<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSL decryption and Http redirection in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-and-http-redirection/m-p/33303#M24387</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;can you tell me the reason ?&lt;/P&gt;&lt;P&gt;thank you&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 16 May 2012 14:39:58 GMT</pubDate>
    <dc:creator>minow</dc:creator>
    <dc:date>2012-05-16T14:39:58Z</dc:date>
    <item>
      <title>SSL decryption and Http redirection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-and-http-redirection/m-p/33295#M24379</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I am testing SSL decryption and it seems to work fine&amp;nbsp; except when Http redirection is involved. E.g. when you try to connect to Https://gmail.com , google redirects you to &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://www.google.com"&gt;https://www.google.com&lt;/A&gt;&lt;SPAN&gt; and it gives me a certificate error because of the hostname in the cert does (www.google.com in this case)not match with the hostname that you are connecting to (gmail.com originally).&amp;nbsp; Is there some way of working around this ? I am using PANOS 4.0.4.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sunil&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Aug 2011 14:26:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-and-http-redirection/m-p/33295#M24379</guid>
      <dc:creator>sunilsadanandan</dc:creator>
      <dc:date>2011-08-26T14:26:08Z</dc:date>
    </item>
    <item>
      <title>Re: SSL decryption and Http redirection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-and-http-redirection/m-p/33296#M24380</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Sunil,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have you tried to access other SSL site? Do you see the cert error?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Even you have been redirected from gmail to &lt;A href="http://www.google.com/mail"&gt;www.google.com/mail&lt;/A&gt;, our device should self-signed another SSL cert in realtime. I wonder if actually the error will show up even you are accessing other SSL site with SSL decryption enabled as well.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Aug 2011 16:38:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-and-http-redirection/m-p/33296#M24380</guid>
      <dc:creator>jleung</dc:creator>
      <dc:date>2011-08-30T16:38:56Z</dc:date>
    </item>
    <item>
      <title>Re: SSL decryption and Http redirection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-and-http-redirection/m-p/33297#M24381</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I agree sounds like your firewall certificate isn't trusted&amp;nbsp; If certificates are working should see no error&amp;nbsp;&amp;nbsp; Another example is going to bankofamerica.com will will redirect to www and redirect to https&amp;nbsp; Remember with new browsers they also don't like device self signed certificates and you will likely need a pki or 3rd party&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Aug 2011 16:43:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-and-http-redirection/m-p/33297#M24381</guid>
      <dc:creator>kkeeton</dc:creator>
      <dc:date>2011-08-30T16:43:28Z</dc:date>
    </item>
    <item>
      <title>Re: SSL decryption and Http redirection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-and-http-redirection/m-p/33298#M24382</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;A class="active_link" href="https://live.paloaltonetworks.com/people/jleung" id="jive-281826,483,380,761,392,334" style="text-decoration: none; color: #555555; font-weight: bold;"&gt;jleung&lt;/A&gt;,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks for the response , I do not get the error when I access the other SSL webpages e.g. &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://facebook.com"&gt;https://facebook.com&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://twitter.com"&gt;https://twitter.com&lt;/A&gt;&lt;SPAN&gt;, the firewall sigins and I can see it in the details. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The error on IE is as follows when I connect to Https://gmail.com&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV id="CertCNMismatch" style="display:block"&gt;The security&amp;nbsp; certificate presented by this website was issued for a different website's&amp;nbsp; address.&lt;/DIV&gt;&lt;P id="CertRevoked"&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The following article says that 3rd party certs cannot be used.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="active_link" href="https://live.paloaltonetworks.com/message/7870"&gt;https://live.paloaltonetworks.com/message/7870&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sunil &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Aug 2011 16:58:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-and-http-redirection/m-p/33298#M24382</guid>
      <dc:creator>sunilsadanandan</dc:creator>
      <dc:date>2011-08-30T16:58:50Z</dc:date>
    </item>
    <item>
      <title>Re: SSL decryption and Http redirection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-and-http-redirection/m-p/33299#M24383</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Sunil,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think there maybe something wrong with your cert setting.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For SSL decryption to work, our box need to have either an imported or self generated CA cert. For 4.0.x, you need to go to device -&amp;gt; certificate to generate one. When you generate it, remember to check the box "certificate authority". After that please click on the cert that you have just created and choose "forward trust certificate". Make sure you have chosen "SSL forward proxy" in the option field of the decryption policy. Commit your change.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now if you go to any of the HTTPS website, you should always see the cert error from the browser, and when click on the cert, you should see it is issued by the PA box.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Remember that we need a CA cert for SSL decryption to function, so that we can always enumerate the original website SSL cert on the fly. It doesn't bind to any websites. The browser will always show the error prompt though the cert cn name and expiry date are valid and matched, because the SSL cert is issued/signed by our box rather than any of the trust CA by Windows/MAC OS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you don't want to see the error prompt, you could leverage AD to install all the certs to your corporate PCs, or leverage your corporate CA server (if there is one) to create a subordinate CA cert and import it to PA box.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Using 3rd party signed cert (e.g. bought one from Verisign) can never help you, as those 3rd parties are selling you site cert but not CA cert. And we need CA cert which can sign certs.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Sep 2011 16:05:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-and-http-redirection/m-p/33299#M24383</guid>
      <dc:creator>jleung</dc:creator>
      <dc:date>2011-09-01T16:05:10Z</dc:date>
    </item>
    <item>
      <title>Re: SSL decryption and Http redirection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-and-http-redirection/m-p/33300#M24384</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Sunil did you ever find out the answer to your question?&lt;/P&gt;&lt;P&gt;I'm running into the same issue on a project I'm working on due to a coworkers temporary incapacitation. If it go to &lt;A href="https://www.gmail.com/"&gt;https://www.gmail.com&lt;/A&gt; I will get an error saying The security certificate presented by this website was issued for a different website’s address. If I view the certificate I see that by my PA-2020(which is a trusted root) however the certificate has been issued to mail.google.com hence the error because the browser is expecting to see a certificate for &lt;A href="http://www.gmail.com"&gt;www.gmail.com&lt;/A&gt;. Figured I'd check the forums before opening a case&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 31 Oct 2011 21:19:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-and-http-redirection/m-p/33300#M24384</guid>
      <dc:creator>mike_in_redding</dc:creator>
      <dc:date>2011-10-31T21:19:00Z</dc:date>
    </item>
    <item>
      <title>Re: SSL decryption and Http redirection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-and-http-redirection/m-p/33301#M24385</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;did you solved this issue?&lt;/P&gt;&lt;P&gt;we are running 4.1.6 and have simmilar poblems with gmail when it is redirected to the https url&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 May 2012 10:22:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-and-http-redirection/m-p/33301#M24385</guid>
      <dc:creator>minow</dc:creator>
      <dc:date>2012-05-16T10:22:55Z</dc:date>
    </item>
    <item>
      <title>Re: SSL decryption and Http redirection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-and-http-redirection/m-p/33302#M24386</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN&gt;SSL decryption has been running fine for most website but it's true &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://www.gmail.com"&gt;https://www.gmail.com&lt;/A&gt;&lt;SPAN&gt; is one of the few that is creating troubles.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 May 2012 13:36:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-and-http-redirection/m-p/33302#M24386</guid>
      <dc:creator>essnet</dc:creator>
      <dc:date>2012-05-16T13:36:24Z</dc:date>
    </item>
    <item>
      <title>Re: SSL decryption and Http redirection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-and-http-redirection/m-p/33303#M24387</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;can you tell me the reason ?&lt;/P&gt;&lt;P&gt;thank you&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 May 2012 14:39:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-and-http-redirection/m-p/33303#M24387</guid>
      <dc:creator>minow</dc:creator>
      <dc:date>2012-05-16T14:39:58Z</dc:date>
    </item>
    <item>
      <title>Re: SSL decryption and Http redirection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-and-http-redirection/m-p/33304#M24388</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;My opinion is the following : www.gmail.com is hosted on same server than www.google.com , to achieve that Google didn't create (for once) a multi SAN SSL certificate but relies on TLSv1 feature that allows Client and Server to negociate which certificate to use.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If client asks for www.gmail.com, Server will present gmail.com certificate, if Client asks mail.google.com during TLS negociation then Server will present mail.google.com certificate.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As PA seems to fails explicitly on those I have several theories:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;PA doesn't support TLS certificate negociation when you ask it to decrypt so it will fallback to default presented certificate: mail.google.com.&lt;/LI&gt;&lt;LI&gt;PA caches which certificate is associated to an IP (for performance benefits) and will reuse it next time you connect, whatever you are trying to negociate (until cache expires)&lt;/LI&gt;&lt;LI&gt;A mix of the above theories.&lt;/LI&gt;&lt;/UL&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 May 2012 15:02:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-and-http-redirection/m-p/33304#M24388</guid>
      <dc:creator>essnet</dc:creator>
      <dc:date>2012-05-16T15:02:27Z</dc:date>
    </item>
    <item>
      <title>Re: SSL decryption and Http redirection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-and-http-redirection/m-p/33305#M24389</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Today PAN Support confirmed me in a ticket : SSL decryption doesn't support SSLv3/TLSv1 fully : they clear original client HELLO packet to replace all values by their owns ones.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; They even asked me to open a Feature Request... I hope it's the kind of ones they can implement "FAST" because I am relying a lot on Decryption which is a major feature that makes PAN ahead of others.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 May 2012 07:08:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-and-http-redirection/m-p/33305#M24389</guid>
      <dc:creator>essnet</dc:creator>
      <dc:date>2012-05-30T07:08:57Z</dc:date>
    </item>
  </channel>
</rss>

