<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Paloalto TLS/SSL error while forwarding logs over TLS Syslog in Panorama Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/panorama-discussions/paloalto-tls-ssl-error-while-forwarding-logs-over-tls-syslog/m-p/1205221#M2757</link>
    <description>&lt;P&gt;&lt;SPAN&gt;No help even from palo alto support team, so using normal syslog for log collection&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 23 Jan 2025 19:23:02 GMT</pubDate>
    <dc:creator>vasanthakumaran.chandran</dc:creator>
    <dc:date>2025-01-23T19:23:02Z</dc:date>
    <item>
      <title>Paloalto TLS/SSL error while forwarding logs over TLS Syslog</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/paloalto-tls-ssl-error-while-forwarding-logs-over-tls-syslog/m-p/586288#M2327</link>
      <description>&lt;P&gt;&lt;SPAN class="ph uicontrol"&gt;PKCS12 Certificate&amp;nbsp; and Password generated from Paloalto is used at syslog server to establish connection between both system and used to decrypt the logs. However after establishing the connection the ssl handshake is broken and we see below error.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Syslog&amp;nbsp;SSL error while writing stream; tls_error='rsa routines:RSA_padding_check_PKCS1_type_1:invalid padding'. location='/opt/pancfg/mgmt/syslogng/pan_sysng,cfg:59:3'&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kindly help to understand this error, is it anything related to the certificate generated or do we have any other checklist to fix this issue.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 09 May 2024 14:17:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/paloalto-tls-ssl-error-while-forwarding-logs-over-tls-syslog/m-p/586288#M2327</guid>
      <dc:creator>vasanthakumaran.chandran</dc:creator>
      <dc:date>2024-05-09T14:17:35Z</dc:date>
    </item>
    <item>
      <title>Re: Paloalto TLS/SSL error while forwarding logs over TLS Syslog</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/paloalto-tls-ssl-error-while-forwarding-logs-over-tls-syslog/m-p/586291#M2328</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Its possible its showing the incorrect error in relation to this bug ID:&lt;/P&gt;
&lt;TABLE class="table colsep rowsep  table-striped" width="651px"&gt;
&lt;TBODY class="tbody"&gt;
&lt;TR class="row"&gt;
&lt;TD width="100.891px" height="140px" class="entry"&gt;
&lt;DIV&gt;
&lt;DIV class="p"&gt;
&lt;DIV&gt;
&lt;DIV&gt;PAN-241772&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/TD&gt;
&lt;TD width="549.109px" height="140px" class="entry relcol"&gt;
&lt;DIV class="p"&gt;Fixed an issue where, when TLSv1.3 was used, an incorrect error message&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;
&lt;DIV&gt;invalid padding&amp;nbsp;&lt;SPAN&gt;was displayed instead of the expected error message&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Invalid server certificate&lt;/DIV&gt;
.&lt;/DIV&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The certificate used for secure syslog on the firewall needs to have the CN set as the IP address of the interface that it is using to send the secure syslog information. Is this the case in your setup? And are you using a self-signed certificate, if so does wherever you're logging syslog data to trust this certificate?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000HCLCCA4&amp;amp;lang=en_US%E2%80%A9" target="_blank" rel="noopener"&gt;How To Setup Syslog Monitoring Over TLS - Knowledge Base - Palo Alto Networks&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 09 May 2024 14:25:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/paloalto-tls-ssl-error-while-forwarding-logs-over-tls-syslog/m-p/586291#M2328</guid>
      <dc:creator>Claw4609</dc:creator>
      <dc:date>2024-05-09T14:25:56Z</dc:date>
    </item>
    <item>
      <title>Re: Paloalto TLS/SSL error while forwarding logs over TLS Syslog</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/paloalto-tls-ssl-error-while-forwarding-logs-over-tls-syslog/m-p/586366#M2329</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We are using TLSv1.2,&amp;nbsp; is this also having incorrect error message issue?.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;And CN ip address used is the Firewall interface IP, also the self-signed certificate is imported to the syslog server still we are not able to fix this error.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Syslog&amp;nbsp;SSL error while writing stream; tls_error='rsa routines:RSA_padding_check_PKCS1_type_1:invalid padding'. location='/opt/pancfg/mgmt/syslogng/pan_sysng,cfg:59:3'&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 10 May 2024 05:28:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/paloalto-tls-ssl-error-while-forwarding-logs-over-tls-syslog/m-p/586366#M2329</guid>
      <dc:creator>vasanthakumaran.chandran</dc:creator>
      <dc:date>2024-05-10T05:28:48Z</dc:date>
    </item>
    <item>
      <title>Re: Paloalto TLS/SSL error while forwarding logs over TLS Syslog</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/paloalto-tls-ssl-error-while-forwarding-logs-over-tls-syslog/m-p/586385#M2330</link>
      <description>&lt;P&gt;What version of Pan-os are you using? We've got secure syslog setup and I personally havent received that error before. What happens if you generate a different cert and try that? To confirm, do you have the "Certificate for Secure Syslog" checked on the cert&lt;/P&gt;</description>
      <pubDate>Fri, 10 May 2024 14:25:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/paloalto-tls-ssl-error-while-forwarding-logs-over-tls-syslog/m-p/586385#M2330</guid>
      <dc:creator>Claw4609</dc:creator>
      <dc:date>2024-05-10T14:25:25Z</dc:date>
    </item>
    <item>
      <title>Re: Paloalto TLS/SSL error while forwarding logs over TLS Syslog</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/paloalto-tls-ssl-error-while-forwarding-logs-over-tls-syslog/m-p/586387#M2331</link>
      <description>&lt;P&gt;pan os 10.2.8-h3 is the version. Yes we followed the guide&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000HCLCCA4&amp;amp;lang=en_US%E2%80%A9" target="_blank" rel="noopener nofollow noreferrer"&gt;How To Setup Syslog Monitoring Over TLS - Knowledge Base - Palo Alto Networks&lt;/A&gt;&amp;nbsp;and&amp;nbsp;&lt;SPAN&gt;"Certificate for Secure Syslog" checked on the cert. Also tried with different cert couple of time as well.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;We have onboarded 3 more firewalls folowing the guide and no issues. Only this firewall is having error.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Attached the error for reference.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2567-05-10 at 21.44.50.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/59619i798FC2F6E40FE56A/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Screenshot 2567-05-10 at 21.44.50.png" alt="Screenshot 2567-05-10 at 21.44.50.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Fri, 10 May 2024 14:47:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/paloalto-tls-ssl-error-while-forwarding-logs-over-tls-syslog/m-p/586387#M2331</guid>
      <dc:creator>vasanthakumaran.chandran</dc:creator>
      <dc:date>2024-05-10T14:47:00Z</dc:date>
    </item>
    <item>
      <title>Re: Paloalto TLS/SSL error while forwarding logs over TLS Syslog</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/paloalto-tls-ssl-error-while-forwarding-logs-over-tls-syslog/m-p/1205219#M2755</link>
      <description>&lt;P&gt;Hi Vasanth, I am facing similar issue.. were you able to figure out what was wrong in your case?&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jan 2025 19:07:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/paloalto-tls-ssl-error-while-forwarding-logs-over-tls-syslog/m-p/1205219#M2755</guid>
      <dc:creator>pvootla</dc:creator>
      <dc:date>2025-01-23T19:07:58Z</dc:date>
    </item>
    <item>
      <title>Re: Paloalto TLS/SSL error while forwarding logs over TLS Syslog</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/paloalto-tls-ssl-error-while-forwarding-logs-over-tls-syslog/m-p/1205221#M2757</link>
      <description>&lt;P&gt;&lt;SPAN&gt;No help even from palo alto support team, so using normal syslog for log collection&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jan 2025 19:23:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/paloalto-tls-ssl-error-while-forwarding-logs-over-tls-syslog/m-p/1205221#M2757</guid>
      <dc:creator>vasanthakumaran.chandran</dc:creator>
      <dc:date>2025-01-23T19:23:02Z</dc:date>
    </item>
  </channel>
</rss>

