- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
03-28-2024 06:28 AM
Hello
I configured my firewall with SSL decryption. Regarding the certificate, what is the best practice ? Is-it to generate the certificate used for Outbound traffic from our internal PKI (with the problem to deploy the certificate on Linux system or application who not use Windows store) or to generate certificate from our public authority ?
BR
03-28-2024 08:30 AM
If you have a lot of machines/applications that don't trust your internal and do trust your public, then it's probably worth the few hundred dollars to just issue from public. You also get the benefit that public authorities typically remind you of expiration. We use internal CA for decrypt but we're all Windows and Mac where we can control cert stores.
The main drawback is the very possible change of publicly issues certs going to 90 day expiration at some point in the future.
04-02-2024 07:21 AM
Hi Jerome,
You will not be able to use your public PKI infrastructure because most of them don't issue a sub CA certificate. You need a Sub CA certificate in order for the firewall to generate certificates for the websites you are visiting.
Best practices is to use an internal PKI you manage because in a Windows world this make redistributing the SubCA certificate easy.
there is a difference between the certificates you create and use for web servers and the one you will be using for SSL decryption.
But if you are all linux and you need to deploy the certificates to the clients anway you can create a subCA cert on the palo itself.
05-07-2024 11:48 AM
Internal PKI like MS windows CA, usually if you have this already all your domain clients will have a RootCA or a SubCA, then generate a cert on the palo and cut the new internal cert from internal CA.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!