Certificate Generated during SSL Decryption configuration.
During commit Process, error "forward decrypt trust cert is not configured" message is seen
Environment
Palo Alto Firewalls.
PAN-OS 8.1 and above.
Certificate Configuration.
Cause
SSL decryption requires a certificate for forward proxy. The certificate generated is not marked as "forward Trust certificate".
Resolution
Use the following process to correctly generate and mark the certificate for SSL decryption.
Create a self generated certificate with 'Certificate Authority' checked under GUI: Device > Certificate Management > Certificates > Generate:
Once generated, open the certificate (GUI: Device > Certificate Management > Certificates) and check for Forward Trust Certificate
After clicking OK, the certificate store should look like the following:
Repeat the same process for generating and marking "Forward Untrust Certificate". Use different certificates as "Forward Trust Certificate" and "Forward Untrust Certificate" for SSL decryption.