<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSL Decrypt does NOT work with TLS 1.1 or TLS 1.2 in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decrypt-does-not-work-with-tls-1-1-or-tls-1-2/m-p/2370#M1755</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Any update from PAN?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 08 Jan 2013 20:22:39 GMT</pubDate>
    <dc:creator>Georges</dc:creator>
    <dc:date>2013-01-08T20:22:39Z</dc:date>
    <item>
      <title>SSL Decrypt does NOT work with TLS 1.1 or TLS 1.2</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decrypt-does-not-work-with-tls-1-1-or-tls-1-2/m-p/2359#M1744</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm running a cluster of PA (4.0.8) with SSL Decryption configured.&lt;/P&gt;&lt;P&gt;SSL Decryption is not able to decrypt SSL traffic if the HTTPS session is using TLS 1.1 or TLS 1.2.&lt;/P&gt;&lt;P&gt;Test with www.gmail.com&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Chrome : OK (see gmail application in the traffic log)&lt;/P&gt;&lt;P&gt;Firefox : idem&lt;/P&gt;&lt;P&gt;IE 8 or 9 with TLS 1.1 or TLS 1.2 DISABLED : idem&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;IE 8 or 9 with TLS 1.1 or TLS 1.2 ENABLED : see only SSL application&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it solved in 4.1.6 (I plan to upgrade my cluster with this release) ??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hedi&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Jul 2012 09:40:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decrypt-does-not-work-with-tls-1-1-or-tls-1-2/m-p/2359#M1744</guid>
      <dc:creator>licenselu</dc:creator>
      <dc:date>2012-07-19T09:40:49Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decrypt does NOT work with TLS 1.1 or TLS 1.2</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decrypt-does-not-work-with-tls-1-1-or-tls-1-2/m-p/2360#M1745</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Could this be your case &lt;A __default_attr="14818" __jive_macro_name="message" class="jive_macro jive_macro_message" href="https://live.paloaltonetworks.com/"&gt;&lt;/A&gt; ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;According to this &lt;A __default_attr="1504" __jive_macro_name="document" class="jive_macro jive_macro_document" href="https://live.paloaltonetworks.com/"&gt;&lt;/A&gt; PA supports TLSv1. But I think there were discussions in some thread regarding TLS 1.2 or if it was TLS 1.3 which currently wasnt supported and you to contact your sales engineer to file a request.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Jul 2012 11:31:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decrypt-does-not-work-with-tls-1-1-or-tls-1-2/m-p/2360#M1745</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-07-19T11:31:24Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decrypt does NOT work with TLS 1.1 or TLS 1.2</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decrypt-does-not-work-with-tls-1-1-or-tls-1-2/m-p/2361#M1746</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;First, thanks for your answer.&lt;/P&gt;&lt;P&gt;The document only mention SSL2.0, 3.0 and TLS 1.0. No infos about TLS 1.1 or TLS 1.2...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In my case, we don't have any problem with the certificate itself because the SSL interception is not doing it's job...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will upgrade 4.1.6 and keep you inform if it's solved or not...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hedi&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Jul 2012 15:41:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decrypt-does-not-work-with-tls-1-1-or-tls-1-2/m-p/2361#M1746</guid>
      <dc:creator>licenselu</dc:creator>
      <dc:date>2012-07-19T15:41:40Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decrypt does NOT work with TLS 1.1 or TLS 1.2</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decrypt-does-not-work-with-tls-1-1-or-tls-1-2/m-p/2362#M1747</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After upgrading to 4.1.6, I can confirm PA is NOT ABLE to decrypt TLS 1.1 or TLS1.2.&lt;/P&gt;&lt;P&gt;I'm waiting an OFFICIAL answer from PA now : When will it be supported ???&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hedi&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Jul 2012 12:15:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decrypt-does-not-work-with-tls-1-1-or-tls-1-2/m-p/2362#M1747</guid>
      <dc:creator>licenselu</dc:creator>
      <dc:date>2012-07-20T12:15:54Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decrypt does NOT work with TLS 1.1 or TLS 1.2</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decrypt-does-not-work-with-tls-1-1-or-tls-1-2/m-p/2363#M1748</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;as far as i know later Versions of TLS are currently not supported.&lt;/P&gt;&lt;P&gt;This Information was from PanOS 4.0.x&lt;/P&gt;&lt;P&gt;but since i didn't see anything in the Release Notes of 4.1.x it should be still correct.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Marco&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Jul 2012 14:45:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decrypt-does-not-work-with-tls-1-1-or-tls-1-2/m-p/2363#M1748</guid>
      <dc:creator>ExclusiveNetworksGermany</dc:creator>
      <dc:date>2012-07-23T14:45:09Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decrypt does NOT work with TLS 1.1 or TLS 1.2</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decrypt-does-not-work-with-tls-1-1-or-tls-1-2/m-p/2364#M1749</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt; I totally second your claims. In addition TLS 1.0 is partially finished : it lacks TLS Extensions, which make for example &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://www.gmail.com"&gt;https://www.gmail.com&lt;/A&gt;&lt;SPAN&gt; to fail decryption.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Aug 2012 09:04:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decrypt-does-not-work-with-tls-1-1-or-tls-1-2/m-p/2364#M1749</guid>
      <dc:creator>essnet</dc:creator>
      <dc:date>2012-08-07T09:04:20Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decrypt does NOT work with TLS 1.1 or TLS 1.2</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decrypt-does-not-work-with-tls-1-1-or-tls-1-2/m-p/2365#M1750</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;According to Chrome dev team, newest version has TLS 1.1 disabled because of issues with IIS : &lt;A href="http://googlechromereleases.blogspot.fr/2012/08/stable-channel-update_21.html" title="http://googlechromereleases.blogspot.fr/2012/08/stable-channel-update_21.html"&gt;Chrome Releases: Stable Channel Update&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you Microsoft, you're saving us for once :smileysilly:&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Aug 2012 08:17:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decrypt-does-not-work-with-tls-1-1-or-tls-1-2/m-p/2365#M1750</guid>
      <dc:creator>essnet</dc:creator>
      <dc:date>2012-08-22T08:17:08Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decrypt does NOT work with TLS 1.1 or TLS 1.2</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decrypt-does-not-work-with-tls-1-1-or-tls-1-2/m-p/2366#M1751</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is answer is receiver from my local SE.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri','sans-serif';"&gt;"TLS v1.1 should be supported as of v4.0.x.&lt;BR /&gt;I found a note that if diffie hellman is used in the key establishment we can’t decrypt."&lt;BR /&gt; &lt;BR /&gt; "v1.2 seems to be targeted for the next major release (5.x)."&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri','sans-serif';"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri','sans-serif';"&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri','sans-serif';"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri','sans-serif';"&gt;Hedi&lt;BR /&gt; &lt;BR /&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Aug 2012 08:59:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decrypt-does-not-work-with-tls-1-1-or-tls-1-2/m-p/2366#M1751</guid>
      <dc:creator>licenselu</dc:creator>
      <dc:date>2012-08-22T08:59:32Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decrypt does NOT work with TLS 1.1 or TLS 1.2</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decrypt-does-not-work-with-tls-1-1-or-tls-1-2/m-p/2367#M1752</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; I have been in relation for months with product and support managers, it was said many times that 1.1 is not supported and 1.0 is partially (lack of critical extensions). &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Strange we don't have same informations :smileygrin:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Anyway, I am always running my own tests and found out that above SSLv2, compatibility is poor.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Aug 2012 09:04:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decrypt-does-not-work-with-tls-1-1-or-tls-1-2/m-p/2367#M1752</guid>
      <dc:creator>essnet</dc:creator>
      <dc:date>2012-08-22T09:04:01Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decrypt does NOT work with TLS 1.1 or TLS 1.2</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decrypt-does-not-work-with-tls-1-1-or-tls-1-2/m-p/2368#M1753</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Would TLS 1.1 and 1.2 be decrypted by PANOS 5.0 for now?&lt;/P&gt;&lt;P&gt;TLS 1.1 with differ hellman could no be decrypted&amp;nbsp; on PANOS 5.0 also?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;P&gt;Roh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Nov 2012 02:23:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decrypt-does-not-work-with-tls-1-1-or-tls-1-2/m-p/2368#M1753</guid>
      <dc:creator>ttongfly</dc:creator>
      <dc:date>2012-11-26T02:23:31Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decrypt does NOT work with TLS 1.1 or TLS 1.2</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decrypt-does-not-work-with-tls-1-1-or-tls-1-2/m-p/2369#M1754</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; 5.0 doesn't bring better TLS support but it's bringing more control about actions when decryption fails or certificates is not trusted.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Decryption is no go for me until 5.1&amp;nbsp; (if they put it in 5.1)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Nov 2012 17:12:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decrypt-does-not-work-with-tls-1-1-or-tls-1-2/m-p/2369#M1754</guid>
      <dc:creator>essnet</dc:creator>
      <dc:date>2012-11-28T17:12:54Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decrypt does NOT work with TLS 1.1 or TLS 1.2</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decrypt-does-not-work-with-tls-1-1-or-tls-1-2/m-p/2370#M1755</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Any update from PAN?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Jan 2013 20:22:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decrypt-does-not-work-with-tls-1-1-or-tls-1-2/m-p/2370#M1755</guid>
      <dc:creator>Georges</dc:creator>
      <dc:date>2013-01-08T20:22:39Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decrypt does NOT work with TLS 1.1 or TLS 1.2</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decrypt-does-not-work-with-tls-1-1-or-tls-1-2/m-p/2371#M1756</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm running PAN 5.0.2.&amp;nbsp; Still not working.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Apr 2013 16:56:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decrypt-does-not-work-with-tls-1-1-or-tls-1-2/m-p/2371#M1756</guid>
      <dc:creator>edmondsadmin</dc:creator>
      <dc:date>2013-04-18T16:56:33Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decrypt does NOT work with TLS 1.1 or TLS 1.2</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decrypt-does-not-work-with-tls-1-1-or-tls-1-2/m-p/2372#M1757</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we currently do not support decryption of TLS1.2. TLS 1.2 hasn't be broadly supported by browsers until more or less practical TLS 1.0 and block cipher related attacks where demonstrated by cryptographers as proof of concept code. We do see a slow increase of TLS 1.2 support in major browsers lately. Especially Google Chrome and Apple Safari support in their standard configuration now. Since PANOS 5.0, if we detect a TLS1.1 or TLS1.2 session, we first try to downgrade it to TLS1.0 and decrypt. If that fails, we won't decrypt the session and either drop the session or allow it encrypted based upon your policy settings.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Jul 2013 21:22:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decrypt-does-not-work-with-tls-1-1-or-tls-1-2/m-p/2372#M1757</guid>
      <dc:creator>mwalter</dc:creator>
      <dc:date>2013-07-30T21:22:26Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decrypt does NOT work with TLS 1.1 or TLS 1.2</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decrypt-does-not-work-with-tls-1-1-or-tls-1-2/m-p/2373#M1758</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Why not implement support for TLS 1.1 and 1.2?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I really dont get it...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Aug 2013 19:38:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decrypt-does-not-work-with-tls-1-1-or-tls-1-2/m-p/2373#M1758</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2013-08-01T19:38:54Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decrypt does NOT work with TLS 1.1 or TLS 1.2</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decrypt-does-not-work-with-tls-1-1-or-tls-1-2/m-p/2374#M1759</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;For now, TLS 1.1 and 1.2 Support in SSL decryption? Anybody knows about that?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Nov 2013 02:26:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decrypt-does-not-work-with-tls-1-1-or-tls-1-2/m-p/2374#M1759</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-11-07T02:26:11Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decrypt does NOT work with TLS 1.1 or TLS 1.2</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decrypt-does-not-work-with-tls-1-1-or-tls-1-2/m-p/2375#M1760</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;According to my local SE, TLS 1.2 decryption should be supported in release train 6.x...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HA&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Nov 2013 08:07:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decrypt-does-not-work-with-tls-1-1-or-tls-1-2/m-p/2375#M1760</guid>
      <dc:creator>licenselu</dc:creator>
      <dc:date>2013-11-07T08:07:56Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decrypt does NOT work with TLS 1.1 or TLS 1.2</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decrypt-does-not-work-with-tls-1-1-or-tls-1-2/m-p/2376#M1761</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Would this be valid for the whole range from PA-200 to PA-5000 or just specific models?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Like will PA-2000 and PA-4000 be exluded?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 01 Dec 2013 17:02:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decrypt-does-not-work-with-tls-1-1-or-tls-1-2/m-p/2376#M1761</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2013-12-01T17:02:23Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decrypt does NOT work with TLS 1.1 or TLS 1.2</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decrypt-does-not-work-with-tls-1-1-or-tls-1-2/m-p/2377#M1762</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello, some news about tls 1.2 which belong to PAN-OS 6.0 previous releases of PAN-OS only supported TLS version 1.1. This release provides the Palo Alto Networks firewall with the ability to decrypt inbound sessions and forward proxy sessions that negotiate with TLS 1.2. With this release TLS 1.2 is enabled by default and cannot be disabled. This implementation includes the following details:  TLS 1.2 is supported as defined by RFC 5246.  The following additional cipher suites are supported: TLS_RSA_WITH_AES_128_CBC_SHA256 and TLS_RSA_WITH_AES_256_CBC_SHA256.  Newer unsupported versions of TLS (1.3+) will be downgraded to 1.2 when used with the PAN-OS. without any limitation for specific models&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Feb 2014 10:07:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decrypt-does-not-work-with-tls-1-1-or-tls-1-2/m-p/2377#M1762</guid>
      <dc:creator>kdd</dc:creator>
      <dc:date>2014-02-04T10:07:16Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decrypt does NOT work with TLS 1.1 or TLS 1.2</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decrypt-does-not-work-with-tls-1-1-or-tls-1-2/m-p/2378#M1763</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Unfortunately&amp;nbsp; I have tested SSL Decryption with Site that supports TLS1.2 and PANOS 6.0.10 with the latest version of firefox (v38.0.5) and I get "Secure Connection Failed" because firefox 38 does not failback from TLS version 1.2 to TLS version 1.1 as mentioned in the following &lt;SPAN style="font-size: 9.0pt; font-family: 'Helvetica',sans-serif; color: #1f497d;"&gt;&lt;A href="https://support.mozilla.org/en-US/kb/tls-error-reports" target="_blank"&gt;https://support.mozilla.org/en-US/kb/tls-error-reports&lt;BR /&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 9.0pt; font-family: 'Helvetica',sans-serif; color: #1f497d;"&gt;since TLS1.1 is considered insecure TLS version by mozilla foundation&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;It seems that the problem appears only if the Cipher suite of the site is TLS_RSA_WITH_AES_256_CBC_SHA256 and SSL Decryption with TLS1.2. This does not apply for Cipher Suite TLS_RSA_WITH_AES_128_CBC_SHA256 and TLS1.2/&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Jun 2015 14:36:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decrypt-does-not-work-with-tls-1-1-or-tls-1-2/m-p/2378#M1763</guid>
      <dc:creator>ggoudr</dc:creator>
      <dc:date>2015-06-03T14:36:22Z</dc:date>
    </item>
  </channel>
</rss>

