PCNSE · Question #669
An administrator is configuring SSL decryption and needs to ensure that all certificates for both SSL Inbound inspection and SSL Forward Proxy are installed properly on the firewall. When…
The correct answer is A. Forward Untrust certificate C. Forward Trust certificate D. End-entity (leaf) certificate. Private keys are required only when the firewall must actively sign or decrypt traffic. The Forward Trust certificate is used by the firewall to re-sign certificates for trusted sites during SSL Forward Proxy - it must have the private key to perform signing. The Forward…
Question
An administrator is configuring SSL decryption and needs to ensure that all certificates for both SSL Inbound inspection and SSL Forward Proxy are installed properly on the firewall. When certificates are being imported to the firewall for these purposes, which three certificates require a private key? (Choose three.)
Options
- AForward Untrust certificate
- BEnterprise Root CA certificate
- CForward Trust certificate
- DEnd-entity (leaf) certificate
- EIntermediate certificate(s)
How the community answered
(28 responses)- A86% (24)
- B7% (2)
- E7% (2)
Explanation
Private keys are required only when the firewall must actively sign or decrypt traffic. The Forward Trust certificate is used by the firewall to re-sign certificates for trusted sites during SSL Forward Proxy - it must have the private key to perform signing. The Forward Untrust certificate serves the same signing purpose for untrusted or unknown sites. The end-entity (leaf) certificate is required for SSL Inbound Inspection, where the firewall decrypts inbound traffic on behalf of an internal server - it needs the server's private key to do so. The Enterprise Root CA and Intermediate certificates are used only for chain-of-trust validation; the firewall only needs their public certificates, not private keys.
Topics
Community Discussion
No community discussion yet for this question.