<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic how to work decryption policy? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-work-decryption-policy/m-p/1316#M1015</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;STRONG&gt;Hi.. all,&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;how are you today ? any one please describe about decryption policy and how log bits (0-2048) support? &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt; &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt; :smileyinfo:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Thanks &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Satish &lt;/STRONG&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 19 May 2014 04:23:52 GMT</pubDate>
    <dc:creator>Satish</dc:creator>
    <dc:date>2014-05-19T04:23:52Z</dc:date>
    <item>
      <title>how to work decryption policy?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-work-decryption-policy/m-p/1316#M1015</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;STRONG&gt;Hi.. all,&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;how are you today ? any one please describe about decryption policy and how log bits (0-2048) support? &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt; &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt; :smileyinfo:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Thanks &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Satish &lt;/STRONG&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 May 2014 04:23:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-work-decryption-policy/m-p/1316#M1015</guid>
      <dc:creator>Satish</dc:creator>
      <dc:date>2014-05-19T04:23:52Z</dc:date>
    </item>
    <item>
      <title>Re: how to work decryption policy?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-work-decryption-policy/m-p/1317#M1016</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The basic overview for ssl decryption is doc-2008.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-2008"&gt;Controlling SSL Decryption&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PA does support 2048 bit certs.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 May 2014 16:19:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-work-decryption-policy/m-p/1317#M1016</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2014-05-19T16:19:00Z</dc:date>
    </item>
    <item>
      <title>Re: how to work decryption policy?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-work-decryption-policy/m-p/1318#M1017</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear Steven,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thnx for you reply.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 May 2014 18:09:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-work-decryption-policy/m-p/1318#M1017</guid>
      <dc:creator>Satish</dc:creator>
      <dc:date>2014-05-19T18:09:34Z</dc:date>
    </item>
    <item>
      <title>Re: how to work decryption policy?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-work-decryption-policy/m-p/1319#M1018</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Following doc explains on different Decryption Certs&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-2006"&gt;SSL Decryption Certificates&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Numan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 May 2014 13:48:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-work-decryption-policy/m-p/1319#M1018</guid>
      <dc:creator>mbutt</dc:creator>
      <dc:date>2014-05-20T13:48:42Z</dc:date>
    </item>
    <item>
      <title>Re: how to work decryption policy?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-work-decryption-policy/m-p/1320#M1019</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;Dear Steven,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;I have a question after have read your comment.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;We use a self-generated certificate with 2048 bits from FW for ssl outbound decryption.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;But we always see 1024 bits certificate when connecting to facebook.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;2048 bits certificate can be generated by FW-self, but can not use to decryption. because FW does not support. Right?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;Thanks and Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;KC Lee&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Sep 2014 17:40:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-work-decryption-policy/m-p/1320#M1019</guid>
      <dc:creator>KiCheon.Lee</dc:creator>
      <dc:date>2014-09-22T17:40:27Z</dc:date>
    </item>
    <item>
      <title>Re: how to work decryption policy?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-work-decryption-policy/m-p/1321#M1020</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi KC Lee,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For outbound SSL decryption, 1024 bit key is used between PA and clients connection regardless of the key length of PA generated CA certificate, or key length of real server presents. This is by design. Hope that helps. Thank you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Sep 2014 19:30:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-work-decryption-policy/m-p/1321#M1020</guid>
      <dc:creator>ssharma</dc:creator>
      <dc:date>2014-09-22T19:30:01Z</dc:date>
    </item>
    <item>
      <title>Re: how to work decryption policy?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-work-decryption-policy/m-p/1322#M1021</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Satish,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Decryption is firewall acting as man in the middle. Firewall will intercept ssl connection from end clients to server, send a response back to client appearing as server with certificates and start a new connection from firewall's external interface to the server to get requested data.&amp;nbsp; That way we have 2 portion of connection one that originates at clients and ends at the firewall's internal interface and other that originates at external interface and ends at the server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Firewall will manage these 2 communication for each ssl communication.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For outbound SSL decryption, 1024 bit key is used between PA and clients connection regardless of the key length of PA generated CA certificate, or key length of real server presents. This is by design. Hope that helps. Thank you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Sep 2014 19:33:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-work-decryption-policy/m-p/1322#M1021</guid>
      <dc:creator>ssharma</dc:creator>
      <dc:date>2014-09-22T19:33:26Z</dc:date>
    </item>
    <item>
      <title>Re: how to work decryption policy?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-work-decryption-policy/m-p/1323#M1022</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi ssharma,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank your very much for your answer.&lt;/P&gt;&lt;P&gt;It helps me so clear.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;KC Lee&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Sep 2014 02:49:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-work-decryption-policy/m-p/1323#M1022</guid>
      <dc:creator>KiCheon.Lee</dc:creator>
      <dc:date>2014-09-23T02:49:35Z</dc:date>
    </item>
  </channel>
</rss>

