- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
09-15-2021 04:43 AM
Hi, i have a requirement to do ssl inspection from traffic from 2 different security domains, i have imported CA and issuing certs from the different DC's etc, i have then created new 2 certs for the to be used as the forward trust certs, but when i click on the cert to select forward trust cert option, it seems I can only have one cert which is forward trust cert at one time on the firewall, as soon as i click on the other cert and select forward trust cert, the first cert has this option removed
So is it possible to have more then one forward trust cert on the firewall at the same time ?
Thanks in advance
Regards
Paul
09-15-2021 08:39 AM
@scoobyboy Unfortunately there is no way to specify multiple forward trust certificates, but this would definitely be a useful you should submit a feature request for it.
Not ideal, but certificates are virtual system specific and the only option I can think of and if s is to use multiple vsys for the different types of decrypted traffic.
09-15-2021 08:39 AM
@scoobyboy Unfortunately there is no way to specify multiple forward trust certificates, but this would definitely be a useful you should submit a feature request for it.
Not ideal, but certificates are virtual system specific and the only option I can think of and if s is to use multiple vsys for the different types of decrypted traffic.
09-15-2021 09:09 AM
@batd2 yeah i didnt think so, its a bit of pain, and i guess the Palo isnt a full blown proxy, problem is on a VM, so no vsys for me! but thanks for the reply,
Cheers
09-21-2022 07:48 AM
Did you submit a feature request for this? I am working on a project with the same need - multiple forward trust certificates.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!