PCNSE · Question #502
SSL Forward Proxy decryption is configured but the firewall uses Untrusted-CA to sign the website https //www important-website com certificate End-users are receiving me "security certificate is…
The correct answer is A. Navigate to Device > Certificate Management > Certificates > Device Certificates, import Well-. To prevent warnings for a legitimately trusted website during SSL Forward Proxy decryption, while still generating warnings for other untrusted sites, the firewall must be configured to trust the legitimate certificate chain of the problem website.
Question
Options
- ANavigate to Device > Certificate Management > Certificates > Device Certificates, import Well-
- BInstall the Well-Known-lntermediate-CA and Well-Known-Root-CA certificates on all end-user
- CNavigate to Device > Certificate Management > Certificates > Default Trusted Certificate
- DClear the Forward Untrust Certificate check box on the Untrusted-CA certificate and commit the
How the community answered
(40 responses)- A70% (28)
- B5% (2)
- C15% (6)
- D10% (4)
Why each option
To prevent warnings for a legitimately trusted website during SSL Forward Proxy decryption, while still generating warnings for other untrusted sites, the firewall must be configured to trust the legitimate certificate chain of the problem website.
Importing the Well-Known-Intermediate-CA and Well-Known-Root-CA into the firewall's certificates (as trusted CAs) ensures the firewall can validate the original certificate chain of important-website.com. Once the firewall trusts the original certificate, it will then use its designated Forward Trust CA (which is typically deployed to end-user machines) to re-sign the website's certificate, thereby eliminating the 'security certificate is not trusted' warning for important-website.com. This allows the firewall to correctly identify other genuinely untrusted websites and use its Forward Untrust CA to generate warnings for them, meeting both requirements.
End-users already trust the Well-Known-Intermediate-CA and Well-Known-Root-CA, which is evident because the site is trusted without decryption; installing them again will not fix the firewall's decryption behavior or its internal trust decisions.
Disabling the Well-Known-Intermediate-CA and Well-Known-Root-CA in the firewall's trusted certificate authorities would further prevent the firewall from validating important-website.com, worsening the problem by ensuring it's treated as untrusted.
Clearing the 'Forward Untrust Certificate' checkbox would likely prevent warnings for *all* untrusted websites by changing how the firewall handles them, directly contradicting the requirement that end-users *should* get warnings for other untrusted websites.
Concept tested: SSL Forward Proxy Certificate Trust Management
Source: https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/decryption/configure-ssl-forward-proxy
Topics
Community Discussion
No community discussion yet for this question.