Commit error - vsys1 decryption: forward decrypt untrust cert is not configured

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Commit error - vsys1 decryption: forward decrypt untrust cert is not configured

L3 Networker

Hi,

This commit error: "Warning: vsys1 decryption: forward decrypt untrust cert is not configured, forward decrypt trust cert will be used instead." Means, that i must generate "Forward untrust certificate" or what?

3 REPLIES 3

L7 Applicator

cert.PNG.png

Yes, you need to generate/import a CA cert on the PA and designate it as "Forward untrust cert" if you configure outbound SSL proxy as shown in the screenshot.

L5 Sessionator

Good Morning,

Its recommended that the users are presented with a forward untrust certificate, if the server certificate of the web site that the user browses for isnt part of the Trusted CA certificates in the firewall. This is to let the customer know that the website in question is not trusted or safe. Usually the PANFW has most of the CA certificates under its list, and for the ones that are not present, the PANFW considers them as being unsafe.

When configured with the forwared untrust certificate, the user can come to know that the website in question not a safe website

L5 Sessionator

Here is a doc which explains on how the different Decryptions (Inbound, outbound, forward proxy) is done on the firewall and general guidlines on how to configure it

https://live.paloaltonetworks.com/docs/DOC-1412

Here are few other useful docs for SSL decryption

https://live.paloaltonetworks.com/docs/DOC-2008

https://live.paloaltonetworks.com/docs/DOC-2006

Hope this helps.

Thanks
Numan

  • 9023 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!