How to Perform Client Certificate Install for SSL Decryption
92720
Created On 09/25/18 19:24 PM - Last Modified 06/08/23 19:46 PM
Environment
- Palo Alto Firewall.
- Supported PAN-OS.
- SSL decryption configured
- Certificate installation on Windows Host.
Cause
Resolution
- Export certificate from the Palo Alto Networks firewall
- Go to Device > Certificate Management > Certificates
- Under the Device Certificates tab, select the certificate to export
- Click the Export button
- Install the certificate on the client system
- Double-click on the certificate
- Click Install Certificate to launch the Certificate Import Wizard
- On the Certificate Store page, check "Place all certificates in the following store"
- Note: When importing into the client browser, ensure that you add the certificate to the Trusted Root Certification Authorities certificate store. On Windows systems, the default import location is the Personal certificate store. See. Configure SSL Forward Proxy
- Click Browse and select "Trusted Root Certification Authorities"
- Click Next and then Finish
- Click Yes when the Security Warning appears
- Click OK on the success dialog
Verification
Chrome browser
- Enter Settings page
- Click "Show advanced settings…" at the bottom of the page
- Scroll down to HTTPS/SSL and click "Manage certificates…"
- Go to the Trusted Root Certification Authorities tab and verify the imported certificate
Internet Explorer browser
- Bring up the Internet Options dialog
- Go to the Content tab
- Click Certificates
- Go to the Trusted Root Certification Authorities tab and verify the imported certificate
Additional Information
Local Machine and Current User Certificate Stores