<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Wildcard SSL in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/wildcard-ssl/m-p/21087#M15391</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;for the whitelist, I ended up just adding the url *.domain.com to allow connections to wildcarded SSL hosts to work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, I think PAN should work on a better method of identifying the actual URL, rather than the listing the wildcard SSL in the logs.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 23 Jan 2011 00:05:41 GMT</pubDate>
    <dc:creator>camkim_MDEA</dc:creator>
    <dc:date>2011-01-23T00:05:41Z</dc:date>
    <item>
      <title>Wildcard SSL</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildcard-ssl/m-p/21086#M15390</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So we have a couple hosts where we use a Wildcard SSL and I noticed that in our URL filtering, it shows up as *.domain.com (application SSL) rather than service1.domain.com and service2.domain.com&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've been trying to troubleshoot an issue where we use a whitelist for a certain business unit and we have service1.domain.com listed in the access URL list, but they keep getting dropped. Is the short term solution just to add *.domain.com to get around this issue?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Long term, I would think there has to be a differen solution, considering how prevalent Wildcard SSL cert are today.Just our organization alone, we probably will have 20 hosts, all using the same certificate. We need to be able to identify the traffic by the correct URL.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Jan 2011 16:35:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildcard-ssl/m-p/21086#M15390</guid>
      <dc:creator>camkim_MDEA</dc:creator>
      <dc:date>2011-01-19T16:35:06Z</dc:date>
    </item>
    <item>
      <title>Re: Wildcard SSL</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildcard-ssl/m-p/21087#M15391</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;for the whitelist, I ended up just adding the url *.domain.com to allow connections to wildcarded SSL hosts to work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, I think PAN should work on a better method of identifying the actual URL, rather than the listing the wildcard SSL in the logs.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 23 Jan 2011 00:05:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildcard-ssl/m-p/21087#M15391</guid>
      <dc:creator>camkim_MDEA</dc:creator>
      <dc:date>2011-01-23T00:05:41Z</dc:date>
    </item>
  </channel>
</rss>

