Block sessions with untrusted issuers in the Forward
Proxy Decryption profile.
When you block sessions with untrusted issuers in the Decryption profile, the
Decryption logs log the error.
Select ObjectsDecryptionDecryption Profiles. Then, select a profile to modify or create a new
profile.
Filter the log to identify sessions that failed due to revoked certificates
using the query (error eq ‘Untrusted issuer CA’).
(Optional) Double-check the certificate expiration date at the Qualys
SSL Labs site.
Enter the hostname of the server (Server Name
Identification column of the Decryption log) in the
Hostname field and Submit
it to view certificate information for the host.