Why does Prisma Browser display the 'ERR_PROXY_CERTIFICATE_INVALID' error for private apps or internet?
1858
Created On 08/05/25 22:36 PM - Last Modified 04/16/26 21:40 PM
Symptom
Prisma Browser displays ERR_PROXY_CERTIFICATE_INVALID error when accessing private apps or internet.
Environment
- Prisma Access
- Prisma Browser (Formerly Prisma Access Browser)
Cause
- The traffic from Prisma Browser to Prisma Access Explicit Proxy is subject to SSL decryption.
- Since the Prisms Browser by default does not trust unknown CA (For example an organisation's CA certificate which is decrypting all the traffic), the communication fails with error "ERR_PROXY_CERTIFICATE_INVALID"
Resolution
- Refer to the Prisma Browser prerequisites, which list the FQDNs that must be allowed and excluded from decryption for your specific region.
- Configure the upstream firewall or security device to exclude the Explicit Proxy FQDN from decryption. (The FQDN can be found under prisma://troubleshoot/ section in Prisma Access integration section.
- Alternatively, Import the decryption CA certificate in Prisma Browser security policy as a Trusted certificate. This will make sure the browser trusts the connection to EP FQDN even with decryption.