<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic on Palo Alto Certificate create in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/on-palo-alto-certificate-create/m-p/1141#M892</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;DIV id="imcontent"&gt;&lt;SPAN style="color: #000000; font-family: &amp;amp;quot;Segoe UI&amp;amp;quot;; font-size: 10pt; direction: ltr; word-wrap: break-word;"&gt;We create a certificate on our local CA. We want to decrypt traffic in Palo Alto using this certificate. We decided to use the CN as "*" to match all destination hostnames the client will use. We installed the certificate and the intermediate and root certificates on Palo Alto but we could not be able to decrypt the traffic via this certificate. Could you help us to decrypt the traffic and to understand whether it is successfull or not?&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 29 Feb 2012 07:49:09 GMT</pubDate>
    <dc:creator>kuveytturk</dc:creator>
    <dc:date>2012-02-29T07:49:09Z</dc:date>
    <item>
      <title>on Palo Alto Certificate create</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/on-palo-alto-certificate-create/m-p/1141#M892</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;DIV id="imcontent"&gt;&lt;SPAN style="color: #000000; font-family: &amp;amp;quot;Segoe UI&amp;amp;quot;; font-size: 10pt; direction: ltr; word-wrap: break-word;"&gt;We create a certificate on our local CA. We want to decrypt traffic in Palo Alto using this certificate. We decided to use the CN as "*" to match all destination hostnames the client will use. We installed the certificate and the intermediate and root certificates on Palo Alto but we could not be able to decrypt the traffic via this certificate. Could you help us to decrypt the traffic and to understand whether it is successfull or not?&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Feb 2012 07:49:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/on-palo-alto-certificate-create/m-p/1141#M892</guid>
      <dc:creator>kuveytturk</dc:creator>
      <dc:date>2012-02-29T07:49:09Z</dc:date>
    </item>
    <item>
      <title>Re: on Palo Alto Certificate create</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/on-palo-alto-certificate-create/m-p/1142#M893</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You create a new CA to be used for this purpose.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The CA public and private cert is then imported to the PAN so it can create the MITM certs on the fly to perform the SSL-termination/inspection.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The CA public cert is then imported to the client as a trusted issuer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The CN used for the CA is the line your browser will display when you click on the lock (in the browser) and it says "This site has been verified by XXX".&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Feb 2012 09:29:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/on-palo-alto-certificate-create/m-p/1142#M893</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-02-29T09:29:15Z</dc:date>
    </item>
  </channel>
</rss>

