SSL Decryption Fails: sec_error_reused_issuer_and_serial

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

SSL Decryption Fails: sec_error_reused_issuer_and_serial

L3 Networker

In the newest PA-OS 3.1.2 seems to be a problem with the Proxy-Certificate.

If browsing with Firefox, you get "Errocode: sec_error_reused_issuer_and_serial" on all HTTPS-Sites, if you have implented the proxy certificate in the certificat store (and if not, you can surf without problems after click on "ignore security warning"). With Opera, SSL-Connections fails with a "white window", whether you have installed the proxy certificate in the browser certificate store or not.

1 accepted solution

Accepted Solutions

L2 Linker

Please open a case with Support.

View solution in original post

6 REPLIES 6

L2 Linker

Please open a case with Support.

We did so some days before. But till now, we got no answer.

I believe your SE opened a case regarding this issue yesterday.  He has been working with Support so you may want to get in touch with him.

Yes, our SE started a support case. Unfortunenately, we got no solution but only a workaround, which did not work. PA recommended to reimport the PA Certificate through the Firefox security warning dialogue. Otherwise we have to wait on version 3.1.3, which "maybe" helps.

A procedrue for exporting/importing the certificate from/to Firefox can be found at the following link.  It did work in our lab.

(outdated link removed)

This workaround does not works in our environment.

First we dont see a certificate hierarchy in the firefox but only the solitary certificate from the HTTPs Server.

Second we cannot import the server key as a CA key. Firefox says: "this is not a certificate from a certificate authority ...". Please have a look at the gif-attachement.

I assume, we have another problem with our certificate. We tried first to generate the certificate with the appliance software, just now we use an imported certificate, build with openssl.

Our two 2050 appliances works in a high availability mode.

  • 1 accepted solution
  • 4392 Views
  • 6 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!