The designation for a root certificate issued by a CA that the
firewall trusts. The firewall can use a self-signed root CA
certificate to automatically issue certificates for other
applications (for example, SSL Forward Proxy).
Also, if a firewall must establish secure connections with other
firewalls, the root CA that issues their certificates must be in the
list of trusted root CAs on the firewall.
(Panorama managed firewalls) The Trusted Root
CA setting for a CA must be configured as part of
the template configuration, and not part of the template stack
configuration. If you configure the Trusted Root
CA setting for a CA as part of the template stack
configuration, the associated templates do not inherit the setting
for the CA.
|