forward trust certificate

cancel
Showing results for 
Search instead for 
Did you mean: 

forward trust certificate

L1 Bithead

Hi, i have a requirement to do ssl inspection from traffic from 2 different security domains, i have imported CA and issuing certs from the different DC's etc, i have then created new 2 certs for the to be used as the forward trust certs, but when i click on the cert to select forward trust cert option, it seems I can only have one cert which is forward trust cert at one time on the firewall, as soon as i click on the other cert and select forward trust cert, the first cert has this option removed 

 

So is it possible to have more then one forward trust cert on the firewall at the same time ? 

 

Thanks in advance 

 

Regards

Paul

1 ACCEPTED SOLUTION

Accepted Solutions

L4 Transporter

@scoobyboy Unfortunately there is no way to specify multiple forward trust certificates, but this would definitely be a useful you should submit a feature request for it. 

Not ideal, but certificates are virtual system specific and the only option I can think of and if s is to use multiple vsys for the different types of decrypted traffic. 

View solution in original post

2 REPLIES 2

L4 Transporter

@scoobyboy Unfortunately there is no way to specify multiple forward trust certificates, but this would definitely be a useful you should submit a feature request for it. 

Not ideal, but certificates are virtual system specific and the only option I can think of and if s is to use multiple vsys for the different types of decrypted traffic. 

L1 Bithead

@batd2 yeah i didnt think so, its a bit of pain, and i guess the Palo isnt a full blown proxy, problem is on a VM, so no vsys for me! but thanks for the reply, 

 

Cheers

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!