<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: issue with SSL decrypt-forward proxy in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-ssl-decrypt-forward-proxy/m-p/16408#M11977</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How is configured you decryption policy ?&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If you access for exemple to &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.birdres.com" rel="nofollow"&gt;http://www.birdres.com&lt;/A&gt;&lt;SPAN&gt;, decryption should have no impact on it because it's http and not ssl.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;which PA model ? wich version ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please read: &lt;A href="https://live.paloaltonetworks.com/docs/DOC-1412"&gt;How to Implement SSL Decryption&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope help&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;V.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 05 Jun 2014 15:20:55 GMT</pubDate>
    <dc:creator>VinceM</dc:creator>
    <dc:date>2014-06-05T15:20:55Z</dc:date>
    <item>
      <title>issue with SSL decrypt-forward proxy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-ssl-decrypt-forward-proxy/m-p/16407#M11976</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Customer Network configured with SSL decrypt-forward proxy. Now t&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;hey can't able to browse more sites (eg:birdres.com, sap.snn,etc). &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;They were not satisfied with exclude ssl decrypt. (due to more no.of sites in exclude list). Is there any other way?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Jun 2014 08:22:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-with-ssl-decrypt-forward-proxy/m-p/16407#M11976</guid>
      <dc:creator>Javith</dc:creator>
      <dc:date>2014-06-05T08:22:01Z</dc:date>
    </item>
    <item>
      <title>Re: issue with SSL decrypt-forward proxy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-ssl-decrypt-forward-proxy/m-p/16408#M11977</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How is configured you decryption policy ?&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If you access for exemple to &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.birdres.com" rel="nofollow"&gt;http://www.birdres.com&lt;/A&gt;&lt;SPAN&gt;, decryption should have no impact on it because it's http and not ssl.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;which PA model ? wich version ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please read: &lt;A href="https://live.paloaltonetworks.com/docs/DOC-1412"&gt;How to Implement SSL Decryption&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope help&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;V.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Jun 2014 15:20:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-with-ssl-decrypt-forward-proxy/m-p/16408#M11977</guid>
      <dc:creator>VinceM</dc:creator>
      <dc:date>2014-06-05T15:20:55Z</dc:date>
    </item>
    <item>
      <title>Re: issue with SSL decrypt-forward proxy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-ssl-decrypt-forward-proxy/m-p/16409#M11978</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Javith,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you please verify the URL's, which is not working as expected with below mentioned list. &lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;There are few applications that do not play well when decryption is turned on, on the PA firewall.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Here is a document with a list of the applications we've already identified that should be excluded from decryption:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-1423"&gt;List of Applications Excluded from SSL Decryption&lt;/A&gt;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;Reference doc: &lt;A href="https://live.paloaltonetworks.com/docs/DOC-1241"&gt;How to Exclude a Single URL from SSL Decryption&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Jun 2014 15:39:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-with-ssl-decrypt-forward-proxy/m-p/16409#M11978</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-06-05T15:39:45Z</dc:date>
    </item>
    <item>
      <title>Re: issue with SSL decrypt-forward proxy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-ssl-decrypt-forward-proxy/m-p/16410#M11979</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Hulk,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When browsing &lt;A class="jive-link-external-small" href="http://www.birdres.com/" rel="nofollow" style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #006595;"&gt;http://www.birdres.com &lt;/A&gt;(and 70 other sites ) they got the certification error message in browser. Customer don't want to configure exclude-list for those 70sites-not related to ur exclude rule (which will keep on increasing). If they proceed with the certification error msg then webpage loaded and displayed. then again got cert error within a second.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Jun 2014 16:35:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-with-ssl-decrypt-forward-proxy/m-p/16410#M11979</guid>
      <dc:creator>Javith</dc:creator>
      <dc:date>2014-06-05T16:35:16Z</dc:date>
    </item>
    <item>
      <title>Re: issue with SSL decrypt-forward proxy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-ssl-decrypt-forward-proxy/m-p/16411#M11980</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This may be relevant:&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-6866"&gt;SSL Decryption for Some Site Shows as Not Trusted&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I checked &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://www.birdres.com" rel="nofollow"&gt;https://www.birdres.com&lt;/A&gt;&lt;SPAN&gt; (rather than &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://" rel="nofollow"&gt;http://&lt;/A&gt;&lt;SPAN&gt;) and found that it does not use the GoDaddy intermediate CA referenced in the above article, but it's possible that the "Verisign Class 3 International Server CA - G3" intermediate CA is in the same boat as the article I provided.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try grabbing that Verisign intermediate CA and installing it as a trusted root on the firewall that is doing the decryption.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps,&lt;/P&gt;&lt;P&gt;Greg&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Jun 2014 16:52:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-with-ssl-decrypt-forward-proxy/m-p/16411#M11980</guid>
      <dc:creator>gwesson</dc:creator>
      <dc:date>2014-06-05T16:52:23Z</dc:date>
    </item>
    <item>
      <title>Re: issue with SSL decrypt-forward proxy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-ssl-decrypt-forward-proxy/m-p/16412#M11981</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can i copy the same root CA (which is in the article) and load into the firewall ?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Jun 2014 17:28:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-with-ssl-decrypt-forward-proxy/m-p/16412#M11981</guid>
      <dc:creator>Javith</dc:creator>
      <dc:date>2014-06-05T17:28:49Z</dc:date>
    </item>
    <item>
      <title>Re: issue with SSL decrypt-forward proxy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-ssl-decrypt-forward-proxy/m-p/16413#M11982</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The one in the article is not a root, but rather an Intermediate CA. It's for GoDaddy, and you're welcome to install it (I recommend doing so in fact). It won't help you if the Verisign cert I talked about is missing, because Verisign is not GoDaddy so you'd need to get the Verisign cert separately.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My recommendation is to try the steps in the article, and see if the number of sites you have issues with is reduced at all. If not, then the issue discussed in the article may not be what you are affected with.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best,&lt;/P&gt;&lt;P&gt;Greg&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Jun 2014 17:52:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-with-ssl-decrypt-forward-proxy/m-p/16413#M11982</guid>
      <dc:creator>gwesson</dc:creator>
      <dc:date>2014-06-05T17:52:08Z</dc:date>
    </item>
    <item>
      <title>Re: issue with SSL decrypt-forward proxy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-ssl-decrypt-forward-proxy/m-p/16414#M11983</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I loaded the CA as per gwesson recommendation. But two of these sites(will keep increasing) remains with cert error.&lt;/P&gt;&lt;P&gt;I see the certificates of these two sites(scn.sap.com/welcome and birdres.com) - both doesn't have public audit records and not trusted.&lt;/P&gt;&lt;P&gt;one site with verisign and other site with geo trust cert..Anybody please suggest.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Jun 2014 06:18:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-with-ssl-decrypt-forward-proxy/m-p/16414#M11983</guid>
      <dc:creator>Javith</dc:creator>
      <dc:date>2014-06-06T06:18:24Z</dc:date>
    </item>
    <item>
      <title>Re: issue with SSL decrypt-forward proxy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-ssl-decrypt-forward-proxy/m-p/16415#M11984</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank You for your replies.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I opened a TAC case for this issue.&lt;/P&gt;&lt;P&gt;TAC engineer said these two sites requiring the client side authentication. He also demonstrates it using HTTP Watch( HTTP debugger).&lt;/P&gt;&lt;P&gt;So this two sites also in SSL-decrypt exclude list for PAN FW. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Jun 2014 10:18:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-with-ssl-decrypt-forward-proxy/m-p/16415#M11984</guid>
      <dc:creator>Javith</dc:creator>
      <dc:date>2014-06-11T10:18:28Z</dc:date>
    </item>
  </channel>
</rss>

