SSL Decryption - Firefox error: "sec_error_reused_issuer_and_serial"

Reply
Highlighted
L2 Linker

SSL Decryption - Firefox error: "sec_error_reused_issuer_and_serial"

After turning on the SSL-Decryption, firefox tells me every moring after restart this error  "sec_error_reused_issuer_and_serial", after deleleting the whole history and a restart of firefox it works, but that workaround every morning couldn't be the solution.

Anybody some suggestions??


thx

L4 Transporter

Re: SSL Decryption - Firefox error: "sec_error_reused_issuer_and_serial"

Hi,

when you get this message? when open any https websites or open the PA-WebGui?

if you get it with any https websites, please check the Trusted and Untrusted Certificates. Take a look:

ssl-certs.png

The Certificates are generated all from PA.

gateway.example.com = DNS entry with the IP of your internet breakout  at your PA

pa-webgui.example.com = DNS entry with the IP of your MGT from your PA

Export the RootCA certificate and import it in your firefox. And if you having more PAs with the same RootCA and WebGui certificates generated from you will always get the problem with FF when opening the WebGui. Try Chrome or IE.

L2 Linker

Re: SSL Decryption - Firefox error: "sec_error_reused_issuer_and_serial"

Hi Hithead,

i had only one certificate for all purposes signed as a Subordinate-CA from my Organisation-CA???  IE has no problems with that, only FF.

L4 Transporter

Re: SSL Decryption - Firefox error: "sec_error_reused_issuer_and_serial"

hi,

FF has a problem with it. FF call it a "security feature" and IE ignore the  usage of the same CA on different sites. Difficult to explain.

But by the way: Do not use a trusted certificate with the option "forward trusted certificate". If a page is recognized as untrusted by the PA, the user will not be promoted with a certificate error. It will trust it. Generate a new certificate with PA, with the same values but do not choose an issuer (signed by) and select the usage "untrusted Certificate" for it.

L2 Linker

Re: SSL Decryption - Firefox error: "sec_error_reused_issuer_and_serial"

"Do not use a trusted certificate with the option "forward trusted certificate".

Sorry I didn't really understand.

You mean "Do not use a trusted certificate with the option "forward untrusted certificate"?

L4 Transporter

Re: SSL Decryption -  Firefox error: "sec_error_reused_issuer_and_serial"

oh, you are right =)

I mean untrusted :smileyhappy:

L2 Linker

Re: SSL Decryption - Firefox error: "sec_error_reused_issuer_and_serial"

Okay :smileygrin:.  I have tested it and it looks good with the untrusted certificates.

And for the "security feature" in FF, i will look for a workaround :smileyhappy:.

But I have one more question: Do you mean it's useful to work with OCSP-Responder or CRL-Lists? Any Ideas or best practice, because there are different meanings about that?

L4 Transporter

Re: SSL Decryption - Firefox error: "sec_error_reused_issuer_and_serial"

we don't activated that, because of a bug. But we will enable it soon again (with 6.0.2). Only crl . After enable it, you have to check the system logs, if your PA can download the crl .

BTW: read this https://live.paloaltonetworks.com/thread/8984

L4 Transporter

Re: SSL Decryption - Firefox error: "sec_error_reused_issuer_and_serial"

This has been fixed in 6.0.2 which has been released yesterday.

L2 Linker

Re: SSL Decryption - Firefox error: "sec_error_reused_issuer_and_serial"

hi again,

okay i will test the OCSP with the new PAN-OS Version soon, but now I have another problem with the selfsigned certificate for the untrusted Certificates, because I get many certificate errors because the most intermediate CA's are not in the default trusted certificate list on the PA.

So what is the best way to solve the problem. It seems to be a little bit difficult to import all possible certificates for the Sub-CA's??

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!