Errors - ROOT CA authority untrusted / invalid

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Errors - ROOT CA authority untrusted / invalid

L1 Bithead

PA-VM Series 8, vm-mode: Microsoft Azure

sw-version: 10.1.6-h6 global-protect-client-package-version: 5.2.1

 

Issue:

when trying to access websites, we are getting a lot of errors saying that the ROOT CA authority is untrusted/invalid

 

Error details: Received fatal alert CertificateUnknown from the client. CA Issuer URL (truncated):http://crt.sectigo.com/SectigoRSADomainValidationSecureServerCA

 

Certificate Information,

CA- Trusted Root CA

status Valid

 

3 REPLIES 3

L3 Networker

Hi,

The error states this has come from the client and means that the client does not trust the issue URL. Palo has pulled out the originating CA Cert for you but the issue is most likely you are doing decryption and the client does not trust your decryption cert. This is either because:

1) it does not have the decryption cert chain installed and/or trusted

2) the browser is not using the machine trust store (e.g. firefox) and maintains its own trust store that will need the cert chain adding

 

We also see this when the traffic is from inside an application that does not use the machine trust store, or is doing cert pinning but you state your issue is with browsing so probably not that.

 

Cheers,

Shannon

L1 Bithead

I will try  & let me know.

As a test, or if you completely trust this particular website, you could also exclude it from decryption; but I always prefer to resolve it properly and allow the firewall to decrypt and inspect the traffic for threats instead of just excluding decryption and blinding trusting it.

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!