nerdexam
Palo_Alto_Networks

PCNSE · Question #502

SSL Forward Proxy decryption is configured but the firewall uses Untrusted-CA to sign the website https //www important-website com certificate End-users are receiving me "security certificate is…

The correct answer is A. Navigate to Device > Certificate Management > Certificates > Device Certificates, import Well-. To prevent warnings for a legitimately trusted website during SSL Forward Proxy decryption, while still generating warnings for other untrusted sites, the firewall must be configured to trust the legitimate certificate chain of the problem website.

Submitted by certguy· Apr 18, 2026Deploy and Configure

Question

SSL Forward Proxy decryption is configured but the firewall uses Untrusted-CA to sign the website https //www important-website com certificate End-users are receiving me "security certificate is not trusted is warning Without SSL decryption the web browser shows that the website certificate is trusted and signed by a well-known certificate chain Well-Known- lntermediate and Well-Known-Root-CA. The network security administrator who represents the customer requires the following two behaviors when SSL Forward Proxy is enabled: 2. End-users should get the warning for any other untrusted website Which approach meets the two customer requirements?

Options

  • ANavigate to Device > Certificate Management > Certificates > Device Certificates, import Well-
  • BInstall the Well-Known-lntermediate-CA and Well-Known-Root-CA certificates on all end-user
  • CNavigate to Device > Certificate Management > Certificates > Default Trusted Certificate
  • DClear the Forward Untrust Certificate check box on the Untrusted-CA certificate and commit the

How the community answered

(40 responses)
  • A
    70% (28)
  • B
    5% (2)
  • C
    15% (6)
  • D
    10% (4)

Why each option

To prevent warnings for a legitimately trusted website during SSL Forward Proxy decryption, while still generating warnings for other untrusted sites, the firewall must be configured to trust the legitimate certificate chain of the problem website.

ANavigate to Device > Certificate Management > Certificates > Device Certificates, import Well-Correct

Importing the Well-Known-Intermediate-CA and Well-Known-Root-CA into the firewall's certificates (as trusted CAs) ensures the firewall can validate the original certificate chain of important-website.com. Once the firewall trusts the original certificate, it will then use its designated Forward Trust CA (which is typically deployed to end-user machines) to re-sign the website's certificate, thereby eliminating the 'security certificate is not trusted' warning for important-website.com. This allows the firewall to correctly identify other genuinely untrusted websites and use its Forward Untrust CA to generate warnings for them, meeting both requirements.

BInstall the Well-Known-lntermediate-CA and Well-Known-Root-CA certificates on all end-user

End-users already trust the Well-Known-Intermediate-CA and Well-Known-Root-CA, which is evident because the site is trusted without decryption; installing them again will not fix the firewall's decryption behavior or its internal trust decisions.

CNavigate to Device > Certificate Management > Certificates > Default Trusted Certificate

Disabling the Well-Known-Intermediate-CA and Well-Known-Root-CA in the firewall's trusted certificate authorities would further prevent the firewall from validating important-website.com, worsening the problem by ensuring it's treated as untrusted.

DClear the Forward Untrust Certificate check box on the Untrusted-CA certificate and commit the

Clearing the 'Forward Untrust Certificate' checkbox would likely prevent warnings for *all* untrusted websites by changing how the firewall handles them, directly contradicting the requirement that end-users *should* get warnings for other untrusted websites.

Concept tested: SSL Forward Proxy Certificate Trust Management

Source: https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/decryption/configure-ssl-forward-proxy

Topics

#SSL Decryption#Forward Proxy#Certificate Management#Certificate Trust

Community Discussion

No community discussion yet for this question.

Full PCNSE Practice