<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Java Cert error due to decryption? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/java-cert-error-due-to-decryption/m-p/413666#M93003</link>
    <description>&lt;P&gt;Yeah, but then I have to bypass decryption on AWS, Azure, and GCP IP blocks... That seems entirely unreasonable.&lt;/P&gt;</description>
    <pubDate>Wed, 16 Jun 2021 19:09:03 GMT</pubDate>
    <dc:creator>Gareth.Doyle</dc:creator>
    <dc:date>2021-06-16T19:09:03Z</dc:date>
    <item>
      <title>Java Cert error due to decryption?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/java-cert-error-due-to-decryption/m-p/413567#M92990</link>
      <description>&lt;P&gt;My organization is in the process of moving from one VPN solution to GlobalProtect. We are seeing several applications being unable to run certain features, or run successfully at all, and the error logs appear similar to this (I say similar because this specific message is from one application, others may vary, but all are similar):&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;&lt;EM&gt;sun.security.validator.ValidatorException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target&lt;/EM&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;A second one:&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;EM&gt;javax.net.ssl.SSLHandshakeException: sun.security.validator.ValidatorException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target&lt;/EM&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Our workstation team has tried implementing our organization's root and intermediary certificates into a specific Java cert store according to some information they found online, but the error persists. The only change was moving to GlobalProtect. I have found that bypassing our decryption policies on the Palo Alto fixes this issue, but bypassing decryption for things that often reach out to cloud resources (thereby bypassing decryption to huge chunks of the internet) is not fully acceptable.&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Has anyone experienced anything like this and/or have any suggestions?&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Thanks!&lt;/DIV&gt;</description>
      <pubDate>Wed, 16 Jun 2021 13:21:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/java-cert-error-due-to-decryption/m-p/413567#M92990</guid>
      <dc:creator>Gareth.Doyle</dc:creator>
      <dc:date>2021-06-16T13:21:39Z</dc:date>
    </item>
    <item>
      <title>Re: Java Cert error due to decryption?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/java-cert-error-due-to-decryption/m-p/413648#M93000</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;While I would love to tell you to decrypt everything, somethings just break when you due. I would suggest not decrypting that traffic.&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Wed, 16 Jun 2021 18:49:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/java-cert-error-due-to-decryption/m-p/413648#M93000</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2021-06-16T18:49:02Z</dc:date>
    </item>
    <item>
      <title>Re: Java Cert error due to decryption?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/java-cert-error-due-to-decryption/m-p/413666#M93003</link>
      <description>&lt;P&gt;Yeah, but then I have to bypass decryption on AWS, Azure, and GCP IP blocks... That seems entirely unreasonable.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Jun 2021 19:09:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/java-cert-error-due-to-decryption/m-p/413666#M93003</guid>
      <dc:creator>Gareth.Doyle</dc:creator>
      <dc:date>2021-06-16T19:09:03Z</dc:date>
    </item>
    <item>
      <title>Re: Java Cert error due to decryption?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/java-cert-error-due-to-decryption/m-p/413678#M93004</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Yes I agree. However you can use one or more of the other options to get a bit more granular/generic.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="OtakarKlier_0-1623870916006.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/34451i68F9480E4B1F1A3C/image-size/medium?v=v2&amp;amp;px=400" role="button" title="OtakarKlier_0-1623870916006.png" alt="OtakarKlier_0-1623870916006.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Wed, 16 Jun 2021 19:15:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/java-cert-error-due-to-decryption/m-p/413678#M93004</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2021-06-16T19:15:27Z</dc:date>
    </item>
    <item>
      <title>Re: Java Cert error due to decryption?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/java-cert-error-due-to-decryption/m-p/414076#M93044</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/80358"&gt;@Gareth.Doyle&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;That's where the URL category would be recommended when creating your exception. So instead of excluding AWS/Azure/GCP, you would focus more on what resources are actually causing the issue and where the Java application is trying to fetch them from. Then just build out an exception for those URLs.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 18 Jun 2021 03:39:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/java-cert-error-due-to-decryption/m-p/414076#M93044</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2021-06-18T03:39:13Z</dc:date>
    </item>
    <item>
      <title>Re: Java Cert error due to decryption?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/java-cert-error-due-to-decryption/m-p/414240#M93084</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/80358"&gt;@Gareth.Doyle&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How does you trust path to the root ca look?&lt;/P&gt;
&lt;P&gt;Is it root &amp;gt; intermediate &amp;gt; decryption ca? Did you also try to import the decryption ca into the java trust store? And this question might be obvious, but did you make sure to import the CA certs as trusted issuer/CA certs?&lt;/P&gt;</description>
      <pubDate>Sat, 19 Jun 2021 19:55:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/java-cert-error-due-to-decryption/m-p/414240#M93084</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2021-06-19T19:55:41Z</dc:date>
    </item>
  </channel>
</rss>

