Palo Alto Networks Certified Network Security Administrator (PCNSA)Security Policy ConfigurationMedium
A company is implementing decryption for outbound SSL/TLS traffic. After enabling decryption, users report certificate warnings and trust errors on their web browsers when accessing various websites. Which of the following is the most likely cause for these errors?
- AThe decryption policy is configured to 'No Decrypt' for the affected traffic.
- BThe SSL/TLS handshake between the client and the firewall is failing.
- CThe web servers are using self-signed certificates.
- DThe firewall's root CA certificate is not installed on user workstations.
Show answer & explanationAnswer & explanation
Correct answer: D. The firewall's root CA certificate is not installed on user workstations.
When the firewall decrypts SSL/TLS traffic, it acts as a man-in-the-middle, re-signing server certificates with its own enterprise root CA. If this firewall's root CA certificate is not trusted by the user's browser (i.e., not installed), the browser will issue certificate warnings because it cannot validate the certificate chain.
Why the other options are wrong
- A. If the decryption policy was 'No Decrypt', users wouldn't experience certificate warnings related to the firewall; the traffic would simply pass through encrypted.
- B. A failing SSL/TLS handshake would typically result in a connection error, not specifically a certificate warning about trust.
- C. While web servers using self-signed certificates can cause warnings, this issue would occur regardless of decryption. The problem here is specifically related to the *firewall's* role in decrypting.
SSL/TLS Decryption Trust
For SSL/TLS decryption to function without browser warnings, the firewall's generated root CA certificate must be installed and trusted by client devices.
- Firewall acts as an intermediary (man-in-the-middle).
- Re-signs server certificates with its own CA.
- Client devices must trust the firewall's CA to avoid warnings.
Memory trick: Decryption Needs Client Trust of Firewall's Key.