SSL Inspection

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

SSL Inspection

L3 Networker

Hello

 

I configured my firewall with SSL decryption. Regarding the certificate, what is the best practice ? Is-it to generate the certificate used for Outbound traffic from our internal PKI (with the problem to deploy the certificate on Linux system or application who not use Windows store) or to generate certificate from our public authority ?

 

BR

3 REPLIES 3

L5 Sessionator

If you have a lot of machines/applications that don't trust your internal and do trust your public, then it's probably worth the few hundred dollars to just issue from public. You also get the benefit that public authorities typically remind you of expiration. We use internal CA for decrypt but we're all Windows and Mac where we can control cert stores.

The main drawback is the very possible change of publicly issues certs going to 90 day expiration at some point in the future.

L3 Networker

Hi Jerome,

 

You will not be able to use your public PKI infrastructure because most of them don't issue a sub CA certificate.   You need a Sub CA certificate in order for the firewall to generate certificates for the websites you are visiting.

Best practices is to use an internal PKI you manage because in a Windows world this make redistributing the SubCA certificate easy.

there is a difference between the certificates you create and use for web servers and the one you will be using for SSL decryption.

But if you are all linux and you need to deploy the certificates to the clients anway you can create a subCA cert on the palo itself.

 

L3 Networker

Internal PKI like MS windows CA, usually if you have this already all your domain clients will have a RootCA or a SubCA, then generate a cert on the palo and cut the new internal cert from internal CA. 

 

https://www.justus.ws/tech/paloalto-ca-cert/

  • 1205 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!