<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Revoked Certificate treating as Valid, is it a bug? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/revoked-certificate-treating-as-valid-is-it-a-bug/m-p/24222#M17657</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="margin-top:0pt;margin-right:0pt;margin-bottom:0pt;margin-left:0pt;padding-top:0pt;padding-right:0pt;padding-bottom:0pt;padding-left:0pt"&gt;I am using PA2050 PanOS4.02.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-top:0pt;margin-right:0pt;margin-bottom:0pt;margin-left:0pt;padding-top:0pt;padding-right:0pt;padding-bottom:0pt;padding-left:0pt"&gt;I also want to know is the cert if being timeout or allowed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-top:0pt;margin-right:0pt;margin-bottom:0pt;margin-left:0pt;padding-top:0pt;padding-right:0pt;padding-bottom:0pt;padding-left:0pt"&gt;On OSCP responder log, I can check PA2050 queries and the response to PA2050&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-top:0pt;margin-right:0pt;margin-bottom:0pt;margin-left:0pt;padding-top:0pt;padding-right:0pt;padding-bottom:0pt;padding-left:0pt"&gt;On PA2050, as the capture, it shows the cert has been revoked. (I cannot find log for good cert though, I don"t know if PA do not log good cert events or it cannot get response)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-top:0pt;margin-right:0pt;margin-bottom:0pt;margin-left:0pt;padding-top:0pt;padding-right:0pt;padding-bottom:0pt;padding-left:0pt"&gt;However both good or revoked cert is not allowed if the "block timeout cert" is checked. &lt;/P&gt;&lt;P style="margin-top:0pt;margin-right:0pt;margin-bottom:0pt;margin-left:0pt;padding-top:0pt;padding-right:0pt;padding-bottom:0pt;padding-left:0pt"&gt;And other reason I think all cert has been timeout is PA do retry every query 3 times.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-top:0pt;margin-right:0pt;margin-bottom:0pt;margin-left:0pt;padding-top:0pt;padding-right:0pt;padding-bottom:0pt;padding-left:0pt"&gt;So the unknown area is:&lt;/P&gt;&lt;P style="margin-top:0pt;margin-right:0pt;margin-bottom:0pt;margin-left:0pt;padding-top:0pt;padding-right:0pt;padding-bottom:0pt;padding-left:0pt"&gt;1. It looks like PA2050 timeout all revoked and good cert, but interestingly it actuallly got response from OSCP responder which able to log a revoked cert events.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 29 May 2011 23:55:40 GMT</pubDate>
    <dc:creator>muratahk</dc:creator>
    <dc:date>2011-05-29T23:55:40Z</dc:date>
    <item>
      <title>Revoked Certificate treating as Valid, is it a bug?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/revoked-certificate-treating-as-valid-is-it-a-bug/m-p/24219#M17654</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have set up Client Certification Profile, and use in SSL VPN. I tried to revoke a cert. Firefox already able to valid that cert is invalid but PaloAlto still allow that certificate, I was able to verify from my OSCP server that PaloAlto had a successful query to my server, but I dont know what it is still allowing that revoked cert in SSL VPN.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 14 May 2011 12:26:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/revoked-certificate-treating-as-valid-is-it-a-bug/m-p/24219#M17654</guid>
      <dc:creator>muratahk</dc:creator>
      <dc:date>2011-05-14T12:26:15Z</dc:date>
    </item>
    <item>
      <title>Re: Revoked Certificate treating as Valid, is it a bug?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/revoked-certificate-treating-as-valid-is-it-a-bug/m-p/24220#M17655</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I checked on the log, the ocsp responder replied the cert is revoked. But seems PA ignore the reply and retry 3 times and timeout the cert. If I check block timeout cert, all cert will be blocked. If I uncheck block time cert, all cert will be allowed. I do not know why it timeout the cert while system log already set it get response from OCSP that the cert was revoked or Good. I think it is a bug.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 May 2011 01:09:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/revoked-certificate-treating-as-valid-is-it-a-bug/m-p/24220#M17655</guid>
      <dc:creator>muratahk</dc:creator>
      <dc:date>2011-05-17T01:09:15Z</dc:date>
    </item>
    <item>
      <title>Re: Revoked Certificate treating as Valid, is it a bug?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/revoked-certificate-treating-as-valid-is-it-a-bug/m-p/24221#M17656</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It looks like we are able to contact the OCSP responder and get the correct certificate status. It's not clear from your posts whether a revoked certificate is being allowed or timing out?&amp;nbsp; Do valid certificates work and and do we log the correct response?&amp;nbsp; Are your results similar or different with IE? Have you tried just CRL checking? I would expect that if a revoked certificate is presented that we would not allow it and present a page saying it is revoked. What version PANOS are you running?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 28 May 2011 17:47:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/revoked-certificate-treating-as-valid-is-it-a-bug/m-p/24221#M17656</guid>
      <dc:creator>schiang1</dc:creator>
      <dc:date>2011-05-28T17:47:46Z</dc:date>
    </item>
    <item>
      <title>Re: Revoked Certificate treating as Valid, is it a bug?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/revoked-certificate-treating-as-valid-is-it-a-bug/m-p/24222#M17657</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="margin-top:0pt;margin-right:0pt;margin-bottom:0pt;margin-left:0pt;padding-top:0pt;padding-right:0pt;padding-bottom:0pt;padding-left:0pt"&gt;I am using PA2050 PanOS4.02.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-top:0pt;margin-right:0pt;margin-bottom:0pt;margin-left:0pt;padding-top:0pt;padding-right:0pt;padding-bottom:0pt;padding-left:0pt"&gt;I also want to know is the cert if being timeout or allowed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-top:0pt;margin-right:0pt;margin-bottom:0pt;margin-left:0pt;padding-top:0pt;padding-right:0pt;padding-bottom:0pt;padding-left:0pt"&gt;On OSCP responder log, I can check PA2050 queries and the response to PA2050&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-top:0pt;margin-right:0pt;margin-bottom:0pt;margin-left:0pt;padding-top:0pt;padding-right:0pt;padding-bottom:0pt;padding-left:0pt"&gt;On PA2050, as the capture, it shows the cert has been revoked. (I cannot find log for good cert though, I don"t know if PA do not log good cert events or it cannot get response)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-top:0pt;margin-right:0pt;margin-bottom:0pt;margin-left:0pt;padding-top:0pt;padding-right:0pt;padding-bottom:0pt;padding-left:0pt"&gt;However both good or revoked cert is not allowed if the "block timeout cert" is checked. &lt;/P&gt;&lt;P style="margin-top:0pt;margin-right:0pt;margin-bottom:0pt;margin-left:0pt;padding-top:0pt;padding-right:0pt;padding-bottom:0pt;padding-left:0pt"&gt;And other reason I think all cert has been timeout is PA do retry every query 3 times.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-top:0pt;margin-right:0pt;margin-bottom:0pt;margin-left:0pt;padding-top:0pt;padding-right:0pt;padding-bottom:0pt;padding-left:0pt"&gt;So the unknown area is:&lt;/P&gt;&lt;P style="margin-top:0pt;margin-right:0pt;margin-bottom:0pt;margin-left:0pt;padding-top:0pt;padding-right:0pt;padding-bottom:0pt;padding-left:0pt"&gt;1. It looks like PA2050 timeout all revoked and good cert, but interestingly it actuallly got response from OSCP responder which able to log a revoked cert events.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 29 May 2011 23:55:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/revoked-certificate-treating-as-valid-is-it-a-bug/m-p/24222#M17657</guid>
      <dc:creator>muratahk</dc:creator>
      <dc:date>2011-05-29T23:55:40Z</dc:date>
    </item>
    <item>
      <title>Re: Revoked Certificate treating as Valid, is it a bug?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/revoked-certificate-treating-as-valid-is-it-a-bug/m-p/24223#M17658</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Muratahk,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The issue you have described seems similar to a bug which we are aware about. To verify the issue you are seeing is the same as the bug which we are planning to fix in next release,&amp;nbsp; you will have to open up a support case.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 01 Jun 2011 23:38:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/revoked-certificate-treating-as-valid-is-it-a-bug/m-p/24223#M17658</guid>
      <dc:creator>mrajdev</dc:creator>
      <dc:date>2011-06-01T23:38:07Z</dc:date>
    </item>
  </channel>
</rss>

