<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic page cannot be viewed properly in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/page-cannot-be-viewed-properly/m-p/30882#M22602</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is a web page that cannot be viewed properly because of ssl decryption.Decryption is made for gmail applications by using custom url&lt;/P&gt;&lt;P&gt;Is there a way to fix that without disabling ssl decryption ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 16 Jul 2013 19:47:20 GMT</pubDate>
    <dc:creator>Retired Member</dc:creator>
    <dc:date>2013-07-16T19:47:20Z</dc:date>
    <item>
      <title>page cannot be viewed properly</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/page-cannot-be-viewed-properly/m-p/30882#M22602</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is a web page that cannot be viewed properly because of ssl decryption.Decryption is made for gmail applications by using custom url&lt;/P&gt;&lt;P&gt;Is there a way to fix that without disabling ssl decryption ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Jul 2013 19:47:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/page-cannot-be-viewed-properly/m-p/30882#M22602</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-07-16T19:47:20Z</dc:date>
    </item>
    <item>
      <title>Re: page cannot be viewed properly</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/page-cannot-be-viewed-properly/m-p/30883#M22603</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Try to locate which TLS version is being used.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It seems that PA (still) doesnt properly support TLS1.2 (or if it was TLS1.1). There were previously rumours that this would have been fixed in PANOS 5.0 but it doesnt seem like that.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Jul 2013 20:01:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/page-cannot-be-viewed-properly/m-p/30883#M22603</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2013-07-16T20:01:35Z</dc:date>
    </item>
    <item>
      <title>Re: page cannot be viewed properly</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/page-cannot-be-viewed-properly/m-p/30884#M22604</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN&gt;The gmail server is an interesting animal when it comes to SSL. If you go to "&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://gmail.com"&gt;https://gmail.com&lt;/A&gt;&lt;SPAN&gt;" it fails to decrypt, but if you go to "&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://mail.google.com"&gt;https://mail.google.com&lt;/A&gt;&lt;SPAN&gt;". I haven't found a solid answer to that in my testing, and I can only speculate that it has to do with the multiple handshakes, redirects, and certs used.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try hitting the full (final) URL for google services to see if it will decrypt properly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Greg&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Jul 2013 00:41:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/page-cannot-be-viewed-properly/m-p/30884#M22604</guid>
      <dc:creator>gwesson</dc:creator>
      <dc:date>2013-07-17T00:41:58Z</dc:date>
    </item>
    <item>
      <title>Re: page cannot be viewed properly</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/page-cannot-be-viewed-properly/m-p/30885#M22605</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN&gt;According to &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://www.ssllabs.com/ssltest/analyze.html"&gt;https://www.ssllabs.com/ssltest/analyze.html&lt;/A&gt;&lt;SPAN&gt; both sites has:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Protocols&lt;/P&gt;&lt;P&gt;TLS 1.2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Yes&lt;/P&gt;&lt;P&gt;TLS 1.1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Yes&lt;/P&gt;&lt;P&gt;TLS 1.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Yes&lt;/P&gt;&lt;P&gt;SSL 3.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Yes&lt;/P&gt;&lt;P&gt;SSL 2.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; No&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cipher Suites (SSLv3+ suites in server-preferred order, then SSLv2 suites where used)&lt;/P&gt;&lt;P&gt;TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (0xc02f)&amp;nbsp;&amp;nbsp; ECDH 256 bits (eq. 3072 bits RSA)&amp;nbsp;&amp;nbsp; Forward Secrecy&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 128&lt;/P&gt;&lt;P&gt;TLS_ECDHE_RSA_WITH_RC4_128_SHA (0xc011)&amp;nbsp;&amp;nbsp; ECDH 256 bits (eq. 3072 bits RSA)&amp;nbsp;&amp;nbsp; Forward Secrecy&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 128&lt;/P&gt;&lt;P&gt;TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA (0xc013)&amp;nbsp;&amp;nbsp; ECDH 256 bits (eq. 3072 bits RSA)&amp;nbsp;&amp;nbsp; Forward Secrecy&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 128&lt;/P&gt;&lt;P&gt;TLS_RSA_WITH_AES_128_GCM_SHA256 (0x9c)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 128&lt;/P&gt;&lt;P&gt;SSL_RSA_WITH_RC4_128_SHA (0x5)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 128&lt;/P&gt;&lt;P&gt;SSL_RSA_WITH_RC4_128_MD5 (0x4)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 128&lt;/P&gt;&lt;P&gt;TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (0xc030)&amp;nbsp;&amp;nbsp; ECDH 256 bits (eq. 3072 bits RSA)&amp;nbsp;&amp;nbsp; Forward Secrecy&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 256&lt;/P&gt;&lt;P&gt;TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384 (0xc028)&amp;nbsp;&amp;nbsp; ECDH 256 bits (eq. 3072 bits RSA)&amp;nbsp;&amp;nbsp; Forward Secrecy&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 256&lt;/P&gt;&lt;P&gt;TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA (0xc014)&amp;nbsp;&amp;nbsp; ECDH 256 bits (eq. 3072 bits RSA)&amp;nbsp;&amp;nbsp; Forward Secrecy&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 256&lt;/P&gt;&lt;P&gt;TLS_RSA_WITH_AES_256_GCM_SHA384 (0x9d)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 256&lt;/P&gt;&lt;P&gt;TLS_RSA_WITH_AES_256_CBC_SHA256 (0x3d)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 256&lt;/P&gt;&lt;P&gt;TLS_RSA_WITH_AES_256_CBC_SHA (0x35)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 256&lt;/P&gt;&lt;P&gt;TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA (0xc012)&amp;nbsp;&amp;nbsp; ECDH 256 bits (eq. 3072 bits RSA)&amp;nbsp;&amp;nbsp; Forward Secrecy&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 168&lt;/P&gt;&lt;P&gt;SSL_RSA_WITH_3DES_EDE_CBC_SHA (0xa)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 168&lt;/P&gt;&lt;P&gt;TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 (0xc027)&amp;nbsp;&amp;nbsp; ECDH 256 bits (eq. 3072 bits RSA)&amp;nbsp;&amp;nbsp; Forward Secrecy&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 128&lt;/P&gt;&lt;P&gt;TLS_RSA_WITH_AES_128_CBC_SHA256 (0x3c)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 128&lt;/P&gt;&lt;P&gt;TLS_RSA_WITH_AES_128_CBC_SHA (0x2f)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 128&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However www.gmail.com has a note of "This site works only in browsers with SNI support.".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could it be that PA doesnt have support för SNI?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For more info of SNI:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://en.wikipedia.org/wiki/Server_Name_Indication"&gt;http://en.wikipedia.org/wiki/Server_Name_Indication&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://wiki.apache.org/httpd/NameBasedSSLVHostsWithSNI"&gt;http://wiki.apache.org/httpd/NameBasedSSLVHostsWithSNI&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Other than that the certs seems to be issued weekly (for both sites the valid from was set to 12 july 2013...), could it be some ssl-cache problem within PA?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Jul 2013 21:12:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/page-cannot-be-viewed-properly/m-p/30885#M22605</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2013-07-17T21:12:07Z</dc:date>
    </item>
    <item>
      <title>Re: page cannot be viewed properly</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/page-cannot-be-viewed-properly/m-p/30886#M22606</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;good point.Maybe you are right about cache.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Jul 2013 21:19:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/page-cannot-be-viewed-properly/m-p/30886#M22606</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-07-17T21:19:35Z</dc:date>
    </item>
    <item>
      <title>Re: page cannot be viewed properly</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/page-cannot-be-viewed-properly/m-p/30887#M22607</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This happens with chrome only.&lt;/P&gt;&lt;P&gt;I searched and found &lt;/P&gt;&lt;P&gt;&lt;A __default_attr="17482" __jive_macro_name="message" class="jive_macro jive_macro_message" href="https://live.paloaltonetworks.com/"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;but that did not solve our problem.When I disable decryption it works fine.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Jul 2013 21:04:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/page-cannot-be-viewed-properly/m-p/30887#M22607</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-07-19T21:04:34Z</dc:date>
    </item>
    <item>
      <title>Re: page cannot be viewed properly</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/page-cannot-be-viewed-properly/m-p/30888#M22608</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is the decryption certificate used by the firewall,&amp;nbsp; trusted by the PC from where you are browsing the web-page ? I have seen similar issues, downloading the SSL forward proxy certificate that is used on the firewall and adding it to the trusted root ca folder in certificate store of the pc fixed the issue for me.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Jul 2013 21:43:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/page-cannot-be-viewed-properly/m-p/30888#M22608</guid>
      <dc:creator>sdurga</dc:creator>
      <dc:date>2013-07-19T21:43:20Z</dc:date>
    </item>
    <item>
      <title>Re: page cannot be viewed properly</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/page-cannot-be-viewed-properly/m-p/30889#M22609</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;it was imported for a long time.importing again to root after that issue has fixed the page problem.Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Jul 2013 23:33:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/page-cannot-be-viewed-properly/m-p/30889#M22609</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-07-19T23:33:30Z</dc:date>
    </item>
  </channel>
</rss>

