Bad certificate _ inbound ssl inspection

Showing results for 
Show  only  | Search instead for 
Did you mean: 

Bad certificate _ inbound ssl inspection

L3 Networker

Hi All


we are using 3rd party singed certificate for inbound SSL inspection , once we imported the certificate it is not showing any error and commit is working fine . once we add the certificate to decryption policy it is showing error as bad certificate and commit is failing . The certificate is 3rd part signed CA and its not the CA or subordinate CA this is normal server certificate and the key option after import is showing green check mark that means it has the key and also the certificate is valid . please advise what could be the issue for this bad certificate error ...


Cyber Elite
Cyber Elite


Can you provide the full error message; I would suspect that the firewall doesn't trust the full certificate chain. 

Hi @BPry


the actual error is failed to load: bad certificate.

error loading vsys cfg

failed to handle config_update_start


What's the signature algorithm that's being used on the cert you are trying to utilize. There's an issue when you attempt to utilize the RSASSA-PSS algorithm to sign certificates. 

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!