07-11-2018 09:16 AM
we are using 3rd party singed certificate for inbound SSL inspection , once we imported the certificate it is not showing any error and commit is working fine . once we add the certificate to decryption policy it is showing error as bad certificate and commit is failing . The certificate is 3rd part signed CA and its not the CA or subordinate CA this is normal server certificate and the key option after import is showing green check mark that means it has the key and also the certificate is valid . please advise what could be the issue for this bad certificate error ...
07-11-2018 02:11 PM
Can you provide the full error message; I would suspect that the firewall doesn't trust the full certificate chain.
07-11-2018 10:28 PM
the actual error is failed to load: bad certificate.
error loading vsys cfg
failed to handle config_update_start
07-12-2018 11:19 AM
What's the signature algorithm that's being used on the cert you are trying to utilize. There's an issue when you attempt to utilize the RSASSA-PSS algorithm to sign certificates.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!