PANOS 4.1 error message: untrust cert is not configured

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

PANOS 4.1 error message: untrust cert is not configured

Not applicable

When I have configured SSL decryption, I always get this warning message when I commit:

· Warning: vsys1 decryption: forward decrypt untrust cert is not configured, forward decrypt trust cert will be used instead.

· (Module: device)

· Configuration committed successfully

How can I get rid of this message when I haven't configured an SSL unrust certificate?

Mike

1 accepted solution

Accepted Solutions

L6 Presenter

Just ignore the warning (or contact your sales rep to file a feature request where one can setup which warnings you wish to ignore by default).

The warning is there to notify that you might have missed something that is commonly used when doing SSL-termination.

When you perform SSL-termination the PAN will setup and verify the SSL-session. In order to handle the case of "what to do if the SSL-session is invalid" PAN choosed to use the untrust cert method.

By setting up a dedicated "untrust cert" and place this as blacklisted untrusted issuers in your client browser the client will be notified that there is something wrong with the cert that the site uses which the client is trying to access.


For more information check https://live.paloaltonetworks.com/thread/4229?tstart=0

View solution in original post

1 REPLY 1

L6 Presenter

Just ignore the warning (or contact your sales rep to file a feature request where one can setup which warnings you wish to ignore by default).

The warning is there to notify that you might have missed something that is commonly used when doing SSL-termination.

When you perform SSL-termination the PAN will setup and verify the SSL-session. In order to handle the case of "what to do if the SSL-session is invalid" PAN choosed to use the untrust cert method.

By setting up a dedicated "untrust cert" and place this as blacklisted untrusted issuers in your client browser the client will be notified that there is something wrong with the cert that the site uses which the client is trying to access.


For more information check https://live.paloaltonetworks.com/thread/4229?tstart=0

  • 1 accepted solution
  • 2023 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!