PCNSE · Question #841
SSL Forward Proxy decryption is configured, but the firewall uses Untrusted-CA to sign the certificate is not trusted" warning. Without SSL decryption, the web browser shows that the website…
The correct answer is C. Navigate to Device > Certificate Management > Certificates > Default Trusted Certificate. The goal is for important-website.com (whose certificate is signed by Well-Known-Intermediate-CA and Well-Known-Root-CA) to appear trusted to end-users, while untrusted sites still trigger a warning. The issue is that the firewall doesn't recognize the Well-Known-Root-CA as…
Question
SSL Forward Proxy decryption is configured, but the firewall uses Untrusted-CA to sign the certificate is not trusted" warning. Without SSL decryption, the web browser shows that the website certificate is trusted and signed by a well-known certificate chain Well-Known- Intermediate and Well-Known-Root-CA. The network security administrator who represents the customer requires the following two behaviors when SSL Forward Proxy is enabled:
important-website.com/website
- End-users should get the warning for any other untrusted website
Which approach meets the two customer requirements?
Options
- AInstall the Well-Known-Intermediate-CA and Well-Known-Root-CA certificates on all end-user
- BClear the Forward Untrust Certificate check box on the Untrusted-CA certificate and commit the
- CNavigate to Device > Certificate Management > Certificates > Default Trusted Certificate
- DNavigate to Device > Certificate Management > Certificates > Device Certificates, import Well-
How the community answered
(15 responses)- A7% (1)
- B7% (1)
- C73% (11)
- D13% (2)
Explanation
The goal is for important-website.com (whose certificate is signed by Well-Known-Intermediate-CA and Well-Known-Root-CA) to appear trusted to end-users, while untrusted sites still trigger a warning. The issue is that the firewall doesn't recognize the Well-Known-Root-CA as trusted, so it uses its Untrusted-CA to re-sign the decrypted certificate, causing a browser warning even for legitimate sites. By navigating to Device > Certificate Management > Certificates > Default Trusted Certificate Authorities (C) and enabling the Well-Known-Root-CA and Well-Known-Intermediate-CA entries, the firewall recognizes that CA chain as trusted. It then uses the Forward Trust Certificate to re-sign certificates for sites in that chain (no warning), while continuing to use Untrusted-CA for genuinely untrusted sites (warning preserved).
Topics
Community Discussion
No community discussion yet for this question.