SSL Forward Proxy decryption failures for sessions using DigiCert CA
Incident Report for Palo Alto Networks Cloud Services
Resolved
This incident has been resolved.
Posted Mar 24, 2023 - 15:07 UTC
Update
We are continuing to monitor for any further issues.
Posted Mar 11, 2023 - 04:34 UTC
Monitoring
After reviewing internally with the teams, the below fix has been identified to address the issue:

Modify any of the following configurations and commit the changes. This will automatically clear the certificate cache.

Decryption policy
Decryption profile
Device Certificates - Must check Trusted Root CA to clear the cache if adding a certificate. When importing intermediate CA certificate please follow the steps in the following tech doc

If you continue to run into issues despite applying the above recommended changes, please reach out to the support team to assist further.
Posted Mar 11, 2023 - 04:32 UTC
Update
The issue has been root caused and the SRE/Dev team are working internally to determine the steps to fix the issue.
The next update will be shared by March 11, 02:00 AM UTC
Posted Mar 10, 2023 - 22:11 UTC
Update
We are continuing to work on a fix for this issue.
Posted Mar 10, 2023 - 19:45 UTC
Identified
The users may be presented with an expired certificate that was signed by the forward proxy for websites that use Digicert CA certs in the certificate cache.

We are continuing to investigate this issue and we will update about the next steps by March 10, 10 PM UTC
Posted Mar 10, 2023 - 19:44 UTC