Why does Prisma Browser display the 'ERR_PROXY_CERTIFICATE_INVALID' error for private apps or internet?

Why does Prisma Browser display the 'ERR_PROXY_CERTIFICATE_INVALID' error for private apps or internet?

1858
Created On 08/05/25 22:36 PM - Last Modified 04/16/26 21:40 PM


Symptom


Prisma Browser displays ERR_PROXY_CERTIFICATE_INVALID error when accessing private apps or internet.
ERR_PROXY_CERTIFICATE_INVALID 



Environment


  • Prisma Access
  • Prisma Browser (Formerly Prisma Access Browser)


Cause


  • The traffic from Prisma Browser to Prisma Access Explicit Proxy is subject to SSL decryption.
  • Since the Prisms Browser by default does not trust unknown CA (For example an organisation's CA certificate which is decrypting all the traffic), the communication fails with error "ERR_PROXY_CERTIFICATE_INVALID"


Resolution


 

  1. Refer to the Prisma Browser prerequisites, which list the FQDNs that must be allowed and excluded from decryption for your specific region.
  2. Configure the upstream firewall or security device to exclude the Explicit Proxy FQDN from decryption. (The FQDN can be found under prisma://troubleshoot/ section in Prisma Access integration section.

 Prisma Troubleshoot page 

 

  1. Alternatively, Import the decryption CA certificate in Prisma Browser security policy as a Trusted certificate. This will make sure the browser trusts the connection to EP FQDN even with decryption.  

Add a CA cert 



Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA1Ki000000TNjMKAW&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail