While troubleshooting an SSL Forward Proxy decryption issue, which PAN-OS CLI command would you use to check the details of the end entity certificate that is signed by the Forward Trust Certificate or Forward Untrust Certificate?
A.
show system setting ssl-decrypt certs
B.
show system setting ssl-decrypt certificate
C.
debug dataplane show ssl-decrypt ssl-stats
D.
show system setting ssl-decrypt certificate-cache
Read the question - "end entity certificate".
Now run the various command options on your firewall.
Answer A is invalid syntax
Answer B shows you your Certificates installed on your Palo; not end-entity certificates
Answer C shows you some various hit counters.
Answer D shows you certificate details from "end entities"
Answer is D. The cache space is limited, so you will only see recent certificates cached if you have a busy firewall. But the certificates in that certificate cache are placed there when the firewall retrieves the certificate for a traffic flow that matches an SSL Forward Proxy decryption policy. Note that the end-entity certificate is the final link in the chain of trust.
Answer is D. The cache space is limited, so you will only see recent certificates cached if you have a busy firewall. But the certificates in that certificate cache are placed there when the firewall retrieves the certificate for a traffic flow that matches an SSL Forward Proxy decryption policy. Note that the end-entity certificate is the final link in the chain of trust.
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
ConfuzedOne
Highly Voted 1 year, 7 months agoUFanat
Highly Voted 2 years, 7 months agoapiloran
Most Recent 3 months, 3 weeks agokacper_n99
8 months, 1 week agoEluis007
9 months, 1 week agoWhizdhum
1 year, 1 month agoWhizdhum
1 year, 1 month agonguyendtv50
1 year, 7 months agotomsui44
1 year, 8 months agoDenskyDen
1 year, 12 months agoTAKUM1y
2 years, 2 months agoManKing36
2 years, 8 months agoUFanat
2 years, 7 months agoshinichi_88
2 years, 11 months ago