificate-as-forward-trust/m-p/288354#M76826</guid>
      <dc:creator>nugroho</dc:creator>
      <dc:date>2019-09-13T13:18:33Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to use wildcard certificate as forward trust certificate?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-use-wildcard-certificate-as-forward-trust/m-p/288371#M76831</link>
      <description>&lt;P&gt;You can not user the wildcard certificate nor the other ones for forward trust.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Sep 2019 14:09:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-use-wildcard-certificate-as-forward-trust/m-p/288371#M76831</guid>
      <dc:creator>tommyschoemans</dc:creator>
      <dc:date>2019-09-13T14:09:06Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to use wildcard certificate as forward trust certificate?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-use-wildcard-certificate-as-forward-trust/m-p/514915#M106857</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;
&lt;P&gt;Can I use wild card Certificate for Decryption Policy.&lt;/P&gt;</description>
      <pubDate>Thu, 15 Sep 2022 05:34:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-use-wildcard-certificate-as-forward-trust/m-p/514915#M106857</guid>
      <dc:creator>MangeshM</dc:creator>
      <dc:date>2022-09-15T05:34:13Z</dc:date>
    </item>
  </channel>
</rss>

