<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Secure Renegotiation in PANOS 9x? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/secure-renegotiation-in-panos-9x/m-p/523599#M108406</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/162723"&gt;@Ghidini&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There are actually 2 existing FRs for this feature:&lt;/P&gt;
&lt;P data-unlink="true"&gt;&lt;SPAN class="news-body-text"&gt;&lt;SPAN&gt;&lt;STRONG&gt;FR ID:&lt;/STRONG&gt; 8112 (support for secure renegotiation / inbound SSL decrypt and GlobalProtect&amp;nbsp;)&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P data-unlink="true"&gt;&lt;SPAN class="news-body-text"&gt;&lt;SPAN&gt;&lt;STRONG&gt;FR ID:&lt;/STRONG&gt; 18516 (Support for RFC 5746&amp;nbsp;)&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P data-unlink="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-unlink="true"&gt;&lt;SPAN class="news-body-text"&gt;&lt;SPAN&gt;Please reach out to your local SE and you can have your vote added to them.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P data-unlink="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-unlink="true"&gt;&lt;SPAN class="news-body-text"&gt;&lt;SPAN&gt;Kind regards,&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P data-unlink="true"&gt;&lt;SPAN class="news-body-text"&gt;&lt;SPAN&gt;-Kiwi.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV id="ConnectiveDocSignExtentionInstalled" data-extension-version="1.0.4"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
    <pubDate>Thu, 08 Dec 2022 07:32:11 GMT</pubDate>
    <dc:creator>kiwi</dc:creator>
    <dc:date>2022-12-08T07:32:11Z</dc:date>
    <item>
      <title>Secure Renegotiation in PANOS 9x?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/secure-renegotiation-in-panos-9x/m-p/256219#M72690</link>
      <description>&lt;P&gt;I'm seeing some posts stating that Secure Renegotiation is not supported on the Palo Alto platform. Is this still true for the latest release, v9.x? If so, how is it enabled?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Apr 2019 23:31:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/secure-renegotiation-in-panos-9x/m-p/256219#M72690</guid>
      <dc:creator>richardhicks</dc:creator>
      <dc:date>2019-04-04T23:31:30Z</dc:date>
    </item>
    <item>
      <title>Re: Secure Renegotiation in PANOS 9x?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/secure-renegotiation-in-panos-9x/m-p/256377#M72735</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/110304"&gt;@richardhicks&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I'm fairly certain that TLS Renegotiation was fixed in an update to 6.0, so it's been available for a while. Regardless renegotiation is dying anyways; TLS 1.3 removes it completely.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Apr 2019 19:58:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/secure-renegotiation-in-panos-9x/m-p/256377#M72735</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-04-05T19:58:56Z</dc:date>
    </item>
    <item>
      <title>Re: Secure Renegotiation in PANOS 9x?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/secure-renegotiation-in-panos-9x/m-p/256382#M72739</link>
      <description>&lt;P&gt;Good to hear. So how to enable it? I'm certainly glad that TLS 1.3 eliminates it, but my customer has TLS 1.2 at the moment and need to elminate this audit finding. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Apr 2019 20:43:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/secure-renegotiation-in-panos-9x/m-p/256382#M72739</guid>
      <dc:creator>richardhicks</dc:creator>
      <dc:date>2019-04-05T20:43:11Z</dc:date>
    </item>
    <item>
      <title>Re: Secure Renegotiation in PANOS 9x?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/secure-renegotiation-in-panos-9x/m-p/256449#M72751</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/110304"&gt;@richardhicks&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;At least on a global protect portal website secure renegotiation is still not supported ... so I assume this also applies to inbound decryption.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What do you think when TLS1.3 support will be added? I would saysomewhere in 2021 &lt;span class="lia-unicode-emoji" title=":face_with_tongue:"&gt;😛&lt;/span&gt; (with PAN-OS 10?)&lt;/P&gt;</description>
      <pubDate>Sun, 07 Apr 2019 11:26:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/secure-renegotiation-in-panos-9x/m-p/256449#M72751</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2019-04-07T11:26:47Z</dc:date>
    </item>
    <item>
      <title>Re: Secure Renegotiation in PANOS 9x?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/secure-renegotiation-in-panos-9x/m-p/256480#M72764</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Last I heard it was still being targeted for 9.1**, but it wouldn't suprise me at all of this got pushed back to 10*. There's some really interesting papers you can find that speak in detail about the additional issues with TLS 1.3 and attempting to intercept that communication in a passive format.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;*version names referenced are simply picked from historical release information. &lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;**Inside Baseball (IE: Roadmap) discussions are strictly confidential and enforced through an NDA. The information presented in this post is non-official information and was not directly supplied by Palo Alto Networks or its employees.&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 07 Apr 2019 01:21:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/secure-renegotiation-in-panos-9x/m-p/256480#M72764</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-04-07T01:21:28Z</dc:date>
    </item>
    <item>
      <title>Re: Secure Renegotiation in PANOS 9x?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/secure-renegotiation-in-panos-9x/m-p/443370#M100208</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/110304"&gt;@richardhicks&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are there any current versions of PAN-OS that support secure renegotiation?&lt;BR /&gt;Inbound decryption SERVER-INITIATED Secure Renegotiation IS NOT supported.&lt;BR /&gt;Secure Renegotiatio----&amp;gt;Not supported ACTION NEEDED (more info)&lt;BR /&gt;Secure Client-Initiated Renegotiation---- &amp;gt;No&lt;/P&gt;&lt;P&gt;From palo alto side can to possible to configure&amp;nbsp;support secure renegotiation&lt;/P&gt;&lt;P&gt;if it is&amp;nbsp; feature request then can you please provide me FR number&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Oct 2021 07:12:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/secure-renegotiation-in-panos-9x/m-p/443370#M100208</guid>
      <dc:creator>bit_byte</dc:creator>
      <dc:date>2021-10-26T07:12:28Z</dc:date>
    </item>
    <item>
      <title>Re: Secure Renegotiation in PANOS 9x?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/secure-renegotiation-in-panos-9x/m-p/523469#M108399</link>
      <description>&lt;P&gt;Is finally secure renegotiation (in inbound decryption) supported in the 10.1 or 11.0 firmware?&lt;/P&gt;
&lt;P&gt;It seems is a feature that has been missing for too long.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 07 Dec 2022 10:38:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/secure-renegotiation-in-panos-9x/m-p/523469#M108399</guid>
      <dc:creator>Ghidini</dc:creator>
      <dc:date>2022-12-07T10:38:47Z</dc:date>
    </item>
    <item>
      <title>Re: Secure Renegotiation in PANOS 9x?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/secure-renegotiation-in-panos-9x/m-p/523599#M108406</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/162723"&gt;@Ghidini&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There are actually 2 existing FRs for this feature:&lt;/P&gt;
&lt;P data-unlink="true"&gt;&lt;SPAN class="news-body-text"&gt;&lt;SPAN&gt;&lt;STRONG&gt;FR ID:&lt;/STRONG&gt; 8112 (support for secure renegotiation / inbound SSL decrypt and GlobalProtect&amp;nbsp;)&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P data-unlink="true"&gt;&lt;SPAN class="news-body-text"&gt;&lt;SPAN&gt;&lt;STRONG&gt;FR ID:&lt;/STRONG&gt; 18516 (Support for RFC 5746&amp;nbsp;)&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P data-unlink="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-unlink="true"&gt;&lt;SPAN class="news-body-text"&gt;&lt;SPAN&gt;Please reach out to your local SE and you can have your vote added to them.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P data-unlink="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-unlink="true"&gt;&lt;SPAN class="news-body-text"&gt;&lt;SPAN&gt;Kind regards,&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P data-unlink="true"&gt;&lt;SPAN class="news-body-text"&gt;&lt;SPAN&gt;-Kiwi.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV id="ConnectiveDocSignExtentionInstalled" data-extension-version="1.0.4"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Thu, 08 Dec 2022 07:32:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/secure-renegotiation-in-panos-9x/m-p/523599#M108406</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2022-12-08T07:32:11Z</dc:date>
    </item>
    <item>
      <title>Re: Secure Renegotiation in PANOS 9x?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/secure-renegotiation-in-panos-9x/m-p/554375#M112662</link>
      <description>&lt;P&gt;10.2.5 and SSLLabs result for GlobalProtect portal went from A- to A+&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":party_popper:"&gt;🎉&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;It requires removing weak ciphers from CLI though.&lt;/P&gt;</description>
      <pubDate>Sat, 19 Aug 2023 21:16:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/secure-renegotiation-in-panos-9x/m-p/554375#M112662</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-08-19T21:16:52Z</dc:date>
    </item>
    <item>
      <title>Re: Secure Renegotiation in PANOS 9x?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/secure-renegotiation-in-panos-9x/m-p/558746#M113335</link>
      <description>&lt;P&gt;Thank you,&lt;/P&gt;
&lt;P&gt;currently we are on 10.1.10 release.&lt;/P&gt;
&lt;P&gt;So, to obtain an A+ we must upgrade exactly to 10.2.5 release or we need only to remove weak ciphers by CLI?&lt;/P&gt;
&lt;P&gt;Which is the real solution?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for your support,&lt;/P&gt;
&lt;P&gt;Daniel&lt;/P&gt;</description>
      <pubDate>Wed, 20 Sep 2023 09:54:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/secure-renegotiation-in-panos-9x/m-p/558746#M113335</guid>
      <dc:creator>Ghidini</dc:creator>
      <dc:date>2023-09-20T09:54:29Z</dc:date>
    </item>
    <item>
      <title>Re: Secure Renegotiation in PANOS 9x?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/secure-renegotiation-in-panos-9x/m-p/558778#M113341</link>
      <description>&lt;P&gt;You need to upgrade PANOS. Removing weak ciphers gives only A-&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To get A+ you need to upgrade to PANOS that supports&amp;nbsp;&lt;SPAN&gt;renegotiation.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;10.2.5&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;PAN-184630 -&amp;nbsp;Fixed an issue where TLS clients, such as those using OpenSSL 3.0, enforced the TLS renegotiation extension (RFC 5746).&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-release-notes/pan-os-10-2-5-known-and-addressed-issues/pan-os-10-2-5-addressed-issues" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-release-notes/pan-os-10-2-5-known-and-addressed-issues/pan-os-10-2-5-addressed-issues&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;You need to review 10.1.x release notes to see if renegotiation is fixed in any of it's versions.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Sep 2023 12:31:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/secure-renegotiation-in-panos-9x/m-p/558778#M113341</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-09-20T12:31:47Z</dc:date>
    </item>
  </channel>
</rss>

