SSL: Firewall uses untrust-forward cert. for every site

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

SSL: Firewall uses untrust-forward cert. for every site

L3 Networker

Hi,

I just set up SSL Decryption exactly as described in the Getting Started Guide (English)

I have one trusted-forward certificate, imported into browsers, and one untrust-orward certificate, not imported into browsers.

Now when I connect to SSL sites, my browsers complain about untrusted certificates, the firewall is clearly using the untrust-forward certificate. When I configure the imported trust-forward certificate to be the untrust-forward certificate (so the imported certificate is both at the same time), everything works fine.

Something is wrong here. Any ideas?

Thanks

Sascha

1 accepted solution

Accepted Solutions

L3 Networker

Hi,

please forget about it. I deleted all my certificates and re-created them from scratch, rebooted the firewall and now it is working fine. Not sure why it would use the wrong certificate, something must have got messed up. It's working fine now. Thanks for your help guys.

View solution in original post

6 REPLIES 6

L6 Presenter

Hi,

Thanks, but I don't think this is my problem. In my case, *every* site is being signed by the untrust-forward certificate. Even large ones like Google or Facebook.

L3 Networker

I digged a little deeper and it seem the firewall is declaring each site's certificate as "untrusted" (see attached screenshot). So either the firewall is unable to check the certificates or there is some other issue. The list of default trusted CA authorities is populated with roughly 260 entries, so that looks ok. I need some help here, something is going very wrong.

Screen Shot 2013-05-26 at 16.00.10.png

This document may help

The firewall seems to be having trouble with the issuers as you have shown. The large list of CAs should indicate that it is working fine, and I have not seen this issue before. A couple questions that may help:

1. What OS version is your firewall running?

2. Is the content up to date? The most current as of this posting is 375-1810. You can confirm it by looking under the dashboard, or Device > Dynamic Updates.

3. Is there any other SSL interception/proxy device being implemented? Another firewall or a proxy may cause this.

Hope this helps,

Greg Wesson

L3 Networker

Hi,

please forget about it. I deleted all my certificates and re-created them from scratch, rebooted the firewall and now it is working fine. Not sure why it would use the wrong certificate, something must have got messed up. It's working fine now. Thanks for your help guys.

  • 1 accepted solution
  • 4051 Views
  • 6 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!