<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSL Decryption - No bypass at cert error screen in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-no-bypass-at-cert-error-screen/m-p/24410#M17800</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Chrome uses a mechanism called Certificate Pinning for google-based sites (google, youtube, gmail, etc.). If your users don't trust the root CA used in your SSL decryption, there is no way to bypass the message you're seeing. Once you trust the CA used for your decryption, and you clear the cache of the browser, you should be able to go back to gmail and it should work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Chrome, IE, and Safari all use the Windows certificate store. Firefox uses its own, so you'll have to repeat the steps on Firefox if you hit it there too.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Greg&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 10 Jun 2015 17:15:19 GMT</pubDate>
    <dc:creator>gwesson</dc:creator>
    <dc:date>2015-06-10T17:15:19Z</dc:date>
    <item>
      <title>SSL Decryption - No bypass at cert error screen</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-no-bypass-at-cert-error-screen/m-p/24409#M17799</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dears,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We tried to configure SSL Decryption in our 3020 box and for some users with no certificate applied, we have that common certificate error page.... But in our case, we have no "bypass button" ....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we created everything according PA tutorial and also we created a custom URL containing &lt;STRONG&gt;*.google.com&lt;/STRONG&gt; and &lt;STRONG&gt;google.com&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="ScreenShot040.jpg" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/20021_ScreenShot040.jpg" style="height: 510px; width: 620px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Jun 2015 15:47:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-no-bypass-at-cert-error-screen/m-p/24409#M17799</guid>
      <dc:creator>FabioGarcia</dc:creator>
      <dc:date>2015-06-10T15:47:17Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption - No bypass at cert error screen</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-no-bypass-at-cert-error-screen/m-p/24410#M17800</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Chrome uses a mechanism called Certificate Pinning for google-based sites (google, youtube, gmail, etc.). If your users don't trust the root CA used in your SSL decryption, there is no way to bypass the message you're seeing. Once you trust the CA used for your decryption, and you clear the cache of the browser, you should be able to go back to gmail and it should work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Chrome, IE, and Safari all use the Windows certificate store. Firefox uses its own, so you'll have to repeat the steps on Firefox if you hit it there too.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Greg&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Jun 2015 17:15:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-no-bypass-at-cert-error-screen/m-p/24410#M17800</guid>
      <dc:creator>gwesson</dc:creator>
      <dc:date>2015-06-10T17:15:19Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption - No bypass at cert error screen</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-no-bypass-at-cert-error-screen/m-p/24411#M17801</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello and Thank you for the help!!&lt;/P&gt;&lt;P&gt;I tried everything... and just mail.google.com I have no bypass button....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;cert error screen for google.com&lt;/P&gt;&lt;P&gt;&lt;IMG alt="ScreenShot041.jpg" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/20030_ScreenShot041.jpg" style="height: 451px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there any option to bypass this &lt;STRONG&gt;"HTTP Strict Transport Security (HSTS)"&lt;/STRONG&gt; ?? As far as I understood... that site force us to trust the certificate or it will not allow the access.... right ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks and best regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Jun 2015 19:42:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-no-bypass-at-cert-error-screen/m-p/24411#M17801</guid>
      <dc:creator>FabioGarcia</dc:creator>
      <dc:date>2015-06-10T19:42:42Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption - No bypass at cert error screen</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-no-bypass-at-cert-error-screen/m-p/24412#M17802</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;HSTS is a setting enforced by servers, not browsers, which forces the clients connecting to use TLS instead of plain HTTP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You need to install the CA cert used in your firewall's decryption policy onto the clients and make it a trusted CA. That's the only way to correctly use decryption.&lt;/P&gt;&lt;P&gt;Here are the steps for Firefox: &lt;A href="https://live.paloaltonetworks.com/docs/DOC-7521"&gt;After Configuring SSL Decryption Mozilla Firefox Presents Certificate Error&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Jun 2015 20:17:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-no-bypass-at-cert-error-screen/m-p/24412#M17802</guid>
      <dc:creator>gwesson</dc:creator>
      <dc:date>2015-06-10T20:17:08Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption - No bypass at cert error screen</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-no-bypass-at-cert-error-screen/m-p/24413#M17803</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We had a similar issue with a secure site and Firefox wouldn't offer the option to bypass on a PC while it did work on mine. We use the same version, and we're on the same subnet. Clearing the cache in Firefox on his PC is all it took for it offer the option to continue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"for some users with no certificate applied, we have that common certificate error page..."&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BTW, if you're decrypting traffic and don't have the certificate applied for some people and they get the alert, be aware that you're conditioning these users to blindly accept any untrusted connection in the future.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, some sites won't allow to continue if the MIM certificate is not installed, no matter what. Those sites will have to be added to an ssl bypass list.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Larry.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Jun 2015 19:29:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-no-bypass-at-cert-error-screen/m-p/24413#M17803</guid>
      <dc:creator>hvcomputech</dc:creator>
      <dc:date>2015-06-12T19:29:16Z</dc:date>
    </item>
  </channel>
</rss>

