<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSL inbound inspection cert in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-inbound-inspection-cert/m-p/335038#M84468</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for chiming In.. yes, when you are doing Inbound SSL decryption, the cert is NOT an CA..&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 24 Jun 2020 15:08:44 GMT</pubDate>
    <dc:creator>jdelio</dc:creator>
    <dc:date>2020-06-24T15:08:44Z</dc:date>
    <item>
      <title>SSL inbound inspection cert</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-inbound-inspection-cert/m-p/334848#M84431</link>
      <description>&lt;P&gt;Might be silly question, For inbound inspection does the cert has to be a CA.&lt;/P&gt;&lt;P&gt;We use a wildcart so that will have to imported as CA, correct?&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jun 2020 18:30:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-inbound-inspection-cert/m-p/334848#M84431</guid>
      <dc:creator>raji_toor</dc:creator>
      <dc:date>2020-06-23T18:30:16Z</dc:date>
    </item>
    <item>
      <title>Re: SSL inbound inspection cert</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-inbound-inspection-cert/m-p/334881#M84435</link>
      <description>&lt;P&gt;Are there any KB articles or resources for import a certificate for inbound SSL inspection. We do have outbound SSL inspection working with certificate from our internal CA.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jun 2020 21:06:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-inbound-inspection-cert/m-p/334881#M84435</guid>
      <dc:creator>raji_toor</dc:creator>
      <dc:date>2020-06-23T21:06:29Z</dc:date>
    </item>
    <item>
      <title>Re: SSL inbound inspection cert</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-inbound-inspection-cert/m-p/334884#M84437</link>
      <description>&lt;P&gt;The thing about a Decryption Certificate is that it needs to create certificates on the fly as part of the decryption process (Man in the Middle).&amp;nbsp; You cannot purchase a 3rd Party CA (Certificate Authority) , as there is no way that GoDaddy or anyone else would allow you to create their SSL Certs (what a CA does).&amp;nbsp; You either have to have an internal CA that you grant a CA to the Firewall to use as its own (And be trusted) or to use the Firewall as the CA.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just about every SSL article that we have talks about using the built in CA on the Firewall, but I will see if I can find any that may explain the use of an External CA.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jun 2020 21:30:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-inbound-inspection-cert/m-p/334884#M84437</guid>
      <dc:creator>jdelio</dc:creator>
      <dc:date>2020-06-23T21:30:51Z</dc:date>
    </item>
    <item>
      <title>Re: SSL inbound inspection cert</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-inbound-inspection-cert/m-p/334887#M84440</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/23567"&gt;@jdelio&lt;/a&gt;&amp;nbsp; Thanks for response..Yes all articles and videos show with self signed cert. But i can't use this self signed cert for our publicly exposed websites, it has to be a cert from external CA. Self signed can work if it was outbound encryption, which we are already performing with cert from our internal CA.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jun 2020 21:36:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-inbound-inspection-cert/m-p/334887#M84440</guid>
      <dc:creator>raji_toor</dc:creator>
      <dc:date>2020-06-23T21:36:59Z</dc:date>
    </item>
    <item>
      <title>Re: SSL inbound inspection cert</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-inbound-inspection-cert/m-p/334888#M84441</link>
      <description>&lt;P&gt;OK, you are talking about 2 things..&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. Outbound SSL Decryption - Where you use an Internal CA as the CA to create certs for internal users so they natively trust the CA cert.&lt;/P&gt;
&lt;P&gt;2. Inbound SSL Decryption - Where you have a Web server that you want the firewall to decrypt traffic on behalf of.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In the second case, you end up using the Certificate from the Web Server.&amp;nbsp; Essentially Posing AS that Web server, so you can decrypt and encrypt the traffic.&amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So, wherever you purchased the Cert for the Web server, you would just install that certificate on the firewall and use that cert for Inbound SSL decryption..&amp;nbsp; &amp;nbsp;I am sure we have something on that..&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jun 2020 21:45:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-inbound-inspection-cert/m-p/334888#M84441</guid>
      <dc:creator>jdelio</dc:creator>
      <dc:date>2020-06-23T21:45:04Z</dc:date>
    </item>
    <item>
      <title>Re: SSL inbound inspection cert</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-inbound-inspection-cert/m-p/334889#M84442</link>
      <description>&lt;P&gt;Here is one that I created on SSL decryption&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/tutorials/how-to-configure-ssl-decryption/ta-p/65073" target="_blank"&gt;https://live.paloaltonetworks.com/t5/tutorials/how-to-configure-ssl-decryption/ta-p/65073&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also, FYI here is the SSL Decryption resource list:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/management-articles/ssl-decryption-resource-list/ta-p/70397" target="_blank"&gt;https://live.paloaltonetworks.com/t5/management-articles/ssl-decryption-resource-list/ta-p/70397&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;hope this helps..&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jun 2020 21:50:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-inbound-inspection-cert/m-p/334889#M84442</guid>
      <dc:creator>jdelio</dc:creator>
      <dc:date>2020-06-23T21:50:28Z</dc:date>
    </item>
    <item>
      <title>Re: SSL inbound inspection cert</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-inbound-inspection-cert/m-p/334933#M84449</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/56221"&gt;@raji_toor&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;When setting up inbound inspection the certificate won't be a CA cert, you're just going to import the certificate and the private key. The following documentation will walk you through the setup process. Just keep in mind you'll likely want to limit the decryption rule base entry to a select test IP when getting everything setup so you don't cause any security issues on your public resource.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/decryption/configure-ssl-inbound-inspection.html" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/decryption/configure-ssl-inbound-inspection.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jun 2020 04:40:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-inbound-inspection-cert/m-p/334933#M84449</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-06-24T04:40:00Z</dc:date>
    </item>
    <item>
      <title>Re: SSL inbound inspection cert</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-inbound-inspection-cert/m-p/335038#M84468</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for chiming In.. yes, when you are doing Inbound SSL decryption, the cert is NOT an CA..&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jun 2020 15:08:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-inbound-inspection-cert/m-p/335038#M84468</guid>
      <dc:creator>jdelio</dc:creator>
      <dc:date>2020-06-24T15:08:44Z</dc:date>
    </item>
    <item>
      <title>Re: SSL inbound inspection cert</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-inbound-inspection-cert/m-p/335082#M84476</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;and&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/23567"&gt;@jdelio&lt;/a&gt;&amp;nbsp;Thanks for inputs. I had my head stuck with the way we did outbound decryption which was incorrect for inbound inspection.&amp;nbsp;&lt;/P&gt;&lt;P&gt;And just FYI the links shared earlier, i don't have access to them.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I used the wildcard cert now that we also use for GlobalProtect, but the first attempts are failing. I have opened a new discussion for that.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jun 2020 18:44:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-inbound-inspection-cert/m-p/335082#M84476</guid>
      <dc:creator>raji_toor</dc:creator>
      <dc:date>2020-06-24T18:44:19Z</dc:date>
    </item>
    <item>
      <title>Re: SSL inbound inspection cert</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-inbound-inspection-cert/m-p/335316#M84516</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/56221"&gt;@raji_toor&lt;/a&gt;&amp;nbsp; You do not have access to those articles?&amp;nbsp; Do you get an error? everyone should have access to those.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jun 2020 14:57:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-inbound-inspection-cert/m-p/335316#M84516</guid>
      <dc:creator>jdelio</dc:creator>
      <dc:date>2020-06-25T14:57:49Z</dc:date>
    </item>
    <item>
      <title>Re: SSL inbound inspection cert</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-inbound-inspection-cert/m-p/335341#M84519</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/23567"&gt;@jdelio&lt;/a&gt;&amp;nbsp;This is what i get on clicking the links&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="raji_toor_0-1593099595978.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/26419i6DE7E35D6B22DB13/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="raji_toor_0-1593099595978.png" alt="raji_toor_0-1593099595978.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jun 2020 15:40:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-inbound-inspection-cert/m-p/335341#M84519</guid>
      <dc:creator>raji_toor</dc:creator>
      <dc:date>2020-06-25T15:40:04Z</dc:date>
    </item>
    <item>
      <title>Re: SSL inbound inspection cert</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-inbound-inspection-cert/m-p/335419#M84530</link>
      <description>&lt;P&gt;That is not right, especially since you are already a customer.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please allow us to investigate why this is happening.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jun 2020 20:05:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-inbound-inspection-cert/m-p/335419#M84530</guid>
      <dc:creator>jdelio</dc:creator>
      <dc:date>2020-06-25T20:05:07Z</dc:date>
    </item>
  </channel>
</rss>

