<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Failed to get CRL http:// ... in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/failed-to-get-crl-http/m-p/23151#M16881</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Choff,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please make sure service route for CRL updates to an ip address where it can communicate to internet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hari Yadavalli&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 14 Dec 2013 12:30:13 GMT</pubDate>
    <dc:creator>hyadavalli</dc:creator>
    <dc:date>2013-12-14T12:30:13Z</dc:date>
    <item>
      <title>Failed to get CRL http:// ...</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/failed-to-get-crl-http/m-p/23149#M16879</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Im getting tons of failed to get CRL errors in my logs all of the sudden. Im not sure what I did (if anything) to cause this.&lt;/P&gt;&lt;P&gt;Ive tried to fix it,&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;I tried to enable&amp;nbsp; "Server CRL"&lt;/LI&gt;&lt;LI&gt;I did a nslookup on crl.verisign.com and I cant see any connections outbound being denied.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;I cannot fix this.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Any sugestions on how to fix this?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;What is this even for? &lt;/STRONG&gt;I was not aware that the firewall was downloading any&amp;nbsp; CRLs, could it be part of SSL Decrypt? THe admin prior to me tries to get SSL Decrypt working but eh 4xxx serise do not support it (its broken/buggy)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help appreciated, thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="crl errors.JPG.jpg" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/8769_crl errors.JPG.jpg" style="width: 620px; height: 267px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Oct 2013 15:47:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/failed-to-get-crl-http/m-p/23149#M16879</guid>
      <dc:creator>choff123</dc:creator>
      <dc:date>2013-10-02T15:47:41Z</dc:date>
    </item>
    <item>
      <title>Re: Failed to get CRL http:// ...</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/failed-to-get-crl-http/m-p/23150#M16880</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Need to ensure the Palo Alto can resolve these addresses as well as ensure that outbound connections from the device via the service route (management interface default) are allowed.&amp;nbsp; If this does not resolve your issue please open a support ticket.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 14 Dec 2013 00:51:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/failed-to-get-crl-http/m-p/23150#M16880</guid>
      <dc:creator>JimS2</dc:creator>
      <dc:date>2013-12-14T00:51:38Z</dc:date>
    </item>
    <item>
      <title>Re: Failed to get CRL http:// ...</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/failed-to-get-crl-http/m-p/23151#M16881</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Choff,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please make sure service route for CRL updates to an ip address where it can communicate to internet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hari Yadavalli&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 14 Dec 2013 12:30:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/failed-to-get-crl-http/m-p/23151#M16881</guid>
      <dc:creator>hyadavalli</dc:creator>
      <dc:date>2013-12-14T12:30:13Z</dc:date>
    </item>
    <item>
      <title>Re: Failed to get CRL http:// ...</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/failed-to-get-crl-http/m-p/23152#M16882</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here's another approach. If it began to happen after you made some config changes and if you're not sure what was changed, maybe you can look at config log (Monitor =&amp;gt; Logs =&amp;gt; Configuration) to see if there's any corresponding change.&lt;/P&gt;&lt;P&gt;- Yasu&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Dec 2013 07:41:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/failed-to-get-crl-http/m-p/23152#M16882</guid>
      <dc:creator>ymiyashita</dc:creator>
      <dc:date>2013-12-16T07:41:51Z</dc:date>
    </item>
    <item>
      <title>Re: Failed to get CRL http:// ...</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/failed-to-get-crl-http/m-p/23153#M16883</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we had the same issue. You have to create a new firewall policy allowing the MGT interface of the PA to download the CRLs.&lt;/P&gt;&lt;P&gt;Take a look how we solved it:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="2.JPG.jpg" class="jive-image" height="81" src="https://live.paloaltonetworks.com/legacyfs/online/10382_2.JPG.jpg" width="851" /&gt;&lt;/P&gt;&lt;P&gt;With a custom URL category we allowing the crl sites:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="1.jpg" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/10383_1.jpg" style="width: 620px; height: 656px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So you have check the system logs and enter each URL in the custom URL category.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Dec 2013 14:24:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/failed-to-get-crl-http/m-p/23153#M16883</guid>
      <dc:creator>Hithead</dc:creator>
      <dc:date>2013-12-18T14:24:59Z</dc:date>
    </item>
  </channel>
</rss>

