<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSL certificate cache in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-certificate-cache/m-p/30408#M22238</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;A1. "debug dataplane reset ssl-decrypt certificate-cache" command will do the job.&amp;nbsp; (This will also reset the SSL connection of Admin GUI).&lt;/P&gt;&lt;P&gt;A2. If it's kind of hostname based whitelist, I don't think it's possible.&lt;/P&gt;&lt;P&gt;A3. To see if the session is denied by expired cert, show session id &amp;lt;id number&amp;gt;" might help. It shows "session tracker stage deny&amp;nbsp;&amp;nbsp;&amp;nbsp; : proxy decrypt failure". There might be better way to check.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Some other commands,&lt;/P&gt;&lt;P&gt;- show system setting ssl-decrypt ?&lt;/P&gt;&lt;P&gt;&amp;gt; certificate&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Show ssl-decrypt certificate&lt;/P&gt;&lt;P&gt;&amp;gt; certificate-cache&amp;nbsp;&amp;nbsp; Show ssl-decrypt certificate cache&lt;/P&gt;&lt;P&gt;&amp;gt; exclude-cache&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Show ssl-decrypt exclude cache&lt;/P&gt;&lt;P&gt;&amp;gt; memory&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Show ssl-decrypt memory usage&lt;/P&gt;&lt;P&gt;&amp;gt; notify-cache&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Show ssl-decrypt notify cache&lt;/P&gt;&lt;P&gt;&amp;gt; session-cache&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Show ssl-decrypt session cache&lt;/P&gt;&lt;P&gt;&amp;gt; setting&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Show ssl-decrypt settings&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- debug dataplane reset ssl-decrypt ?&lt;/P&gt;&lt;P&gt;&amp;gt; certificate-cache&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Clear all ssl-decrypt certificate cache in dataplane&lt;/P&gt;&lt;P&gt;&amp;gt; certificate-status&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Clear all ssl-decrypt certificate CRL status cached in dataplane&lt;/P&gt;&lt;P&gt;&amp;gt; exclude-cache&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Clear all exclude cache in dataplane&lt;/P&gt;&lt;P&gt;&amp;gt; host-certificate-cache&amp;nbsp;&amp;nbsp; Clear all SSL certificates stored in host&lt;/P&gt;&lt;P&gt;&amp;gt; notify-cache&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Clear all ssl-decrypt notify-user cache in dataplane&lt;/P&gt;&lt;P&gt;&amp;gt; session-cache&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Clear all ssl-decrypt session cache in dataplane&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 28 May 2013 01:27:37 GMT</pubDate>
    <dc:creator>ymiyashita</dc:creator>
    <dc:date>2013-05-28T01:27:37Z</dc:date>
    <item>
      <title>SSL certificate cache</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-certificate-cache/m-p/30406#M22236</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;there are various settings in the decryption profile and also under Device -&amp;gt; Sessions -&amp;gt; Decryption Certificate Revocation Settings to controll how the firewall should deal with expired or self-signed certificates etc. I am currently testing these things in a Lab and I am having difficulties to see any differences in the firewall's behavior when I change any of these settings.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Example: decryption profile allows expired certificates. I can surf to a site that has an expired certificate. Now I change the decryption profile to block expired certificates but I can still open the same website. When I reboot the firewall, I can no longer open that website. So there is obviously some sort of caching going on and the fine print on the bottom of the decryption profile options dialog confirms that (it says 12 hours).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there some way I can control this cache or delete it without rebooting the firewall? I need to be able to change these settings so that they have an immediate effect.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, as a side question:&lt;/P&gt;&lt;P&gt;Say I have a profile that blocks expired certificates. Can I make exceptions to that? Some sort of whitelist?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 26 May 2013 18:18:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-certificate-cache/m-p/30406#M22236</guid>
      <dc:creator>cryptochrome</dc:creator>
      <dc:date>2013-05-26T18:18:07Z</dc:date>
    </item>
    <item>
      <title>Re: SSL certificate cache</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-certificate-cache/m-p/30407#M22237</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Oh, and as a third question: Where in the logs do I find SSL related messages like drops on expired certificates? I know how to find out whether a session was decrypted or not, but how do I dig deeper if I need to troubleshoot something or just filter on "all expired certificates" and things like that?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 26 May 2013 18:22:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-certificate-cache/m-p/30407#M22237</guid>
      <dc:creator>cryptochrome</dc:creator>
      <dc:date>2013-05-26T18:22:01Z</dc:date>
    </item>
    <item>
      <title>Re: SSL certificate cache</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-certificate-cache/m-p/30408#M22238</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;A1. "debug dataplane reset ssl-decrypt certificate-cache" command will do the job.&amp;nbsp; (This will also reset the SSL connection of Admin GUI).&lt;/P&gt;&lt;P&gt;A2. If it's kind of hostname based whitelist, I don't think it's possible.&lt;/P&gt;&lt;P&gt;A3. To see if the session is denied by expired cert, show session id &amp;lt;id number&amp;gt;" might help. It shows "session tracker stage deny&amp;nbsp;&amp;nbsp;&amp;nbsp; : proxy decrypt failure". There might be better way to check.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Some other commands,&lt;/P&gt;&lt;P&gt;- show system setting ssl-decrypt ?&lt;/P&gt;&lt;P&gt;&amp;gt; certificate&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Show ssl-decrypt certificate&lt;/P&gt;&lt;P&gt;&amp;gt; certificate-cache&amp;nbsp;&amp;nbsp; Show ssl-decrypt certificate cache&lt;/P&gt;&lt;P&gt;&amp;gt; exclude-cache&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Show ssl-decrypt exclude cache&lt;/P&gt;&lt;P&gt;&amp;gt; memory&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Show ssl-decrypt memory usage&lt;/P&gt;&lt;P&gt;&amp;gt; notify-cache&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Show ssl-decrypt notify cache&lt;/P&gt;&lt;P&gt;&amp;gt; session-cache&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Show ssl-decrypt session cache&lt;/P&gt;&lt;P&gt;&amp;gt; setting&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Show ssl-decrypt settings&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- debug dataplane reset ssl-decrypt ?&lt;/P&gt;&lt;P&gt;&amp;gt; certificate-cache&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Clear all ssl-decrypt certificate cache in dataplane&lt;/P&gt;&lt;P&gt;&amp;gt; certificate-status&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Clear all ssl-decrypt certificate CRL status cached in dataplane&lt;/P&gt;&lt;P&gt;&amp;gt; exclude-cache&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Clear all exclude cache in dataplane&lt;/P&gt;&lt;P&gt;&amp;gt; host-certificate-cache&amp;nbsp;&amp;nbsp; Clear all SSL certificates stored in host&lt;/P&gt;&lt;P&gt;&amp;gt; notify-cache&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Clear all ssl-decrypt notify-user cache in dataplane&lt;/P&gt;&lt;P&gt;&amp;gt; session-cache&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Clear all ssl-decrypt session cache in dataplane&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 May 2013 01:27:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-certificate-cache/m-p/30408#M22238</guid>
      <dc:creator>ymiyashita</dc:creator>
      <dc:date>2013-05-28T01:27:37Z</dc:date>
    </item>
    <item>
      <title>Re: SSL certificate cache</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-certificate-cache/m-p/30409#M22239</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Awesome, Yasu. Very helpful! Thanks a lot!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 May 2013 07:00:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-certificate-cache/m-p/30409#M22239</guid>
      <dc:creator>cryptochrome</dc:creator>
      <dc:date>2013-05-28T07:00:56Z</dc:date>
    </item>
    <item>
      <title>Re: SSL certificate cache</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-certificate-cache/m-p/100861#M44305</link>
      <description>&lt;P&gt;Can we automate to clear ssl cert cache in PA ? Do we have to do it manually everytime ?&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/8083"&gt;@ymiyashita&lt;/a&gt; wrote:&lt;BR /&gt;&lt;P&gt;A1. "debug dataplane reset ssl-decrypt certificate-cache" command will do the job.&amp;nbsp; (This will also reset the SSL connection of Admin GUI).&lt;/P&gt;&lt;P&gt;A2. If it's kind of hostname based whitelist, I don't think it's possible.&lt;/P&gt;&lt;P&gt;A3. To see if the session is denied by expired cert, show session id &amp;lt;id number&amp;gt;" might help. It shows "session tracker stage deny&amp;nbsp;&amp;nbsp;&amp;nbsp; : proxy decrypt failure". There might be better way to check.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Some other commands,&lt;/P&gt;&lt;P&gt;- show system setting ssl-decrypt ?&lt;/P&gt;&lt;P&gt;&amp;gt; certificate&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Show ssl-decrypt certificate&lt;/P&gt;&lt;P&gt;&amp;gt; certificate-cache&amp;nbsp;&amp;nbsp; Show ssl-decrypt certificate cache&lt;/P&gt;&lt;P&gt;&amp;gt; exclude-cache&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Show ssl-decrypt exclude cache&lt;/P&gt;&lt;P&gt;&amp;gt; memory&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Show ssl-decrypt memory usage&lt;/P&gt;&lt;P&gt;&amp;gt; notify-cache&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Show ssl-decrypt notify cache&lt;/P&gt;&lt;P&gt;&amp;gt; session-cache&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Show ssl-decrypt session cache&lt;/P&gt;&lt;P&gt;&amp;gt; setting&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Show ssl-decrypt settings&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- debug dataplane reset ssl-decrypt ?&lt;/P&gt;&lt;P&gt;&amp;gt; certificate-cache&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Clear all ssl-decrypt certificate cache in dataplane&lt;/P&gt;&lt;P&gt;&amp;gt; certificate-status&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Clear all ssl-decrypt certificate CRL status cached in dataplane&lt;/P&gt;&lt;P&gt;&amp;gt; exclude-cache&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Clear all exclude cache in dataplane&lt;/P&gt;&lt;P&gt;&amp;gt; host-certificate-cache&amp;nbsp;&amp;nbsp; Clear all SSL certificates stored in host&lt;/P&gt;&lt;P&gt;&amp;gt; notify-cache&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Clear all ssl-decrypt notify-user cache in dataplane&lt;/P&gt;&lt;P&gt;&amp;gt; session-cache&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Clear all ssl-decrypt session cache in dataplane&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jul 2016 00:27:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-certificate-cache/m-p/100861#M44305</guid>
      <dc:creator>Srivastava</dc:creator>
      <dc:date>2016-07-29T00:27:16Z</dc:date>
    </item>
  </channel>
</rss>

