<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to disable the use of SSL compression on HTTP-TLS interfaces on the device. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-disable-the-use-of-ssl-compression-on-http-tls-interfaces/m-p/16942#M12347</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please help me on this issue. The IT Security Audit team has scanned the PaloAlto Firewall PA-2050 and they found this vulnerability:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;*********************************************************************************************************&lt;/P&gt;&lt;P&gt;62565 (1) - TLS CRIME Vulnerability&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Synopsis:&lt;/P&gt;&lt;P&gt;The remote service has a configuration that may make it vulnerable to the CRIME attack.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Description:&lt;/P&gt;&lt;P&gt;The remote service has one of two configurations that are known to be required for the CRIME attack:&lt;/P&gt;&lt;P&gt;- SSL / TLS compression is enabled.&lt;/P&gt;&lt;P&gt;- TLS advertises the SPDY protocol earlier than version 4.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Solution:&lt;/P&gt;&lt;P&gt;Disable compression and / or the SPDY service.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Risk Factor:&lt;/P&gt;&lt;P&gt;Medium&lt;/P&gt;&lt;P&gt;*********************************************************************************************************&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;According to the document from PaloAlto "PAN-OS 5.0.3: Release Notes &amp;gt; Addressed Issues"&amp;nbsp; there is: &lt;/P&gt;&lt;P&gt;47813 -- Made a change to disable the use of SSL compression on HTTP-TLS interfaces on the device. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, How can we disable this SSL compression?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Aniz&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 03 Dec 2013 13:47:11 GMT</pubDate>
    <dc:creator>aniz.mohammed@futuretec.com.kw</dc:creator>
    <dc:date>2013-12-03T13:47:11Z</dc:date>
    <item>
      <title>How to disable the use of SSL compression on HTTP-TLS interfaces on the device.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-disable-the-use-of-ssl-compression-on-http-tls-interfaces/m-p/16942#M12347</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please help me on this issue. The IT Security Audit team has scanned the PaloAlto Firewall PA-2050 and they found this vulnerability:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;*********************************************************************************************************&lt;/P&gt;&lt;P&gt;62565 (1) - TLS CRIME Vulnerability&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Synopsis:&lt;/P&gt;&lt;P&gt;The remote service has a configuration that may make it vulnerable to the CRIME attack.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Description:&lt;/P&gt;&lt;P&gt;The remote service has one of two configurations that are known to be required for the CRIME attack:&lt;/P&gt;&lt;P&gt;- SSL / TLS compression is enabled.&lt;/P&gt;&lt;P&gt;- TLS advertises the SPDY protocol earlier than version 4.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Solution:&lt;/P&gt;&lt;P&gt;Disable compression and / or the SPDY service.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Risk Factor:&lt;/P&gt;&lt;P&gt;Medium&lt;/P&gt;&lt;P&gt;*********************************************************************************************************&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;According to the document from PaloAlto "PAN-OS 5.0.3: Release Notes &amp;gt; Addressed Issues"&amp;nbsp; there is: &lt;/P&gt;&lt;P&gt;47813 -- Made a change to disable the use of SSL compression on HTTP-TLS interfaces on the device. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, How can we disable this SSL compression?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Aniz&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Dec 2013 13:47:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-disable-the-use-of-ssl-compression-on-http-tls-interfaces/m-p/16942#M12347</guid>
      <dc:creator>aniz.mohammed@futuretec.com.kw</dc:creator>
      <dc:date>2013-12-03T13:47:11Z</dc:date>
    </item>
    <item>
      <title>Re: How to disable the use of SSL compression on HTTP-TLS interfaces on the device.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-disable-the-use-of-ssl-compression-on-http-tls-interfaces/m-p/16943#M12348</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Aniz,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SPDY feature can be disabled in Chrome's browser properties.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please refer the following document:&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-3496"&gt;Chrome Version 21 Unable to Make SSL Connections to google.com Destinations&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if that helps you!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks and regards,&lt;BR /&gt;Kunal Adak&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Dec 2013 01:09:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-disable-the-use-of-ssl-compression-on-http-tls-interfaces/m-p/16943#M12348</guid>
      <dc:creator>kadak</dc:creator>
      <dc:date>2013-12-04T01:09:25Z</dc:date>
    </item>
  </channel>
</rss>

