<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Disable ciphers in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/disable-ciphers/m-p/512189#M106439</link>
    <description>&lt;P&gt;Yes, you can use that article. I would use the following commands to achieve the best possible score on SSL Labs that you can get with a Palo Alto fw which is A-:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;configure&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;set shared ssl-tls-service-profile &amp;lt;SSL/TLS Service Profile&amp;gt; protocol-settings auth-algo-sha1 no&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;set shared ssl-tls-service-profile &amp;lt;SSL/TLS Service Profile&amp;gt; protocol-settings enc-algo-3des no&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;set shared ssl-tls-service-profile &amp;lt;SSL/TLS Service Profile&amp;gt; protocol-settings enc-algo-aes-128-cbc no&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;set shared ssl-tls-service-profile &amp;lt;SSL/TLS Service Profile&amp;gt; protocol-settings enc-algo-aes-256-cbc no&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;set shared ssl-tls-service-profile &amp;lt;SSL/TLS Service Profile&amp;gt; protocol-settings enc-algo-rc4 no&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;set shared ssl-tls-service-profile &amp;lt;SSL/TLS Service Profile&amp;gt; protocol-settings keyxchg-algo-rsa no&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;set shared ssl-tls-service-profile &amp;lt;SSL/TLS Service Profile&amp;gt; protocol-settings auth-algo-sha256 yes&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;set shared ssl-tls-service-profile &amp;lt;SSL/TLS Service Profile&amp;gt; protocol-settings auth-algo-sha384 yes&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;set shared ssl-tls-service-profile &amp;lt;SSL/TLS Service Profile&amp;gt; protocol-settings enc-algo-aes-128-gcm yes&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;set shared ssl-tls-service-profile &amp;lt;SSL/TLS Service Profile&amp;gt; protocol-settings enc-algo-aes-256-gcm yes&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;set shared ssl-tls-service-profile &amp;lt;SSL/TLS Service Profile&amp;gt; protocol-settings keyxchg-algo-dhe yes&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;commit&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/5544"&gt;@palo&lt;/a&gt; Alto: When will you fix the&amp;nbsp;Secure Renegotiation issue?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 17 Aug 2022 18:51:37 GMT</pubDate>
    <dc:creator>Han.Valk</dc:creator>
    <dc:date>2022-08-17T18:51:37Z</dc:date>
    <item>
      <title>Disable ciphers</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/disable-ciphers/m-p/511964#M106411</link>
      <description>&lt;P&gt;Hi guys,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Would like to know how to disable the following ciphers:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;TLS_DHE_RSA_WITH_AES_256_CBC_SHA&lt;BR /&gt;TLS_DHE_RSA_WITH_AES_128_CBC_SHA&lt;BR /&gt;TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA&lt;BR /&gt;TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA&lt;BR /&gt;TLS_RSA_WITH_AES_256_CBC_SHA&lt;BR /&gt;TLS_RSA_WITH_AES_128_CBC_SHA&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can i follow the following KB to disable:&lt;BR /&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CmqeCAC" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CmqeCAC&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Protocol settings is at TSLv1.0&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Or i can GUI and disable the ciphers from ssl/tls service profile ?&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also, i want to know if i need to disable SSL/TSL on panorama ?&lt;/P&gt;
&lt;P&gt;If yes, is it using the above KB mentioned?&lt;/P&gt;</description>
      <pubDate>Tue, 16 Aug 2022 08:50:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/disable-ciphers/m-p/511964#M106411</guid>
      <dc:creator>JingKai</dc:creator>
      <dc:date>2022-08-16T08:50:56Z</dc:date>
    </item>
    <item>
      <title>Re: Disable ciphers</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/disable-ciphers/m-p/512189#M106439</link>
      <description>&lt;P&gt;Yes, you can use that article. I would use the following commands to achieve the best possible score on SSL Labs that you can get with a Palo Alto fw which is A-:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;configure&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;set shared ssl-tls-service-profile &amp;lt;SSL/TLS Service Profile&amp;gt; protocol-settings auth-algo-sha1 no&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;set shared ssl-tls-service-profile &amp;lt;SSL/TLS Service Profile&amp;gt; protocol-settings enc-algo-3des no&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;set shared ssl-tls-service-profile &amp;lt;SSL/TLS Service Profile&amp;gt; protocol-settings enc-algo-aes-128-cbc no&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;set shared ssl-tls-service-profile &amp;lt;SSL/TLS Service Profile&amp;gt; protocol-settings enc-algo-aes-256-cbc no&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;set shared ssl-tls-service-profile &amp;lt;SSL/TLS Service Profile&amp;gt; protocol-settings enc-algo-rc4 no&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;set shared ssl-tls-service-profile &amp;lt;SSL/TLS Service Profile&amp;gt; protocol-settings keyxchg-algo-rsa no&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;set shared ssl-tls-service-profile &amp;lt;SSL/TLS Service Profile&amp;gt; protocol-settings auth-algo-sha256 yes&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;set shared ssl-tls-service-profile &amp;lt;SSL/TLS Service Profile&amp;gt; protocol-settings auth-algo-sha384 yes&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;set shared ssl-tls-service-profile &amp;lt;SSL/TLS Service Profile&amp;gt; protocol-settings enc-algo-aes-128-gcm yes&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;set shared ssl-tls-service-profile &amp;lt;SSL/TLS Service Profile&amp;gt; protocol-settings enc-algo-aes-256-gcm yes&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;set shared ssl-tls-service-profile &amp;lt;SSL/TLS Service Profile&amp;gt; protocol-settings keyxchg-algo-dhe yes&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;commit&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/5544"&gt;@palo&lt;/a&gt; Alto: When will you fix the&amp;nbsp;Secure Renegotiation issue?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Aug 2022 18:51:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/disable-ciphers/m-p/512189#M106439</guid>
      <dc:creator>Han.Valk</dc:creator>
      <dc:date>2022-08-17T18:51:37Z</dc:date>
    </item>
    <item>
      <title>Re: Disable ciphers</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/disable-ciphers/m-p/512217#M106441</link>
      <description>&lt;P&gt;Hi Han.Valk,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for the solution. But what about panorama?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is it&amp;nbsp;&lt;EM&gt;set panorama ssl-tls-service-profile &amp;lt;SSL/TLS Service Profile&amp;gt; protocol-settings?&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Aug 2022 04:21:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/disable-ciphers/m-p/512217#M106441</guid>
      <dc:creator>JingKai</dc:creator>
      <dc:date>2022-08-18T04:21:33Z</dc:date>
    </item>
  </channel>
</rss>

