SSL decryption troubleshooting - decrypt-cert-validation

Reply
Highlighted
L3 Networker

SSL decryption troubleshooting - decrypt-cert-validation

I have been working with SSL decryption over 4 month on testing team.

 

Most of the traffic is OK but I see some of the traffic are being Aged-Out and some and decrypt-cert-validation as the session end reason.

 

Tried to do packet capture without seeing the reason it being blocked.

 

The end user receive the error:  "There is an issue with the SSL certificate of the server you are trying to contact."

 

The certificate on the original site look OK from comodo and it's valid and the sites are legit.

 

Hope the screenshots from packet captuering will be helpful for discovering the problem.

 

Thank you for the help.

 

2018_09_26_14_53_27_Certificate_Error.jpg2018-09-26 14_57_38-trs.pcap.jpg2018-09-26 14_56_41-rcv (2).pcap.jpg2018-09-26 14_55_59-fw (2).pcap.jpg


Accepted Solutions
Highlighted
Cyber Elite

Re: SSL decryption troubleshooting - decrypt-cert-validation

@SShnap,

This is due to the firewall not trusting the entire certificate chain, or the site not presenting the entire certificate chain. If you look at the entire chain on a PC that is not being decrypted so that you can get the entire chain, then verify that the firewall actually trusts the Root and Intermidate CAs. If not, follow the instructions HERE 

View solution in original post


All Replies
Highlighted
Cyber Elite

Re: SSL decryption troubleshooting - decrypt-cert-validation

@SShnap,

This is due to the firewall not trusting the entire certificate chain, or the site not presenting the entire certificate chain. If you look at the entire chain on a PC that is not being decrypted so that you can get the entire chain, then verify that the firewall actually trusts the Root and Intermidate CAs. If not, follow the instructions HERE 

View solution in original post

Highlighted
L3 Networker

Re: SSL decryption troubleshooting - decrypt-cert-validation

@BPry Thank you for the fast response.

 

when I saw the error I checked the COMODO cert in on Default Trusted Certificate Authorities list on the firewall.

 

Thank you it's working now.

 

Do you know if that list of Default Trusted Certificate Authorities get updated by Palo Alto? so in the future I will be able to remove the cert I added manually?

Highlighted
Cyber Elite

Re: SSL decryption troubleshooting - decrypt-cert-validation

@SShnap,

The default list is generally refreshed during major software updates on the firewall. For the certificates that you have to manually upload on the firewall you essentially have to manage them; so updating them as they expire, deleting them when no longer needed, deleting any that you no longer considered a trusted source, all falls on you to manage. 

Highlighted
L3 Networker

Re: SSL decryption troubleshooting - decrypt-cert-validation

@BPry  So I need to downlaod from each well-known cert vendors and upload them the same way to avoid future ssl decryption failures like that.

 

 

Highlighted
Cyber Elite

Re: SSL decryption troubleshooting - decrypt-cert-validation

@SShnap,

I generally only recommend folks add the certificates they actually need. As you run into the issue then upload the cert and trust it. 

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!