<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSL decryption fails in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-fails/m-p/17368#M12678</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It failed on our end as well, although we decrypted the traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="7725" alt="posteo.JPG" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/7725_posteo.JPG" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="posteo-2.JPG" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/7730_posteo-2.JPG" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="posteo-3.JPG" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/7731_posteo-3.JPG" width="450" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 15 Aug 2013 15:59:53 GMT</pubDate>
    <dc:creator>kprakash</dc:creator>
    <dc:date>2013-08-15T15:59:53Z</dc:date>
    <item>
      <title>SSL decryption fails</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-fails/m-p/17363#M12673</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We are testing SSL decryption on our PA at the moment. We have found a site that could not be decrypted: &lt;A class="active_link" href="https://posteo.de/" title="https://posteo.de/"&gt;https://posteo.de/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Has anyone of you an idea why the decryption fails for that site?&lt;/P&gt;&lt;P&gt;And how could I troubleshoot such problems? Because the normal log does not show any problem, but the browser shows an error message.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Aug 2013 13:37:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-fails/m-p/17363#M12673</guid>
      <dc:creator>montgomery</dc:creator>
      <dc:date>2013-08-15T13:37:52Z</dc:date>
    </item>
    <item>
      <title>Re: SSL decryption fails</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-fails/m-p/17364#M12674</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Good Morning,&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I just checked the certificate for &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://posteo.de/"&gt;https://posteo.de/&lt;/A&gt;&lt;SPAN&gt; and it is signed by StartCom. It also has an intermediate certificate as shown.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Startcom.JPG" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/7718_Startcom.JPG" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you verify if Startcom is part of the Default Trusted Certificate Authorities?&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Startcom.JPG" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/7719_Startcom.JPG" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you being presented with a forward Untrust Certificate? Also are we "Blocking sessions with untrusted issuers" ?&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Startcom.JPG" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/7720_Startcom.JPG" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BR,&lt;/P&gt;&lt;P&gt;Karthik &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Aug 2013 14:04:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-fails/m-p/17364#M12674</guid>
      <dc:creator>kprakash</dc:creator>
      <dc:date>2013-08-15T14:04:50Z</dc:date>
    </item>
    <item>
      <title>Re: SSL decryption fails</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-fails/m-p/17365#M12675</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Karthik,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;Can you verify if Startcom is part of the Default Trusted Certificate Authorities?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;- Yes it is part of the default trusted certificate authorities&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 12px; background-color: #ffffff; font-family: Arial, Helvetica, sans-serif;"&gt;Are you being presented with a forward Untrust Certificate?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 12px; background-color: #ffffff; font-family: Arial, Helvetica, sans-serif;"&gt;- No certificate is shown. IE just shows "This page cannot be displayed"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 12px; background-color: #ffffff; font-family: Arial, Helvetica, sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 12px; background-color: #ffffff; font-family: Arial, Helvetica, sans-serif;"&gt;Also are we "Blocking sessions with untrusted issuers" ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 12px; background-color: #ffffff; font-family: Arial, Helvetica, sans-serif;"&gt;- No.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 12px; background-color: #ffffff; font-family: Arial, Helvetica, sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 12px; background-color: #ffffff; font-family: Arial, Helvetica, sans-serif;"&gt;Thanks!&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 12px; background-color: #ffffff; font-family: Arial, Helvetica, sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Aug 2013 14:45:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-fails/m-p/17365#M12675</guid>
      <dc:creator>hag</dc:creator>
      <dc:date>2013-08-15T14:45:00Z</dc:date>
    </item>
    <item>
      <title>Re: SSL decryption fails</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-fails/m-p/17366#M12676</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;From what you have stated, it looks like we are either not seeing the entire TCP handshake completing for the SSL traffic, or there are some parameters on the Server Certificate that the PANFW doesnt like. If you set the action to No-Decrypt under the Decryption profile, does the webpage load?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Karthik RP&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Aug 2013 15:22:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-fails/m-p/17366#M12676</guid>
      <dc:creator>kprakash</dc:creator>
      <dc:date>2013-08-15T15:22:30Z</dc:date>
    </item>
    <item>
      <title>Re: SSL decryption fails</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-fails/m-p/17367#M12677</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes when we do no decrypt the page is loading as expected.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Aug 2013 15:35:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-fails/m-p/17367#M12677</guid>
      <dc:creator>hag</dc:creator>
      <dc:date>2013-08-15T15:35:52Z</dc:date>
    </item>
    <item>
      <title>Re: SSL decryption fails</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-fails/m-p/17368#M12678</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It failed on our end as well, although we decrypted the traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="7725" alt="posteo.JPG" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/7725_posteo.JPG" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="posteo-2.JPG" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/7730_posteo-2.JPG" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="posteo-3.JPG" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/7731_posteo-3.JPG" width="450" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Aug 2013 15:59:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-fails/m-p/17368#M12678</guid>
      <dc:creator>kprakash</dc:creator>
      <dc:date>2013-08-15T15:59:53Z</dc:date>
    </item>
  </channel>
</rss>

