SSL: Firewall uses untrust-forward cert. for every site

Showing results for 
Show  only  | Search instead for 
Did you mean: 

SSL: Firewall uses untrust-forward cert. for every site

L3 Networker


I just set up SSL Decryption exactly as described in the Getting Started Guide (English)

I have one trusted-forward certificate, imported into browsers, and one untrust-orward certificate, not imported into browsers.

Now when I connect to SSL sites, my browsers complain about untrusted certificates, the firewall is clearly using the untrust-forward certificate. When I configure the imported trust-forward certificate to be the untrust-forward certificate (so the imported certificate is both at the same time), everything works fine.

Something is wrong here. Any ideas?




Accepted Solutions

L3 Networker


please forget about it. I deleted all my certificates and re-created them from scratch, rebooted the firewall and now it is working fine. Not sure why it would use the wrong certificate, something must have got messed up. It's working fine now. Thanks for your help guys.

View solution in original post


L6 Presenter


Thanks, but I don't think this is my problem. In my case, *every* site is being signed by the untrust-forward certificate. Even large ones like Google or Facebook.

L3 Networker

I digged a little deeper and it seem the firewall is declaring each site's certificate as "untrusted" (see attached screenshot). So either the firewall is unable to check the certificates or there is some other issue. The list of default trusted CA authorities is populated with roughly 260 entries, so that looks ok. I need some help here, something is going very wrong.

Screen Shot 2013-05-26 at 16.00.10.png

This document may help

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!