<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Unable to download updates PAN OS 4.1.9 because of self signed certificate on updates.paloaltonetworks.com ? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-download-updates-pan-os-4-1-9-because-of-self-signed/m-p/21676#M15835</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The certificate verification messages should not cause an issue with connecting to the update server.&amp;nbsp; We recently moved to using CDN for the actual content downloads.&amp;nbsp; You should modify your policies controlling outbound traffic to downloads.paloaltonetworks.com in addition to updates.paloaltonetworks.com.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are working on updating the paloalto-updates application signature to include all update related services.&amp;nbsp; No ETA at this point but it is actively being worked on.&amp;nbsp; Once that signature is current you can just allow that application to any destination in your security policies.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you continue to have issues downloading I would suggest opening a support ticket so we can investigate further.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;-- Kevin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 19 Dec 2012 15:59:17 GMT</pubDate>
    <dc:creator>kfindlen</dc:creator>
    <dc:date>2012-12-19T15:59:17Z</dc:date>
    <item>
      <title>Unable to download updates PAN OS 4.1.9 because of self signed certificate on updates.paloaltonetworks.com ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-download-updates-pan-os-4-1-9-because-of-self-signed/m-p/21675#M15834</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Since november we have not received any content updates from updates.paloaltonetworks.com. We changed the rules so every update server (including amazonws.com) was allowed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now the updates start, I see a succesful connection to updates.paloaltonetworks.com, but the job remains in download state at 0%.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I check the ms.log it shows:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;--2012-12-19 14:04:56--&amp;nbsp; &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://updates.paloaltonetworks.com/Updates/UpdateService.asmx/CheckForSignatureUpdate"&gt;https://updates.paloaltonetworks.com/Updates/UpdateService.asmx/CheckForSignatureUpdate&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Resolving updates.paloaltonetworks.com... 199.167.52.13&lt;/P&gt;&lt;P&gt;Connecting to updates.paloaltonetworks.com|199.167.52.13|:443... connected.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;WARNING: cannot verify updates.paloaltonetworks.com's certificate, issued by `/C=US/ST=Arizona/L=Scottsdale/O=GoDaddy.com, Inc./OU=&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://certificates.godaddy.com/repository/CN=Go"&gt;http://certificates.godaddy.com/repository/CN=Go&lt;/A&gt;&lt;SPAN&gt; Daddy Secure Certification Authority/serialNumber=07969287':&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; Self-signed certificate encountered.&lt;/P&gt;&lt;P&gt;HTTP request sent, awaiting response... 200 OK&lt;/P&gt;&lt;P&gt;Length: 4149 (4.1K) [text/xml]&lt;/P&gt;&lt;P&gt;Saving to: `/tmp/.contentinfo.xml.tmp'&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0K&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 100% 4.91M=0.001s&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2012-12-19 14:04:58 (4.91 MB/s) - `/tmp/.contentinfo.xml.tmp' saved [4149/4149]&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does the warning about a self signed certficate prevent the updates from beig downloaded ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The brightcloud URL update works fine.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Dec 2012 13:11:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-download-updates-pan-os-4-1-9-because-of-self-signed/m-p/21675#M15834</guid>
      <dc:creator>seniornwb</dc:creator>
      <dc:date>2012-12-19T13:11:46Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to download updates PAN OS 4.1.9 because of self signed certificate on updates.paloaltonetworks.com ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-download-updates-pan-os-4-1-9-because-of-self-signed/m-p/21676#M15835</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The certificate verification messages should not cause an issue with connecting to the update server.&amp;nbsp; We recently moved to using CDN for the actual content downloads.&amp;nbsp; You should modify your policies controlling outbound traffic to downloads.paloaltonetworks.com in addition to updates.paloaltonetworks.com.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are working on updating the paloalto-updates application signature to include all update related services.&amp;nbsp; No ETA at this point but it is actively being worked on.&amp;nbsp; Once that signature is current you can just allow that application to any destination in your security policies.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you continue to have issues downloading I would suggest opening a support ticket so we can investigate further.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;-- Kevin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Dec 2012 15:59:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-download-updates-pan-os-4-1-9-because-of-self-signed/m-p/21676#M15835</guid>
      <dc:creator>kfindlen</dc:creator>
      <dc:date>2012-12-19T15:59:17Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to download updates PAN OS 4.1.9 because of self signed certificate on updates.paloaltonetworks.com ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-download-updates-pan-os-4-1-9-because-of-self-signed/m-p/21677#M15836</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Adding the downloads.paloaltonetworks.com worked fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your help.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Dec 2012 07:57:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-download-updates-pan-os-4-1-9-because-of-self-signed/m-p/21677#M15836</guid>
      <dc:creator>seniornwb</dc:creator>
      <dc:date>2012-12-20T07:57:06Z</dc:date>
    </item>
  </channel>
</rss>

