SSL decryption troubleshooting - decrypt-cert-validation

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

SSL decryption troubleshooting - decrypt-cert-validation

L3 Networker

I have been working with SSL decryption over 4 month on testing team.

 

Most of the traffic is OK but I see some of the traffic are being Aged-Out and some and decrypt-cert-validation as the session end reason.

 

Tried to do packet capture without seeing the reason it being blocked.

 

The end user receive the error:  "There is an issue with the SSL certificate of the server you are trying to contact."

 

The certificate on the original site look OK from comodo and it's valid and the sites are legit.

 

Hope the screenshots from packet captuering will be helpful for discovering the problem.

 

Thank you for the help.

 

2018_09_26_14_53_27_Certificate_Error.jpg2018-09-26 14_57_38-trs.pcap.jpg2018-09-26 14_56_41-rcv (2).pcap.jpg2018-09-26 14_55_59-fw (2).pcap.jpg

1 accepted solution

Accepted Solutions

Cyber Elite
Cyber Elite

@SShnap,

This is due to the firewall not trusting the entire certificate chain, or the site not presenting the entire certificate chain. If you look at the entire chain on a PC that is not being decrypted so that you can get the entire chain, then verify that the firewall actually trusts the Root and Intermidate CAs. If not, follow the instructions HERE 

View solution in original post

5 REPLIES 5

Cyber Elite
Cyber Elite

@SShnap,

This is due to the firewall not trusting the entire certificate chain, or the site not presenting the entire certificate chain. If you look at the entire chain on a PC that is not being decrypted so that you can get the entire chain, then verify that the firewall actually trusts the Root and Intermidate CAs. If not, follow the instructions HERE 

@BPry Thank you for the fast response.

 

when I saw the error I checked the COMODO cert in on Default Trusted Certificate Authorities list on the firewall.

 

Thank you it's working now.

 

Do you know if that list of Default Trusted Certificate Authorities get updated by Palo Alto? so in the future I will be able to remove the cert I added manually?

@SShnap,

The default list is generally refreshed during major software updates on the firewall. For the certificates that you have to manually upload on the firewall you essentially have to manage them; so updating them as they expire, deleting them when no longer needed, deleting any that you no longer considered a trusted source, all falls on you to manage. 

@BPry  So I need to downlaod from each well-known cert vendors and upload them the same way to avoid future ssl decryption failures like that.

 

 

@SShnap,

I generally only recommend folks add the certificates they actually need. As you run into the issue then upload the cert and trust it. 

  • 1 accepted solution
  • 23209 Views
  • 5 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!