SSL Forward Proxy decryption failures for sessions using DigiCert CA

Incident Report for Palo Alto Networks Cloud Services

Resolved

This incident has been resolved.
Posted Mar 24, 2023 - 15:07 UTC

Update

We are continuing to monitor for any further issues.
Posted Mar 11, 2023 - 04:34 UTC

Monitoring

After reviewing internally with the teams, the below fix has been identified to address the issue:

Modify any of the following configurations and commit the changes. This will automatically clear the certificate cache.

Decryption policy
Decryption profile
Device Certificates - Must check Trusted Root CA to clear the cache if adding a certificate. When importing intermediate CA certificate please follow the steps in the following tech doc

If you continue to run into issues despite applying the above recommended changes, please reach out to the support team to assist further.
Posted Mar 11, 2023 - 04:32 UTC

Update

The issue has been root caused and the SRE/Dev team are working internally to determine the steps to fix the issue.
The next update will be shared by March 11, 02:00 AM UTC
Posted Mar 10, 2023 - 22:11 UTC

Update

We are continuing to work on a fix for this issue.
Posted Mar 10, 2023 - 19:45 UTC

Identified

The users may be presented with an expired certificate that was signed by the forward proxy for websites that use Digicert CA certs in the certificate cache.

We are continuing to investigate this issue and we will update about the next steps by March 10, 10 PM UTC
Posted Mar 10, 2023 - 19:44 UTC