SSL Decryption - Forward Trust Certificate option not available

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

SSL Decryption - Forward Trust Certificate option not available

L2 Linker

Hello

 

I try to configure the ssl decryption on my cluster of PA-220. I have an internal PKI based on Microsoft solution. On the first node, I'm able to generate the request, the csr has been validated by the PKI server and I'm able to export from the PKI  the certificate (base-64 encoded). I'm able to import the certificat in my PA-220 device without error but when I try to enable "Forward Trust Certificate" and "Forward Untrust Certificate" options, I can't select these options. 

 

Why these options are not available ?

 

BR

3 REPLIES 3

L7 Applicator

 is it a trusted root CA?

Hello

 

First, I imported on the device the root-ca certificate. After, I generated a new certificat and specify External Authority in the option Signed By.

 

After, I exported the CSR and I validate the CSR on my PKI server. I exported the certificate from my PKI server as a based-64 format and import the certificate in the device (without error). But I can't select the option "Forward Trust Certificate" on the certificate information.

 

BR

I am also facing this problem. Iam not able to seethe forward trust option( grayed out). Any document is available for this.

NpN
  • 3133 Views
  • 3 replies
  • 1 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!