Bad certificate _ inbound ssl inspection

Reply
L3 Networker

Bad certificate _ inbound ssl inspection

Hi All

 

we are using 3rd party singed certificate for inbound SSL inspection , once we imported the certificate it is not showing any error and commit is working fine . once we add the certificate to decryption policy it is showing error as bad certificate and commit is failing . The certificate is 3rd part signed CA and its not the CA or subordinate CA this is normal server certificate and the key option after import is showing green check mark that means it has the key and also the certificate is valid . please advise what could be the issue for this bad certificate error ...

L7 Applicator

Re: Bad certificate _ inbound ssl inspection

@Rameshwar,

Can you provide the full error message; I would suspect that the firewall doesn't trust the full certificate chain. 

L3 Networker

Re: Bad certificate _ inbound ssl inspection

Hi @BPry

 

the actual error is failed to load: bad certificate.

error loading vsys cfg

failed to handle config_update_start

L7 Applicator

Re: Bad certificate _ inbound ssl inspection

@Rameshwar,

What's the signature algorithm that's being used on the cert you are trying to utilize. There's an issue when you attempt to utilize the RSASSA-PSS algorithm to sign certificates. 

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!