<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Need clarification on recommended Authentication Algorithm in Prisma Access Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/need-clarification-on-recommended-authentication-algorithm/m-p/296687#M28</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/123486"&gt;@devd_25&lt;/a&gt;&amp;nbsp; Anything from SHA256 and above is secure. To use SHA-512 or SHA-384, you need to have compatible servers and are not widely used. Other reasons include processing time.&amp;nbsp; Following public links can add some more info&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://security.stackexchange.com/questions/165559/why-would-i-choose-sha-256-over-sha-512-for-a-ssl-tls-certificate" target="_blank"&gt;https://security.stackexchange.com/questions/165559/why-would-i-choose-sha-256-over-sha-512-for-a-ssl-tls-certificate&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://automationrhapsody.com/md5-sha-1-sha-256-sha-512-speed-performance/" target="_blank"&gt;https://automationrhapsody.com/md5-sha-1-sha-256-sha-512-speed-performance/&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 06 Nov 2019 13:28:47 GMT</pubDate>
    <dc:creator>Sai_Tumuluri</dc:creator>
    <dc:date>2019-11-06T13:28:47Z</dc:date>
    <item>
      <title>Need clarification on recommended Authentication Algorithm</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/need-clarification-on-recommended-authentication-algorithm/m-p/296587#M25</link>
      <description>&lt;P&gt;Quoting from the &lt;A href="https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/vpns/set-up-site-to-site-vpn/define-cryptographic-profiles/define-ipsec-crypto-profiles.html#idf7dc1080-0595-40ef-9849-f3d4887f1b8a" target="_self"&gt;docs&lt;/A&gt; for&amp;nbsp;&lt;STRONG&gt;Define IPSec Crypto Profiles&lt;/STRONG&gt;, it says&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;For the authentication algorithm, use SHA-256 or higher (SHA-384 or higher preferred for long-lived transactions). Do not use SHA-512, SHA-1, or MD5. &lt;/LI-CODE&gt;&lt;P&gt;Whereas, going from most to least secure, it recommends the below order&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;Authentication—sha512, sha384, sha256, sha1, md5.&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;Can someone please help clarify what is right or wrong ? Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 06 Nov 2019 03:32:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/need-clarification-on-recommended-authentication-algorithm/m-p/296587#M25</guid>
      <dc:creator>devd_25</dc:creator>
      <dc:date>2019-11-06T03:32:43Z</dc:date>
    </item>
    <item>
      <title>Re: Need clarification on recommended Authentication Algorithm</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/need-clarification-on-recommended-authentication-algorithm/m-p/296611#M26</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/123486"&gt;@devd_25&lt;/a&gt;&amp;nbsp;The second line shows what is supported on the firewall and the first what is recommended to use.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Nov 2019 07:48:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/need-clarification-on-recommended-authentication-algorithm/m-p/296611#M26</guid>
      <dc:creator>BatD</dc:creator>
      <dc:date>2019-11-06T07:48:27Z</dc:date>
    </item>
    <item>
      <title>Re: Need clarification on recommended Authentication Algorithm</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/need-clarification-on-recommended-authentication-algorithm/m-p/296687#M28</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/123486"&gt;@devd_25&lt;/a&gt;&amp;nbsp; Anything from SHA256 and above is secure. To use SHA-512 or SHA-384, you need to have compatible servers and are not widely used. Other reasons include processing time.&amp;nbsp; Following public links can add some more info&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://security.stackexchange.com/questions/165559/why-would-i-choose-sha-256-over-sha-512-for-a-ssl-tls-certificate" target="_blank"&gt;https://security.stackexchange.com/questions/165559/why-would-i-choose-sha-256-over-sha-512-for-a-ssl-tls-certificate&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://automationrhapsody.com/md5-sha-1-sha-256-sha-512-speed-performance/" target="_blank"&gt;https://automationrhapsody.com/md5-sha-1-sha-256-sha-512-speed-performance/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Nov 2019 13:28:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/need-clarification-on-recommended-authentication-algorithm/m-p/296687#M28</guid>
      <dc:creator>Sai_Tumuluri</dc:creator>
      <dc:date>2019-11-06T13:28:47Z</dc:date>
    </item>
    <item>
      <title>Re: Need clarification on recommended Authentication Algorithm</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/need-clarification-on-recommended-authentication-algorithm/m-p/296958#M31</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/74884"&gt;@BatD&lt;/a&gt;&amp;nbsp;, thats right. However, if you notice, first it says&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;Do not use SHA-512, SHA-1, or MD5. &lt;/PRE&gt;&lt;P&gt;&amp;nbsp;Then, it recommends in the order of most to least secure starting with SHA-512, implying that SHA-512 is most secure. Hence, needed clarification on that. Might be a documentation error.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Nov 2019 08:24:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/need-clarification-on-recommended-authentication-algorithm/m-p/296958#M31</guid>
      <dc:creator>devd_25</dc:creator>
      <dc:date>2019-11-07T08:24:35Z</dc:date>
    </item>
    <item>
      <title>Re: Need clarification on recommended Authentication Algorithm</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/need-clarification-on-recommended-authentication-algorithm/m-p/296959#M32</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/123486"&gt;@devd_25&lt;/a&gt;&amp;nbsp;This is correct, SHA-512 is indeed the most secure, but not recommended for reasons mentioned by&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/31227"&gt;@Sai_Tumuluri&lt;/a&gt;&amp;nbsp;- processing resources, comapability, etc.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Nov 2019 08:32:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/need-clarification-on-recommended-authentication-algorithm/m-p/296959#M32</guid>
      <dc:creator>BatD</dc:creator>
      <dc:date>2019-11-07T08:32:08Z</dc:date>
    </item>
    <item>
      <title>Re: Need clarification on recommended Authentication Algorithm</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/need-clarification-on-recommended-authentication-algorithm/m-p/297319#M34</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/123486"&gt;@devd_25&lt;/a&gt;&amp;nbsp;Please mark if you are satisfied with the solution. This closes the discussion and helps others to fastly identify the solutions&lt;/P&gt;</description>
      <pubDate>Fri, 08 Nov 2019 16:29:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/need-clarification-on-recommended-authentication-algorithm/m-p/297319#M34</guid>
      <dc:creator>Sai_Tumuluri</dc:creator>
      <dc:date>2019-11-08T16:29:43Z</dc:date>
    </item>
  </channel>
</rss>

