<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSL Inspection fails even after Intermediate CA imported in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-inspection-fails-even-after-intermediate-ca-imported/m-p/335388#M84521</link>
    <description>&lt;P&gt;This is a known issue with the COMODO (now Sectigo) and some RSA certs&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Details and work-arounds can be found here:&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/general-topics/sectigo-ca-chain-decryption-issues/td-p/330802" target="_blank" rel="noopener"&gt;https://live.paloaltonetworks.com/t5/general-topics/sectigo-ca-chain-decryption-issues/td-p/330802&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also, I think this may be a "fix" in the latest PANOS: PAN-148068&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;DIV&gt;&lt;DIV class="p"&gt;&lt;DIV&gt;&lt;DIV&gt;PAN-148068&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV&gt;&lt;DIV class="p"&gt;&lt;DIV&gt;Fixed an issue where SSL connections were blocked if you enabled decryption with the option to block sessions that have expired certificates. This issue included servers that sent an expired AddTrust certificate authority (CA) in the certificate chain.&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 25 Jun 2020 18:11:01 GMT</pubDate>
    <dc:creator>shawnhafen</dc:creator>
    <dc:date>2020-06-25T18:11:01Z</dc:date>
    <item>
      <title>SSL Inspection fails even after Intermediate CA imported</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-inspection-fails-even-after-intermediate-ca-imported/m-p/335348#M84520</link>
      <description>&lt;P&gt;I have imported the intermediate CA, from 'Sectigo RSA Domain Validation Secure Server CA' and root CA '&lt;SPAN class="info"&gt;USERTrust RSA Certification Authority&lt;/SPAN&gt;' is already there on firewall default, but still outbound decryption fails.&lt;/P&gt;&lt;P&gt;&lt;A href="https://nvdpl.ca" target="_blank" rel="noopener"&gt;https://nvdpl.ca&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/26420i9C3C43B7066EF8A6/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 691px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/26421iF04FF9746EFE5457/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jun 2020 15:54:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-inspection-fails-even-after-intermediate-ca-imported/m-p/335348#M84520</guid>
      <dc:creator>raji_toor</dc:creator>
      <dc:date>2020-06-25T15:54:15Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Inspection fails even after Intermediate CA imported</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-inspection-fails-even-after-intermediate-ca-imported/m-p/335388#M84521</link>
      <description>&lt;P&gt;This is a known issue with the COMODO (now Sectigo) and some RSA certs&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Details and work-arounds can be found here:&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/general-topics/sectigo-ca-chain-decryption-issues/td-p/330802" target="_blank" rel="noopener"&gt;https://live.paloaltonetworks.com/t5/general-topics/sectigo-ca-chain-decryption-issues/td-p/330802&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also, I think this may be a "fix" in the latest PANOS: PAN-148068&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;DIV&gt;&lt;DIV class="p"&gt;&lt;DIV&gt;&lt;DIV&gt;PAN-148068&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV&gt;&lt;DIV class="p"&gt;&lt;DIV&gt;Fixed an issue where SSL connections were blocked if you enabled decryption with the option to block sessions that have expired certificates. This issue included servers that sent an expired AddTrust certificate authority (CA) in the certificate chain.&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jun 2020 18:11:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-inspection-fails-even-after-intermediate-ca-imported/m-p/335388#M84521</guid>
      <dc:creator>shawnhafen</dc:creator>
      <dc:date>2020-06-25T18:11:01Z</dc:date>
    </item>
  </channel>
</rss>

