nerdexam
Palo_Alto_Networks

PCNSE · Question #841

SSL Forward Proxy decryption is configured, but the firewall uses Untrusted-CA to sign the certificate is not trusted" warning. Without SSL decryption, the web browser shows that the website…

The correct answer is C. Navigate to Device > Certificate Management > Certificates > Default Trusted Certificate. The goal is for important-website.com (whose certificate is signed by Well-Known-Intermediate-CA and Well-Known-Root-CA) to appear trusted to end-users, while untrusted sites still trigger a warning. The issue is that the firewall doesn't recognize the Well-Known-Root-CA as…

Submitted by yasin.bd· Apr 18, 2026Configuration Troubleshooting

Question

SSL Forward Proxy decryption is configured, but the firewall uses Untrusted-CA to sign the certificate is not trusted" warning. Without SSL decryption, the web browser shows that the website certificate is trusted and signed by a well-known certificate chain Well-Known- Intermediate and Well-Known-Root-CA. The network security administrator who represents the customer requires the following two behaviors when SSL Forward Proxy is enabled:

important-website.com/website

  • End-users should get the warning for any other untrusted website

Which approach meets the two customer requirements?

Options

  • AInstall the Well-Known-Intermediate-CA and Well-Known-Root-CA certificates on all end-user
  • BClear the Forward Untrust Certificate check box on the Untrusted-CA certificate and commit the
  • CNavigate to Device > Certificate Management > Certificates > Default Trusted Certificate
  • DNavigate to Device > Certificate Management > Certificates > Device Certificates, import Well-

How the community answered

(15 responses)
  • A
    7% (1)
  • B
    7% (1)
  • C
    73% (11)
  • D
    13% (2)

Explanation

The goal is for important-website.com (whose certificate is signed by Well-Known-Intermediate-CA and Well-Known-Root-CA) to appear trusted to end-users, while untrusted sites still trigger a warning. The issue is that the firewall doesn't recognize the Well-Known-Root-CA as trusted, so it uses its Untrusted-CA to re-sign the decrypted certificate, causing a browser warning even for legitimate sites. By navigating to Device > Certificate Management > Certificates > Default Trusted Certificate Authorities (C) and enabling the Well-Known-Root-CA and Well-Known-Intermediate-CA entries, the firewall recognizes that CA chain as trusted. It then uses the Forward Trust Certificate to re-sign certificates for sites in that chain (no warning), while continuing to use Untrusted-CA for genuinely untrusted sites (warning preserved).

Topics

#SSL Decryption#Certificate Management#Forward Proxy#Trusted CAs

Community Discussion

No community discussion yet for this question.

Full PCNSE Practice