<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Letsencrypt (acme) challenge URL in Custom Signatures</title>
    <link>https://live.paloaltonetworks.com/t5/custom-signatures/letsencrypt-acme-challenge-url/m-p/400172#M391</link>
    <description>&lt;P&gt;I created this pattern to recognize Letsencrypt (acme-protocol) challenge.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You need to create a custom application with these fields:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;Typo: Transaction&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Context: http-req-uri-path&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Pattern:&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;LI-CODE lang="markup"&gt;^GET /\.well-known/acme-challenge/&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That's the best I could bet.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Btw, I did not know before that "http-req-uri-path" had to include the method (GET), so I had a hard time using the regex anchor "^".&lt;/P&gt;</description>
    <pubDate>Mon, 19 Apr 2021 17:09:56 GMT</pubDate>
    <dc:creator>Alejandro_Grijalba</dc:creator>
    <dc:date>2021-04-19T17:09:56Z</dc:date>
    <item>
      <title>Letsencrypt (acme) challenge URL</title>
      <link>https://live.paloaltonetworks.com/t5/custom-signatures/letsencrypt-acme-challenge-url/m-p/400172#M391</link>
      <description>&lt;P&gt;I created this pattern to recognize Letsencrypt (acme-protocol) challenge.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You need to create a custom application with these fields:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;Typo: Transaction&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Context: http-req-uri-path&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Pattern:&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;LI-CODE lang="markup"&gt;^GET /\.well-known/acme-challenge/&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That's the best I could bet.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Btw, I did not know before that "http-req-uri-path" had to include the method (GET), so I had a hard time using the regex anchor "^".&lt;/P&gt;</description>
      <pubDate>Mon, 19 Apr 2021 17:09:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/custom-signatures/letsencrypt-acme-challenge-url/m-p/400172#M391</guid>
      <dc:creator>Alejandro_Grijalba</dc:creator>
      <dc:date>2021-04-19T17:09:56Z</dc:date>
    </item>
    <item>
      <title>Re: Letsencrypt (acme) challenge URL</title>
      <link>https://live.paloaltonetworks.com/t5/custom-signatures/letsencrypt-acme-challenge-url/m-p/458526#M417</link>
      <description>&lt;P&gt;You can look at the "QUALIFIER" option as you can select the request method "POST" or "GET" from there and maybe you will not need to specify it in the pattern match.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/u-v/custom-app-id-and-threat-signatures/custom-application-and-threat-signatures/create-a-custom-application-signature.html" target="_blank"&gt;Create Custom Application Signature (paloaltonetworks.com)&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also for blocking something maybe better use IPS signature than app signature:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/threat-prevention/threat-signatures" target="_blank"&gt;Threat Signature Categories (paloaltonetworks.com)&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/threat-prevention/learn-more-about-and-assess-threats/learn-more-about-threat-signatures.html" target="_blank"&gt;Learn More About Threat Signatures (paloaltonetworks.com)&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jan 2022 09:12:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/custom-signatures/letsencrypt-acme-challenge-url/m-p/458526#M417</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2022-01-13T09:12:15Z</dc:date>
    </item>
  </channel>
</rss>

