Auto update of trusted root CA



Our PANs are not updating the list of trusted root CA certificates which is causing issues with services such as Microsoft Skype for Business and other applications as we have SSL decryption enabled. Using PAN-OS 8.0.7

For example, Microsoft uses certificates signed by DigiCert Baltimore Root. I've checked on Panorama, our DC PANs and our site PANs and none of them have this root CA installed.


The enterprise CA & sub-ordinate CA certificates are working fine.

 The issue is with common public trusted CA providers such as DigiCert root CAs not being trusted on the PANs. When these are not trusted by the PAN, SSL decryption breaks for the end user.

Can you please advise as to how we can have these root CA certificates updated automatically?


Thanks in advance.

