Showing results for 
Show  only  | Search instead for 
Did you mean: 

Who Me Too'd this topic

PAN and intermediate CAs

L6 Presenter

Last couple of days I've had quite a few cases where I had to manually add intermediate CAs as a Trusted Root CA in order for decryption to work (for customers blocking untrusted CAs already on firewall).


These are quite well known intermediate CAs like: 

DigiCert TLS RSA SHA256 2020 CA1

GeoTrust RSA CA 2018

Entrust Certification Authority - L1K

Entrust Certification Authority - L1M



How come PAN's trusted Root CA list is lacking so many? How is it updated? Via content updates? I have content updates schduled daily.

Anyone else having issues with this? I know there was only some to add in the past. But last couple of days I really had many to add at different customers.

SSL Decryption 



Who Me Too'd this topic