<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Slack hooks server certificate invalid in Log Forwarding Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/log-forwarding-discussions/slack-hooks-server-certificate-invalid/m-p/534586#M54</link>
    <description>&lt;P&gt;We're running 10.1.8-h2 but having the same issue.&lt;/P&gt;</description>
    <pubDate>Wed, 15 Mar 2023 20:02:26 GMT</pubDate>
    <dc:creator>scottymuse</dc:creator>
    <dc:date>2023-03-15T20:02:26Z</dc:date>
    <item>
      <title>Slack hooks server certificate invalid</title>
      <link>https://live.paloaltonetworks.com/t5/log-forwarding-discussions/slack-hooks-server-certificate-invalid/m-p/534452#M52</link>
      <description>&lt;P&gt;Our firewalls cannot send to hooks.slack.com since they refreshed their cert yesterday (3/14/2023).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I suspect a problem with the way their chain is signing X1 root CA but until they fix it, is there a way to allow the log forwarding service to ignore the invalid cert and send anyway?&amp;nbsp; I see a kb article about doing this for decryption profiles, but not sure if it applies here.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also is there any debugging that can be done on the palo to get more specific detail about what its problem is with the cert?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance for anyone who can advise.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Mar 2023 13:44:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/log-forwarding-discussions/slack-hooks-server-certificate-invalid/m-p/534452#M52</guid>
      <dc:creator>rlarose</dc:creator>
      <dc:date>2023-03-15T13:44:50Z</dc:date>
    </item>
    <item>
      <title>Re: Slack hooks server certificate invalid</title>
      <link>https://live.paloaltonetworks.com/t5/log-forwarding-discussions/slack-hooks-server-certificate-invalid/m-p/534466#M53</link>
      <description>&lt;P&gt;I'm advised by Slack and the LetsEncrypt folks that the "long chain" certificate format being used is valid, so I guess I need a way to tell the firewall that this is okay.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We're running PanOS 9.1.x -- possible this is addressed in a later OS update?&lt;/P&gt;</description>
      <pubDate>Wed, 15 Mar 2023 15:00:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/log-forwarding-discussions/slack-hooks-server-certificate-invalid/m-p/534466#M53</guid>
      <dc:creator>rlarose</dc:creator>
      <dc:date>2023-03-15T15:00:58Z</dc:date>
    </item>
    <item>
      <title>Re: Slack hooks server certificate invalid</title>
      <link>https://live.paloaltonetworks.com/t5/log-forwarding-discussions/slack-hooks-server-certificate-invalid/m-p/534586#M54</link>
      <description>&lt;P&gt;We're running 10.1.8-h2 but having the same issue.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Mar 2023 20:02:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/log-forwarding-discussions/slack-hooks-server-certificate-invalid/m-p/534586#M54</guid>
      <dc:creator>scottymuse</dc:creator>
      <dc:date>2023-03-15T20:02:26Z</dc:date>
    </item>
    <item>
      <title>Re: Slack hooks server certificate invalid</title>
      <link>https://live.paloaltonetworks.com/t5/log-forwarding-discussions/slack-hooks-server-certificate-invalid/m-p/534597#M55</link>
      <description>&lt;P&gt;Well there go my hopes for an upgrade solution.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Testing against any LE long-chain server (e.g., letsencrypt.org slack.com nba.com) results in failure.&amp;nbsp; Testing against any LE short-chain (e.g., la-sso.bounce51.com) or non-LE (e.g., gmail.com) results in successful validation.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So it does appear to be tied to how Palo's Log Forwarding HTTPS process interprets that long-chain LetsEncrypt cert with the expired X3 root.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you have a PaloAlto support case open?&amp;nbsp; We should reference each other so they know this is not us, it's them.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Mar 2023 20:19:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/log-forwarding-discussions/slack-hooks-server-certificate-invalid/m-p/534597#M55</guid>
      <dc:creator>rlarose</dc:creator>
      <dc:date>2023-03-15T20:19:34Z</dc:date>
    </item>
    <item>
      <title>Re: Slack hooks server certificate invalid</title>
      <link>https://live.paloaltonetworks.com/t5/log-forwarding-discussions/slack-hooks-server-certificate-invalid/m-p/534714#M56</link>
      <description>&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;We're running 10.0.8-h4 but having the same issue for 3 days. We follow some logs with push notification from Slack.&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;If you find the solution to the problem, can you share it here?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;I hope this issue will be resolved as soon as possible.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Mar 2023 13:42:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/log-forwarding-discussions/slack-hooks-server-certificate-invalid/m-p/534714#M56</guid>
      <dc:creator>onercan</dc:creator>
      <dc:date>2023-03-16T13:42:21Z</dc:date>
    </item>
    <item>
      <title>Re: Slack hooks server certificate invalid</title>
      <link>https://live.paloaltonetworks.com/t5/log-forwarding-discussions/slack-hooks-server-certificate-invalid/m-p/534719#M57</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/279750"&gt;@onercan&lt;/a&gt;&amp;nbsp;and &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/79395"&gt;@scottymuse&lt;/a&gt;&amp;nbsp;Can you provide your PaloAlto suport case #numbers?&amp;nbsp; I'd like to make sure they are aware this is a PAN-OS issue, not any of our specific configurations.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Mar 2023 14:16:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/log-forwarding-discussions/slack-hooks-server-certificate-invalid/m-p/534719#M57</guid>
      <dc:creator>rlarose</dc:creator>
      <dc:date>2023-03-16T14:16:25Z</dc:date>
    </item>
    <item>
      <title>Re: Slack hooks server certificate invalid</title>
      <link>https://live.paloaltonetworks.com/t5/log-forwarding-discussions/slack-hooks-server-certificate-invalid/m-p/534720#M58</link>
      <description>&lt;P&gt;Can you both provide your PaloAlto suport case #numbers?&amp;nbsp; I'd like to make sure they are aware this is a PAN-OS issue, not any of our specific configurations.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Mar 2023 14:16:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/log-forwarding-discussions/slack-hooks-server-certificate-invalid/m-p/534720#M58</guid>
      <dc:creator>rlarose</dc:creator>
      <dc:date>2023-03-16T14:16:35Z</dc:date>
    </item>
    <item>
      <title>Re: Slack hooks server certificate invalid</title>
      <link>https://live.paloaltonetworks.com/t5/log-forwarding-discussions/slack-hooks-server-certificate-invalid/m-p/534770#M59</link>
      <description>&lt;P&gt;I just created case 02499701&lt;/P&gt;</description>
      <pubDate>Thu, 16 Mar 2023 20:13:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/log-forwarding-discussions/slack-hooks-server-certificate-invalid/m-p/534770#M59</guid>
      <dc:creator>scottymuse</dc:creator>
      <dc:date>2023-03-16T20:13:10Z</dc:date>
    </item>
    <item>
      <title>Re: Slack hooks server certificate invalid</title>
      <link>https://live.paloaltonetworks.com/t5/log-forwarding-discussions/slack-hooks-server-certificate-invalid/m-p/534874#M60</link>
      <description>&lt;P&gt;We still haven't solved the issue. And you?&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/79395"&gt;@scottymuse&lt;/a&gt;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/2581"&gt;@rlarose&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Mar 2023 16:31:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/log-forwarding-discussions/slack-hooks-server-certificate-invalid/m-p/534874#M60</guid>
      <dc:creator>onercan</dc:creator>
      <dc:date>2023-03-17T16:31:00Z</dc:date>
    </item>
    <item>
      <title>Re: Slack hooks server certificate invalid</title>
      <link>https://live.paloaltonetworks.com/t5/log-forwarding-discussions/slack-hooks-server-certificate-invalid/m-p/534881#M61</link>
      <description>&lt;P&gt;No solution yet&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/279750"&gt;@onercan&lt;/a&gt;&amp;nbsp;-- can you share your PaloAlto support case number?&amp;nbsp; It will help lend weight when we can make clear that this is not an individual config problem, but rather a PanOS problem.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Mar 2023 17:03:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/log-forwarding-discussions/slack-hooks-server-certificate-invalid/m-p/534881#M61</guid>
      <dc:creator>rlarose</dc:creator>
      <dc:date>2023-03-17T17:03:27Z</dc:date>
    </item>
    <item>
      <title>Re: Slack hooks server certificate invalid</title>
      <link>https://live.paloaltonetworks.com/t5/log-forwarding-discussions/slack-hooks-server-certificate-invalid/m-p/535117#M62</link>
      <description>&lt;P&gt;We can't open to case for 10.0.8-h4 End of Support.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Did palo alto engineers respond to the case? &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/79395"&gt;@scottymuse&lt;/a&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Mar 2023 16:51:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/log-forwarding-discussions/slack-hooks-server-certificate-invalid/m-p/535117#M62</guid>
      <dc:creator>onercan</dc:creator>
      <dc:date>2023-03-20T16:51:58Z</dc:date>
    </item>
    <item>
      <title>Re: Slack hooks server certificate invalid</title>
      <link>https://live.paloaltonetworks.com/t5/log-forwarding-discussions/slack-hooks-server-certificate-invalid/m-p/535118#M63</link>
      <description>&lt;P&gt;We know it's not inherent to the PanOS version, as I'm runing 9.1 and &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/79395"&gt;@scottymuse&lt;/a&gt;&amp;nbsp;is running 10.1.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are your firewalls just not under support at all?&amp;nbsp; As long as they are, even on the end-of-support OS, you should be able to raise a case and it would help put pressure on Palo to acknowledge and address it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also press the issue with Slack -- it's their change that broke things.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Mar 2023 17:04:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/log-forwarding-discussions/slack-hooks-server-certificate-invalid/m-p/535118#M63</guid>
      <dc:creator>rlarose</dc:creator>
      <dc:date>2023-03-20T17:04:37Z</dc:date>
    </item>
    <item>
      <title>Re: Slack hooks server certificate invalid</title>
      <link>https://live.paloaltonetworks.com/t5/log-forwarding-discussions/slack-hooks-server-certificate-invalid/m-p/535121#M64</link>
      <description>&lt;P&gt;Here is the latest response I received:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;Greetings!

As you mentioned earlier there is a workaround going on related to this issue.

It is related to a feature request.

I have checked the case associated with Rlarose and the case was closed.

Kindly Let me know if you have any concerns regarding this issue I will be happy to assist you.

Have a great day!&lt;/LI-CODE&gt;&lt;P&gt;I'm not exactly happy with that reply. The workaround I mentioned to TAC was we stopped using it temporarily while it is broken and modified our workflow. I guess properly reading certs is a feature request now?&lt;/P&gt;</description>
      <pubDate>Mon, 20 Mar 2023 17:14:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/log-forwarding-discussions/slack-hooks-server-certificate-invalid/m-p/535121#M64</guid>
      <dc:creator>scottymuse</dc:creator>
      <dc:date>2023-03-20T17:14:01Z</dc:date>
    </item>
    <item>
      <title>Re: Slack hooks server certificate invalid</title>
      <link>https://live.paloaltonetworks.com/t5/log-forwarding-discussions/slack-hooks-server-certificate-invalid/m-p/535122#M65</link>
      <description>&lt;P&gt;My case has not been closed -- they're referring to the case about 2 weeks prior when slack also jiggled the handle on their cert (maybe a dry-run?) which caused me some trouble.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My open, active, unresovled case number you can reference is&amp;nbsp;&lt;SPAN&gt;02496793&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Mar 2023 17:19:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/log-forwarding-discussions/slack-hooks-server-certificate-invalid/m-p/535122#M65</guid>
      <dc:creator>rlarose</dc:creator>
      <dc:date>2023-03-20T17:19:06Z</dc:date>
    </item>
    <item>
      <title>Re: Slack hooks server certificate invalid</title>
      <link>https://live.paloaltonetworks.com/t5/log-forwarding-discussions/slack-hooks-server-certificate-invalid/m-p/535123#M66</link>
      <description>&lt;P&gt;Yeah, I figured there was some &lt;EM&gt;confusion&lt;/EM&gt; (to put it mildly) on that reply regarding your case. I've replied asking for a time frame I could expect this feature request to be fulfilled.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Mar 2023 17:28:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/log-forwarding-discussions/slack-hooks-server-certificate-invalid/m-p/535123#M66</guid>
      <dc:creator>scottymuse</dc:creator>
      <dc:date>2023-03-20T17:28:12Z</dc:date>
    </item>
    <item>
      <title>Re: Slack hooks server certificate invalid</title>
      <link>https://live.paloaltonetworks.com/t5/log-forwarding-discussions/slack-hooks-server-certificate-invalid/m-p/535124#M67</link>
      <description>&lt;P&gt;The feature request they're referring to from the closed case is not related to this problem.&amp;nbsp; It's about avoiding the infinite loop of system logs trying to send to a dead log server, which fails &amp;amp; raises a system log which it tries to send to the log server, which fails &amp;amp; raises a system log..... etc forever.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Mar 2023 17:35:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/log-forwarding-discussions/slack-hooks-server-certificate-invalid/m-p/535124#M67</guid>
      <dc:creator>rlarose</dc:creator>
      <dc:date>2023-03-20T17:35:59Z</dc:date>
    </item>
    <item>
      <title>Re: Slack hooks server certificate invalid</title>
      <link>https://live.paloaltonetworks.com/t5/log-forwarding-discussions/slack-hooks-server-certificate-invalid/m-p/535125#M68</link>
      <description>&lt;P&gt;Ah, yes, now I'm the one confused. Either way, I also referenced your current active case and suggested that properly validating certificates should be a priority. We'll see how they respond.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Mar 2023 17:39:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/log-forwarding-discussions/slack-hooks-server-certificate-invalid/m-p/535125#M68</guid>
      <dc:creator>scottymuse</dc:creator>
      <dc:date>2023-03-20T17:39:48Z</dc:date>
    </item>
    <item>
      <title>Re: Slack hooks server certificate invalid</title>
      <link>https://live.paloaltonetworks.com/t5/log-forwarding-discussions/slack-hooks-server-certificate-invalid/m-p/536375#M69</link>
      <description>&lt;P&gt;Good news, TAC responded to me and called this an "outbreak globally for the slack integration users". They are looking into the cause. My guess is this will be fixed in a future update, but they'll let me know.&lt;/P&gt;</description>
      <pubDate>Fri, 24 Mar 2023 18:31:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/log-forwarding-discussions/slack-hooks-server-certificate-invalid/m-p/536375#M69</guid>
      <dc:creator>scottymuse</dc:creator>
      <dc:date>2023-03-24T18:31:01Z</dc:date>
    </item>
    <item>
      <title>Re: Slack hooks server certificate invalid</title>
      <link>https://live.paloaltonetworks.com/t5/log-forwarding-discussions/slack-hooks-server-certificate-invalid/m-p/536376#M70</link>
      <description>&lt;P&gt;Well acknowledging the noise we're making is a good first step.&amp;nbsp; They need to band-aid it right away, though.&lt;/P&gt;</description>
      <pubDate>Fri, 24 Mar 2023 18:33:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/log-forwarding-discussions/slack-hooks-server-certificate-invalid/m-p/536376#M70</guid>
      <dc:creator>rlarose</dc:creator>
      <dc:date>2023-03-24T18:33:51Z</dc:date>
    </item>
    <item>
      <title>Re: Slack hooks server certificate invalid</title>
      <link>https://live.paloaltonetworks.com/t5/log-forwarding-discussions/slack-hooks-server-certificate-invalid/m-p/536378#M71</link>
      <description>&lt;P&gt;This is really goods news, they finally heard our voice. I hope the update will be posted as soon as possible.&lt;/P&gt;</description>
      <pubDate>Fri, 24 Mar 2023 18:51:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/log-forwarding-discussions/slack-hooks-server-certificate-invalid/m-p/536378#M71</guid>
      <dc:creator>onercan</dc:creator>
      <dc:date>2023-03-24T18:51:42Z</dc:date>
    </item>
  </channel>
</rss>

