The designation for a root certificate issued
by a CA that the firewall trusts. The firewall can use a self-signed
root CA certificate to automatically issue certificates for other
applications (for example, SSL
Forward Proxy). Also, if a firewall must establish
secure connections with other firewalls, the root CA that issues
their certificates must be in the list of trusted root CAs on the
firewall.
(Panorama managed firewalls) The Trusted Root
CA setting for a CA must be configured as part of
the template configuration, and not part of the template stack
configuration. If you configure the Trusted Root
CA setting for a CA as part of the template stack
configuration, the associated templates do not inherit the setting
for the CA. |