<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSL decryption issues with latest Firefox in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-issues-with-latest-firefox/m-p/31771#M23237</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN&gt;This issue still exists in PAN-OS 7.0.0 and Firefox v39. I tried opening &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://support.office.com/" rel="nofollow"&gt;https://support.office.com&lt;/A&gt;&lt;SPAN&gt; and the firewall responsds with a FIN,ACK immediately:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="20251" alt="PA_SSL_Issue .png" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/20251_PA_SSL_Issue .png" style="height: 426px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The internal Root-CA certificate is imported to the Firefox Trusted CA store. The issue doesn't appear when loading the page with IE11 or Chrome43.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 06 Jul 2015 12:34:57 GMT</pubDate>
    <dc:creator>oschuler</dc:creator>
    <dc:date>2015-07-06T12:34:57Z</dc:date>
    <item>
      <title>SSL decryption issues with latest Firefox</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-issues-with-latest-firefox/m-p/31757#M23223</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm having SSL decryption issues with the latest versions of Firefox.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In Firefox i get following error when visiting a https site:&lt;/P&gt;&lt;P&gt;Secure Connection Failed&lt;/P&gt;&lt;P&gt;An error occurred during a connection to live.paloaltonetworks.com. security library:&lt;STRONG&gt; improperly formatted DER-encoded message. (Error code: sec_error_bad_der)&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; The page you are trying to view cannot be shown because the authenticity of the received data could not be verified.&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Please contact the web site owners to inform them of this problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Seems to be related to how Firefox handles certificates, requiring them to be more secure (number of bits and encryption algorithm), but I haven't found the exact requirements yet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can generate and deploy a new certificate, but I'm not sure what will give me one Firefox will accept.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any thoughts ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 May 2015 18:38:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-issues-with-latest-firefox/m-p/31757#M23223</guid>
      <dc:creator>dieter_b</dc:creator>
      <dc:date>2015-05-20T18:38:48Z</dc:date>
    </item>
    <item>
      <title>Re: SSL decryption issues with latest Firefox</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-issues-with-latest-firefox/m-p/31758#M23224</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Also seems related to the Issuer CN in the certificate (see &lt;A href="https://bugzilla.mozilla.org/show_bug.cgi?id=1153204#c2" title="https://bugzilla.mozilla.org/show_bug.cgi?id=1153204#c2"&gt;1153204 – Firefox doesn't connect to https://www.deutschepost.de/ because its issuer certificate contains invalid dNSNam…&lt;/A&gt; )&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In our case it contains the IP adres of the firewall, where Firefox seems to expect a dns name.&lt;/P&gt;&lt;P&gt;I have not been able to confirm this yet...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 May 2015 09:44:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-issues-with-latest-firefox/m-p/31758#M23224</guid>
      <dc:creator>dieter_b</dc:creator>
      <dc:date>2015-05-21T09:44:45Z</dc:date>
    </item>
    <item>
      <title>Re: SSL decryption issues with latest Firefox</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-issues-with-latest-firefox/m-p/31759#M23225</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Does this happen with all https URLs?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 May 2015 14:27:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-issues-with-latest-firefox/m-p/31759#M23225</guid>
      <dc:creator>aabdelhali</dc:creator>
      <dc:date>2015-05-21T14:27:04Z</dc:date>
    </item>
    <item>
      <title>Re: SSL decryption issues with latest Firefox</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-issues-with-latest-firefox/m-p/31760#M23226</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;All url categories that require decryption, yes. So the error definitely relates to the decryption certificate (and not the websites I'm trying to visit).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 May 2015 14:50:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-issues-with-latest-firefox/m-p/31760#M23226</guid>
      <dc:creator>dieter_b</dc:creator>
      <dc:date>2015-05-21T14:50:48Z</dc:date>
    </item>
    <item>
      <title>Re: SSL decryption issues with latest Firefox</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-issues-with-latest-firefox/m-p/31761#M23227</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Dieterb,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;was your issue solved? if not, would be useful if you can write the Firefox version and the CA certificate information.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 25 May 2015 19:27:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-issues-with-latest-firefox/m-p/31761#M23227</guid>
      <dc:creator>GLastra</dc:creator>
      <dc:date>2015-05-25T19:27:03Z</dc:date>
    </item>
    <item>
      <title>Re: SSL decryption issues with latest Firefox</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-issues-with-latest-firefox/m-p/31762#M23228</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Firefox 38.&lt;/P&gt;&lt;P&gt;Firefox 37 and earlier are not affected.&lt;/P&gt;&lt;P&gt;I have not tried a newer beta yet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Certificate is one generated with PA. It only contains a handful of default attributes (organization, email ...).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Replacing the IP with a valid dns entry did not resolve the issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One would call it a Firefox issue... But I guess it's the way the PA generates the certificate. Would be good to know if this issue is resolved with newer PANOS version or to have a workaround.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 May 2015 10:05:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-issues-with-latest-firefox/m-p/31762#M23228</guid>
      <dc:creator>dieter_b</dc:creator>
      <dc:date>2015-05-26T10:05:05Z</dc:date>
    </item>
    <item>
      <title>Re: SSL decryption issues with latest Firefox</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-issues-with-latest-firefox/m-p/31763#M23229</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What version of Pan-OS are you using?&lt;/P&gt;&lt;P&gt;Also, does Chrome or Internet Explorer show the same error while the firewall is attempting to decrypt it?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 May 2015 18:38:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-issues-with-latest-firefox/m-p/31763#M23229</guid>
      <dc:creator>jdelio</dc:creator>
      <dc:date>2015-05-26T18:38:47Z</dc:date>
    </item>
    <item>
      <title>Re: SSL decryption issues with latest Firefox</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-issues-with-latest-firefox/m-p/31764#M23230</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN&gt;It doesn't seem to affect IE or Chrome, but as of Firefox 38.01 we are also seeing the issue. Specifically for us its affecting &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://accounts.google.com" rel="nofollow"&gt;https://accounts.google.com&lt;/A&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://bugzilla.mozilla.org/show_bug.cgi?id=1148766" style="font-size: 10pt; line-height: 1.5em;" title="https://bugzilla.mozilla.org/show_bug.cgi?id=1148766"&gt;https://bugzilla.mozilla.org/show_bug.cgi?id=1148766&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 May 2015 21:36:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-issues-with-latest-firefox/m-p/31764#M23230</guid>
      <dc:creator>TheDave</dc:creator>
      <dc:date>2015-05-26T21:36:24Z</dc:date>
    </item>
    <item>
      <title>Re: SSL decryption issues with latest Firefox</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-issues-with-latest-firefox/m-p/31765#M23231</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We are on 5.0.11&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 May 2015 06:04:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-issues-with-latest-firefox/m-p/31765#M23231</guid>
      <dc:creator>dieter_b</dc:creator>
      <dc:date>2015-05-27T06:04:01Z</dc:date>
    </item>
    <item>
      <title>Re: SSL decryption issues with latest Firefox</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-issues-with-latest-firefox/m-p/31766#M23232</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I bet you are correct, that this is happening due to Firefox handing the security/certificates differently than IE and Chrome. &lt;/P&gt;&lt;P&gt;This also has to deal with how PAN is decrypting and encrypting the traffic differently than what Firefox is expecting, thus causing this issue.&lt;/P&gt;&lt;P&gt;I would recommend opening a case with TAC - PAN Support, if you do not already have one to get this addressed.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 May 2015 14:41:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-issues-with-latest-firefox/m-p/31766#M23232</guid>
      <dc:creator>jdelio</dc:creator>
      <dc:date>2015-05-27T14:41:32Z</dc:date>
    </item>
    <item>
      <title>Re: SSL decryption issues with latest Firefox</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-issues-with-latest-firefox/m-p/31767#M23233</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Take a look at &lt;A href="https://bugzilla.mozilla.org/show_bug.cgi?id=1166216" title="https://bugzilla.mozilla.org/show_bug.cgi?id=1166216"&gt;1166216 – FF38, Secure Connection Failed (sec_error_bad_der) on internal certificates&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Quote from &lt;SPAN class="bz_comment_user"&gt;&amp;nbsp;&amp;nbsp; &lt;SPAN class="vcard_349244 vcard"&gt;&lt;SPAN class="fn"&gt;David Keeler&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&amp;nbsp; &lt;/P&gt;&lt;PRE class="bz_comment_text"&gt;One common issue appears to be the encoding of the RSA modulus. If the highest bit of an integer is set, the proper DER encoding requires a leading zero byte to indicate that the integer is a positive value, not negative.&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This actually seems to confirm that PA generated certificates are faulty.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have opened a case with our reseller. They are now trying to recreate the issue. If they can recreate, they will escalate to Palo Alto support.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 May 2015 14:48:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-issues-with-latest-firefox/m-p/31767#M23233</guid>
      <dc:creator>dieter_b</dc:creator>
      <dc:date>2015-05-27T14:48:02Z</dc:date>
    </item>
    <item>
      <title>Re: SSL decryption issues with latest Firefox</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-issues-with-latest-firefox/m-p/31768#M23234</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This issue isn't present on 6.0.9 or 6.1.4.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I opened a case with PAN Support while we were on 5.0.14 and had this issue, and all they kept coming back to me was that 5.0.X doesn't support TLS1.2 and sent me to a link of their support cipher pages. I told them it wasn't related to that as I forced Firefox to only use TLS1.1 and disabled the unsupported ciphers and was still getting the same problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was getting no where.&amp;nbsp; In the end, we needed to move to 6.x anyway to use some of the new features.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Jun 2015 08:18:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-issues-with-latest-firefox/m-p/31768#M23234</guid>
      <dc:creator>eugenep</dc:creator>
      <dc:date>2015-06-02T08:18:55Z</dc:date>
    </item>
    <item>
      <title>Re: SSL decryption issues with latest Firefox</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-issues-with-latest-firefox/m-p/31769#M23235</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I went trough the bugfixes and found these that may be related:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Release notes 6.0.7: 66635 Enabling SSL Forward Proxy decryption with a self-signed certificate could sometimes cause the certificate presented to the client to have a negative serial number, causing an error on the client.&lt;/LI&gt;&lt;LI&gt;6.0.3: 61696 When using SSL Forward Proxy decryption with self-signed certificates with Firefox, an error was seen from Firefox regarding conflicting certificate serial numbers: sec_error_reused_issuer_and_serial.&lt;/LI&gt;&lt;LI&gt;6.0.0: 59030 Certificates generated during SSL decryption were not adhering to the ASN.1 format. This was leading to the SSL connection being dropped by some servers.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Especially the last one...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Upgrade to 6.0.10 is planned next week, so fingers crossed.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Jun 2015 07:15:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-issues-with-latest-firefox/m-p/31769#M23235</guid>
      <dc:creator>dieter_b</dc:creator>
      <dc:date>2015-06-05T07:15:44Z</dc:date>
    </item>
    <item>
      <title>Re: SSL decryption issues with latest Firefox</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-issues-with-latest-firefox/m-p/31770#M23236</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;With the upgrade and after generating completely new certificates (root CA and client certificate are self signed in our case; server certificate is a public one), the issue seems to be resolved.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Our reseller helpdesk however did not confirm if it had anything to do with the listed bugfixes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We still have issues with certain https websites, where Firefox throws the error&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Secure Connection Failed&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;The connection to the server was reset while the page was loading.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; The page you are trying to view cannot be shown because the authenticity of the received data could not be verified.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Please contact the website owners to inform them of this problem.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Example url: &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://support.office.com/" rel="nofollow"&gt;https://support.office.com/&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Jun 2015 08:27:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-issues-with-latest-firefox/m-p/31770#M23236</guid>
      <dc:creator>dieter_b</dc:creator>
      <dc:date>2015-06-12T08:27:02Z</dc:date>
    </item>
    <item>
      <title>Re: SSL decryption issues with latest Firefox</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-issues-with-latest-firefox/m-p/31771#M23237</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN&gt;This issue still exists in PAN-OS 7.0.0 and Firefox v39. I tried opening &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://support.office.com/" rel="nofollow"&gt;https://support.office.com&lt;/A&gt;&lt;SPAN&gt; and the firewall responsds with a FIN,ACK immediately:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="20251" alt="PA_SSL_Issue .png" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/20251_PA_SSL_Issue .png" style="height: 426px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The internal Root-CA certificate is imported to the Firefox Trusted CA store. The issue doesn't appear when loading the page with IE11 or Chrome43.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Jul 2015 12:34:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-issues-with-latest-firefox/m-p/31771#M23237</guid>
      <dc:creator>oschuler</dc:creator>
      <dc:date>2015-07-06T12:34:57Z</dc:date>
    </item>
    <item>
      <title>Re: SSL decryption issues with latest Firefox</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-issues-with-latest-firefox/m-p/31772#M23238</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;how is your decryption certificate encrypted ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;edit: let me clarify&lt;/P&gt;&lt;P&gt;I've been told since 6.1.4 you can encrypt the cert with &lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri','sans-serif';"&gt;AES256 and that should solve the Firefox issue.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri','sans-serif';"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri','sans-serif';"&gt;But you'd have to generate a new cert of course.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Jul 2015 12:38:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-issues-with-latest-firefox/m-p/31772#M23238</guid>
      <dc:creator>dieter_b</dc:creator>
      <dc:date>2015-07-06T12:38:08Z</dc:date>
    </item>
    <item>
      <title>Re: SSL decryption issues with latest Firefox</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-issues-with-latest-firefox/m-p/71844#M40951</link>
      <description>&lt;P&gt;Has this been verified?&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jan 2016 14:44:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-issues-with-latest-firefox/m-p/71844#M40951</guid>
      <dc:creator>hvcomputech</dc:creator>
      <dc:date>2016-01-29T14:44:55Z</dc:date>
    </item>
    <item>
      <title>Re: SSL decryption issues with latest Firefox</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-issues-with-latest-firefox/m-p/73251#M41376</link>
      <description>&lt;P&gt;I've been on 6.1.7 for a while now. Been testing internally with newly generated certificate. So far I have not encountered the issue anymore in FF.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But PA support also said another fix was made in 6.1.8, issue id 81830.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'll upgrade to 6.1.9 soon. If problem stays away, I'll re-enable decryption for our users.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Feb 2016 14:21:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-issues-with-latest-firefox/m-p/73251#M41376</guid>
      <dc:creator>dieter_b</dc:creator>
      <dc:date>2016-02-22T14:21:30Z</dc:date>
    </item>
  </channel>
</rss>

