<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic disable SSL renegotiation in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/disable-ssl-renegotiation/m-p/27979#M20421</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is there a way to disable SSL renegotiation at firewall level ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Disabling it server side (&lt;A href="http://support.microsoft.com/kb/977377" title="http://support.microsoft.com/kb/977377"&gt; Microsoft Security Advisory: Vulnerability in TLS/SSL could allow spoofing&lt;/A&gt; ) breaks activeSync. I'd like to test a different scenario to get rid of the many false positives we get for the SSL Renegotiation Denial of Service Vulnerability.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 09 Jul 2012 06:22:55 GMT</pubDate>
    <dc:creator>dieter_b</dc:creator>
    <dc:date>2012-07-09T06:22:55Z</dc:date>
    <item>
      <title>disable SSL renegotiation</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/disable-ssl-renegotiation/m-p/27979#M20421</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is there a way to disable SSL renegotiation at firewall level ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Disabling it server side (&lt;A href="http://support.microsoft.com/kb/977377" title="http://support.microsoft.com/kb/977377"&gt; Microsoft Security Advisory: Vulnerability in TLS/SSL could allow spoofing&lt;/A&gt; ) breaks activeSync. I'd like to test a different scenario to get rid of the many false positives we get for the SSL Renegotiation Denial of Service Vulnerability.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Jul 2012 06:22:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/disable-ssl-renegotiation/m-p/27979#M20421</guid>
      <dc:creator>dieter_b</dc:creator>
      <dc:date>2012-07-09T06:22:55Z</dc:date>
    </item>
    <item>
      <title>Re: disable SSL renegotiation</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/disable-ssl-renegotiation/m-p/27980#M20422</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;According to the admin guide (page 178) you can setup custom IPS signatures based on SSL so I hope its possible to setup a vuln signature regarding ssl negotiation which you then block if this comes client -&amp;gt; server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Unfortunately I currently dont have any example on how to setup such signature.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Jul 2012 12:46:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/disable-ssl-renegotiation/m-p/27980#M20422</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-07-09T12:46:19Z</dc:date>
    </item>
  </channel>
</rss>

