- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
02-28-2012 02:23 PM
When I have configured SSL decryption, I always get this warning message when I commit:
· Warning: vsys1 decryption: forward decrypt untrust cert is not configured, forward decrypt trust cert will be used instead.
· (Module: device)
· Configuration committed successfully
How can I get rid of this message when I haven't configured an SSL unrust certificate?
Mike
02-29-2012 01:01 AM
Just ignore the warning (or contact your sales rep to file a feature request where one can setup which warnings you wish to ignore by default).
The warning is there to notify that you might have missed something that is commonly used when doing SSL-termination.
When you perform SSL-termination the PAN will setup and verify the SSL-session. In order to handle the case of "what to do if the SSL-session is invalid" PAN choosed to use the untrust cert method.
By setting up a dedicated "untrust cert" and place this as blacklisted untrusted issuers in your client browser the client will be notified that there is something wrong with the cert that the site uses which the client is trying to access.
For more information check https://live.paloaltonetworks.com/thread/4229?tstart=0
02-29-2012 01:01 AM
Just ignore the warning (or contact your sales rep to file a feature request where one can setup which warnings you wish to ignore by default).
The warning is there to notify that you might have missed something that is commonly used when doing SSL-termination.
When you perform SSL-termination the PAN will setup and verify the SSL-session. In order to handle the case of "what to do if the SSL-session is invalid" PAN choosed to use the untrust cert method.
By setting up a dedicated "untrust cert" and place this as blacklisted untrusted issuers in your client browser the client will be notified that there is something wrong with the cert that the site uses which the client is trying to access.
For more information check https://live.paloaltonetworks.com/thread/4229?tstart=0
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!