<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ELSTER and SSL decryption in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/elster-and-ssl-decryption/m-p/31141#M22779</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In Germany one can use "ELSTER" to transmit tax reports electronically to the financial authorities. Elster is build in many ERP Systems and alike.&lt;/P&gt;&lt;P&gt;Unfortunately the certificate used by the authorities is self signed and therefor not trusted by the PA and gets newley created by and signed by the "forward_untrust" CA in the PA rendering a communication error in the ELSTER software (which has the original certificate hardcoded).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;See attached a little how-to to fix this with a "not decrypt" rule. If anyone finds a better, more granular way to accomplish this, please let me know.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 11 Aug 2012 10:29:52 GMT</pubDate>
    <dc:creator>u13550</dc:creator>
    <dc:date>2012-08-11T10:29:52Z</dc:date>
    <item>
      <title>ELSTER and SSL decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/elster-and-ssl-decryption/m-p/31141#M22779</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In Germany one can use "ELSTER" to transmit tax reports electronically to the financial authorities. Elster is build in many ERP Systems and alike.&lt;/P&gt;&lt;P&gt;Unfortunately the certificate used by the authorities is self signed and therefor not trusted by the PA and gets newley created by and signed by the "forward_untrust" CA in the PA rendering a communication error in the ELSTER software (which has the original certificate hardcoded).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;See attached a little how-to to fix this with a "not decrypt" rule. If anyone finds a better, more granular way to accomplish this, please let me know.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 11 Aug 2012 10:29:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/elster-and-ssl-decryption/m-p/31141#M22779</guid>
      <dc:creator>u13550</dc:creator>
      <dc:date>2012-08-11T10:29:52Z</dc:date>
    </item>
    <item>
      <title>Re: ELSTER and SSL decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/elster-and-ssl-decryption/m-p/31142#M22780</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is certainly a valid work around and you will most likely not be able to find a better or more granular one.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The self signed certificate is not the main problem here, it could be imported into the Palo Alto as a trusted CA.&lt;/P&gt;&lt;P&gt;However, the server ip-addresses seem to use the same certificate (same fingerprint, same s/n) with the common name 'Elster HTTPS-Servlet' which will always result into a failed verification due to 'hostname mismatch'. &lt;/P&gt;&lt;P&gt;Not enough, the certificate of www.elsterft.de is expired since Dec. 19. 2011 (as of today Aug. 11. 2012)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Even if you would be able to overcome all these issues the ssl decryption will most likely still fail, because the server requires a mutual certificate authentication.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Congratulation to the German tax authorities for this great implementation and the ISO 27001 certification.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 11 Aug 2012 19:00:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/elster-and-ssl-decryption/m-p/31142#M22780</guid>
      <dc:creator>panwmod</dc:creator>
      <dc:date>2012-08-11T19:00:35Z</dc:date>
    </item>
  </channel>
</rss>

