<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Captive Portal HTTPS SSL decrypt in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-https-ssl-decrypt/m-p/429884#M94957</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Good afternoon, thank you very much for the answer, it is clearer for me.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And regarding the certificates, I can use the same example, public certificate for the SSL Decrypt and also be used by the Captive Portal in the SSL/TLS profile.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I remain attentive, best regards, thank you.&lt;/P&gt;</description>
    <pubDate>Sat, 28 Aug 2021 04:47:29 GMT</pubDate>
    <dc:creator>Metgatz</dc:creator>
    <dc:date>2021-08-28T04:47:29Z</dc:date>
    <item>
      <title>Captive Portal HTTPS SSL decrypt</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-https-ssl-decrypt/m-p/429831#M94948</link>
      <description>&lt;P&gt;Captive Portal HTTPS decrypt&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Dear all:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Very good afternoon, I have the following doubts and concerns:&lt;/P&gt;&lt;P&gt;-Is it mandatory to configure SSL Decrypt ( I understand that yes, please confirm, it is for the point that when they enter a HTTPS site, it displays the captive portal in HTTPS ).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thinking to avoid having to manually pass and distribute the certificate, as it is impractical, e.g. for external devices, smart phones, etc. to have to install the self signed certificate from Palo Alto, is it possible to generate a CSR and use the Public certificate, externally signed, e.g. Global sing, etc, to be used for the SSL decrypt and the captive portal ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In this case the certificate would be externally validated, thinking in the computers, laptops, cell phones and external devices, but this certificate in the Palo Alto, would be only tied / linked to the LAN interface of Palo Alto, with a local DNS A record of example: My portal.mydomain.com, a local domain, but not external, there would be no problems with validation if the FQDN or CN Hostname of the certificate, resolves to a local IP (The LAN IP of Palo Alto).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please I remain attentive to all your comments, I appreciate the support, the clarification that you can give me.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I remain attentive, best regards.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Aug 2021 23:39:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-https-ssl-decrypt/m-p/429831#M94948</guid>
      <dc:creator>Metgatz</dc:creator>
      <dc:date>2021-08-27T23:39:07Z</dc:date>
    </item>
    <item>
      <title>Re: Captive Portal HTTPS SSL decrypt</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-https-ssl-decrypt/m-p/429854#M94949</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/179185"&gt;@Metgatz&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClevCAC" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClevCAC&lt;/A&gt;&lt;/P&gt;&lt;P&gt;It you are looking to intercept the HTTPS traffic you need to enable decryption to actually send the 302. Depending on a number of factors on how your non-managed devices and equipment your using there's ways to serve a splash page that prompts users connecting to download and internal your certificates.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 28 Aug 2021 02:51:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-https-ssl-decrypt/m-p/429854#M94949</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2021-08-28T02:51:38Z</dc:date>
    </item>
    <item>
      <title>Re: Captive Portal HTTPS SSL decrypt</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-https-ssl-decrypt/m-p/429884#M94957</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Good afternoon, thank you very much for the answer, it is clearer for me.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And regarding the certificates, I can use the same example, public certificate for the SSL Decrypt and also be used by the Captive Portal in the SSL/TLS profile.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I remain attentive, best regards, thank you.&lt;/P&gt;</description>
      <pubDate>Sat, 28 Aug 2021 04:47:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-https-ssl-decrypt/m-p/429884#M94957</guid>
      <dc:creator>Metgatz</dc:creator>
      <dc:date>2021-08-28T04:47:29Z</dc:date>
    </item>
  </channel>
</rss>

