12-21-2022 03:45 PM
PA-VM Series 8, vm-mode: Microsoft Azure
sw-version: 10.1.6-h6 global-protect-client-package-version: 5.2.1
Issue:
when trying to access websites, we are getting a lot of errors saying that the ROOT CA authority is untrusted/invalid
Error details: Received fatal alert CertificateUnknown from the client. CA Issuer URL (truncated):http://crt.sectigo.com/SectigoRSADomainValidationSecureServerCA
Certificate Information,
CA- Trusted Root CA
status Valid
12-22-2022 01:23 PM
Hi,
The error states this has come from the client and means that the client does not trust the issue URL. Palo has pulled out the originating CA Cert for you but the issue is most likely you are doing decryption and the client does not trust your decryption cert. This is either because:
1) it does not have the decryption cert chain installed and/or trusted
2) the browser is not using the machine trust store (e.g. firefox) and maintains its own trust store that will need the cert chain adding
We also see this when the traffic is from inside an application that does not use the machine trust store, or is doing cert pinning but you state your issue is with browsing so probably not that.
Cheers,
Shannon
12-22-2022 01:31 PM
As a test, or if you completely trust this particular website, you could also exclude it from decryption; but I always prefer to resolve it properly and allow the firewall to decrypt and inspect the traffic for threats instead of just excluding decryption and blinding trusting it.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!