<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic About UIA SSL connection in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/about-uia-ssl-connection/m-p/1247004#M6628</link>
    <description>&lt;P&gt;Hello Team,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm currently dealing with an issue where UIA is unable to validate certification.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The certificate does not have a SAN setting.&lt;/P&gt;
&lt;P&gt;I plan to change the certificate to one that has both CN and SAN set, but have not been able to do so yet.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The certificate validation has occurred since applying an OS patch, so I have asked the OS vendor to investigate.&lt;/P&gt;
&lt;P&gt;The OS vendor has stated that there is no Schannel SSP communication when the issue occurs.&lt;BR /&gt;The OS vendor has asked me to confirm whether UIA uses Schannel SSP.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does anyone have information on whether UIA uses Schannel SSP for SSL/TLS communication?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;BR /&gt;Yusuke Narita&lt;/P&gt;</description>
    <pubDate>Thu, 29 Jan 2026 09:57:18 GMT</pubDate>
    <dc:creator>Y.Narita347153</dc:creator>
    <dc:date>2026-01-29T09:57:18Z</dc:date>
    <item>
      <title>About UIA SSL connection</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/about-uia-ssl-connection/m-p/1247004#M6628</link>
      <description>&lt;P&gt;Hello Team,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm currently dealing with an issue where UIA is unable to validate certification.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The certificate does not have a SAN setting.&lt;/P&gt;
&lt;P&gt;I plan to change the certificate to one that has both CN and SAN set, but have not been able to do so yet.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The certificate validation has occurred since applying an OS patch, so I have asked the OS vendor to investigate.&lt;/P&gt;
&lt;P&gt;The OS vendor has stated that there is no Schannel SSP communication when the issue occurs.&lt;BR /&gt;The OS vendor has asked me to confirm whether UIA uses Schannel SSP.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does anyone have information on whether UIA uses Schannel SSP for SSL/TLS communication?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;BR /&gt;Yusuke Narita&lt;/P&gt;</description>
      <pubDate>Thu, 29 Jan 2026 09:57:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/about-uia-ssl-connection/m-p/1247004#M6628</guid>
      <dc:creator>Y.Narita347153</dc:creator>
      <dc:date>2026-01-29T09:57:18Z</dc:date>
    </item>
    <item>
      <title>Re: About UIA SSL connection</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/about-uia-ssl-connection/m-p/1249647#M6758</link>
      <description>&lt;P&gt;The &lt;STRONG&gt;User-ID Agent (UIA)&lt;/STRONG&gt; runs as a Windows service and relies on the &lt;STRONG&gt;Windows TLS/SSL stack&lt;/STRONG&gt; for secure communication. Therefore, TLS operations performed by the agent use the native Windows cryptographic libraries, which include &lt;STRONG&gt;Schannel (Secure Channel SSP)&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;In other words, SSL/TLS communication initiated by the User-ID Agent is handled through the Windows security infrastructure and therefore utilizes &lt;STRONG&gt;Schannel SSP&lt;/STRONG&gt; for certificate validation and TLS negotiation.&lt;/P&gt;&lt;P&gt;Regarding the certificate validation issue, it is possible that the recent OS patch introduced stricter certificate validation requirements. Modern Windows updates often require the &lt;STRONG&gt;Subject Alternative Name (SAN)&lt;/STRONG&gt; extension for proper certificate validation, and certificates that only contain the &lt;STRONG&gt;Common Name (CN)&lt;/STRONG&gt; may fail validation in some cases.&lt;/P&gt;</description>
      <pubDate>Sun, 08 Mar 2026 08:43:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/about-uia-ssl-connection/m-p/1249647#M6758</guid>
      <dc:creator>abayoumi21</dc:creator>
      <dc:date>2026-03-08T08:43:34Z</dc:date>
    </item>
  </channel>
</rss>

