<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSL decryption for public use ? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-for-public-use/m-p/17872#M13006</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi ialeksov,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; It's not possible to purchase a Trust Root CA. What you can buy is a server type certificate, with a specific hostname.&lt;/P&gt;&lt;P&gt;If it was so easy, you can easily imagine the world would not be secure anyomore....&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 02 Sep 2014 22:58:05 GMT</pubDate>
    <dc:creator>cpainchaud</dc:creator>
    <dc:date>2014-09-02T22:58:05Z</dc:date>
    <item>
      <title>SSL decryption for public use ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-for-public-use/m-p/17867#M13001</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We provide internet access for public use (wifi hotspot). For better control and visibility, I would like to introduce SSL decryption (we already use it for our internal users). But there is no way I can deploy the certificate to those users (who I don't know and don't control their devices).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there any way I can enhance control and visibility of web applications in another way ? "Transparent" SSL decryption ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 29 Aug 2014 07:51:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-for-public-use/m-p/17867#M13001</guid>
      <dc:creator>dieter_b</dc:creator>
      <dc:date>2014-08-29T07:51:18Z</dc:date>
    </item>
    <item>
      <title>Re: SSL decryption for public use ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-for-public-use/m-p/17868#M13002</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Dieterb,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Even if, you will not deploy that certificate to &lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;wifi&lt;/SPAN&gt; hotspot users, the traffic will be decrypted. But, every time they will get a certificate warning, while access any SSL page. Since the self generated certificate is issued by PAN firewall and it is not in the browser's certificate ring. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A related discussion thread on same topic: &lt;A href="https://live.paloaltonetworks.com/message/41346"&gt;Decryption certificate&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 29 Aug 2014 08:37:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-for-public-use/m-p/17868#M13002</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-08-29T08:37:55Z</dc:date>
    </item>
    <item>
      <title>Re: SSL decryption for public use ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-for-public-use/m-p/17869#M13003</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I know, but I think it's not done to confront users with constant certificate errors.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I know about the ssl decryption opt-out response page. I could warn the users about this. But I think that is a global option, so it would also appear to our internal users (which is not necessary).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What do others do with public internet traffic passing their PA?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 29 Aug 2014 08:45:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-for-public-use/m-p/17869#M13003</guid>
      <dc:creator>dieter_b</dc:creator>
      <dc:date>2014-08-29T08:45:01Z</dc:date>
    </item>
    <item>
      <title>Re: SSL decryption for public use ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-for-public-use/m-p/17870#M13004</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, you are correct. &lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;opt&lt;/SPAN&gt;-out response page is a global setting, hence it will be applicable &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;for&lt;/SPAN&gt; your internal user's as well.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-5020"&gt;How to Enable/Reset the Opt-Out Page for SSL Decryption&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 29 Aug 2014 08:51:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-for-public-use/m-p/17870#M13004</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-08-29T08:51:50Z</dc:date>
    </item>
    <item>
      <title>Re: SSL decryption for public use ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-for-public-use/m-p/17871#M13005</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi dieterb,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The only way that you might be able to accomplish this is to use a decrypt certificate that is issued by a trusted root CA.&lt;/P&gt;&lt;P&gt;This is the only option since you do not have the ability to push the cert yourself to the devices, since you do not control them.&lt;/P&gt;&lt;P&gt;Using an untrusted certificate looks bad and will prompt the users every time they visit a site to accept the "risk" since their traffic is being "men in the middled" by a device that was cert from an unknown CA.&lt;/P&gt;&lt;P&gt;You can pay a couple of 100$ and get a cert and have no worries about this at all. Most of the customer I have seen prefer this solution.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope this helps you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BR&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Sep 2014 22:33:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-for-public-use/m-p/17871#M13005</guid>
      <dc:creator>ialeksov</dc:creator>
      <dc:date>2014-09-02T22:33:30Z</dc:date>
    </item>
    <item>
      <title>Re: SSL decryption for public use ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-for-public-use/m-p/17872#M13006</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi ialeksov,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; It's not possible to purchase a Trust Root CA. What you can buy is a server type certificate, with a specific hostname.&lt;/P&gt;&lt;P&gt;If it was so easy, you can easily imagine the world would not be secure anyomore....&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Sep 2014 22:58:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-for-public-use/m-p/17872#M13006</guid>
      <dc:creator>cpainchaud</dc:creator>
      <dc:date>2014-09-02T22:58:05Z</dc:date>
    </item>
  </channel>
</rss>

