Our PANs are not updating the list of trusted root CA certificates which is causing issues with services such as Microsoft Skype for Business and other applications as we have SSL decryption enabled. Using PAN-OS 8.0.7
For example, Microsoft uses certificates signed by DigiCert Baltimore Root. I've checked on Panorama, our DC PANs and our site PANs and none of them have this root CA installed.
The enterprise CA & sub-ordinate CA certificates are working fine.
The issue is with common public trusted CA providers such as DigiCert root CAs not being trusted on the PANs. When these are not trusted by the PAN, SSL decryption breaks for the end user.
Can you please advise as to how we can have these root CA certificates updated automatically?
Thanks in advance.
I'm pretty sure the list of default root CAs only update when you upgrade PAN OS. I don't think they are rolled into any updates.
I'm running 8.0.6 and I have Baltimore_CyberTrust_Root included.
I had this issue as well with BitBucket and some other sites I was on code 8.0.7 and upgraded to 8.0.16 and the issue was resolved. I got communication from a Sr DE that there is a refreash feature for the certificate trust list CTL of root CAs in the 8.1 code https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-new-features/networking-features/refresh-of-defa...
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!