<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: certificate profile in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/certificate-profile/m-p/356958#M87706</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/62286"&gt;@Alex_Samad&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;The certificate profile would have to include the intermediate server that actually signed the minemeld certificate, along with any other certificate that it's presenting in its certificate chain. Also you are correct, if you would want to limit this to just one intermediate CA you would only have that certificate in the certificate profile.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 18 Oct 2020 04:24:40 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2020-10-18T04:24:40Z</dc:date>
    <item>
      <title>certificate profile</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/certificate-profile/m-p/356868#M87695</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I want to use/setup a certificate profile for use with an EDL.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The site - internal running minemeld. has multiple int CA.&lt;/P&gt;&lt;P&gt;So for the profile, do I add only the last int CA or all of them.&lt;/P&gt;&lt;P&gt;How does certificate profile work will it say okay if any certificate signed by any of the ca's work ?&lt;/P&gt;&lt;P&gt;how can i limit it to just the last intCA... do i do that by adding in only the last ca ?&lt;/P&gt;</description>
      <pubDate>Sat, 17 Oct 2020 07:09:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/certificate-profile/m-p/356868#M87695</guid>
      <dc:creator>Alex_Samad</dc:creator>
      <dc:date>2020-10-17T07:09:51Z</dc:date>
    </item>
    <item>
      <title>Re: certificate profile</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/certificate-profile/m-p/356958#M87706</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/62286"&gt;@Alex_Samad&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;The certificate profile would have to include the intermediate server that actually signed the minemeld certificate, along with any other certificate that it's presenting in its certificate chain. Also you are correct, if you would want to limit this to just one intermediate CA you would only have that certificate in the certificate profile.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 18 Oct 2020 04:24:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/certificate-profile/m-p/356958#M87706</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-10-18T04:24:40Z</dc:date>
    </item>
    <item>
      <title>Re: certificate profile</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/certificate-profile/m-p/356974#M87708</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;Yes did some testing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;so lets stay I have&amp;nbsp;&lt;/P&gt;&lt;P&gt;RootCA&lt;/P&gt;&lt;P&gt;IntC1&lt;/P&gt;&lt;P&gt;IntC2&lt;/P&gt;&lt;P&gt;Server cert.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;RooCa signs intC1 which signs intC2 which signs Server Cert.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If my cert profile only has intC2.. it fails to verify. I need RootCa + IntC1 + IntC2 for it to authenticate server Cert.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;which I think is actually more of a security flaw.&lt;/P&gt;&lt;P&gt;if I present a leaf cert signed by intC1 it would work, but thats not my intention !&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 18 Oct 2020 07:26:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/certificate-profile/m-p/356974#M87708</guid>
      <dc:creator>Alex_Samad</dc:creator>
      <dc:date>2020-10-18T07:26:44Z</dc:date>
    </item>
  </channel>
</rss>

