wouldn't the only correct answer be B?
Must be a CA to be used. must have private key also. can be a root but doesnt have to be.... so that only leaves B as correct answer? anyone? as far as i know you cant use public certs for decryption? so cant be A
There is no key on the D. The question is "can be used", not "is used". We only need to click on the certificate, then check the box " Forward trust Certificate". Only B is correct.
You are correct. You cannot use certificates from well known third party CA's (like GoDaddy, etc) for decryption. The more elegant approach for SSL Forward Proxy and the easiest by far is a to use a domain CA because automatically all domain joined machines will trust those certificates, overcoming the challenge of distribution of the decryption certificate.
My vote is for C.
https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-admin/decryption/configure-ssl-forward-proxy
In Step 4 of the Use a self-signed certificate as the Forward Trust certificate, which is titled "Generate new subordinate CA certificates for each firewall" it follows with 5. "Click the new certificate to modify it and click the Forward Trust Certificate checkbox to configure the certificate as the Forward Trust Certificate".
The CA box is only necessary to be checked for the Intermediate key. It is the cert created from the Intermediate CA that is used as the Forward Trust cert.
There is no key on the D. The question is "can be used", not "is used". We only need to click on the certificate, then check the box " Forward trust Certificate". Only B is correct.
There is no key on the D. The question is "can be used", not "is used". We only need to click on the certificate, then check the box " Forward trust Certificate". Only B is correct.
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Breyarg
Highly Voted 3 years, 1 month agoNHANTON
3 years agoGivemeMoney
3 years agoKnowledge33
1 year, 7 months agoPretorian
2 years, 5 months agoCarlosDV06
Most Recent 2 months, 2 weeks agoMarshpillowz
12 months agoJRKhan
1 year agoGabranch
1 year, 1 month agoPaloSteve
1 year, 6 months agoKnowledge33
1 year, 7 months agoKKQQ12345
2 years, 5 months agoKKQQ12345
2 years, 5 months agoKnowledge33
1 year, 7 months agoUFanat
2 years, 6 months agoMeira088
2 years, 7 months ago1Adrian1
2 years, 9 months agoNHANTON
3 years agopoiuytr
2 years, 9 months agoNHANTON
3 years ago