<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SSL Decryption - What categories do you decrypt? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-what-categories-do-you-decrypt/m-p/34599#M25390</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Right now we have a policy to never decrypt shopping and finance/banking sites, and we decrypt web based email and social networking.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I know there are issues with certain applications (Windows Update I believe?) if you try to decrypt so I wondered what your decryption/inspection policies are?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 27 Apr 2014 13:05:45 GMT</pubDate>
    <dc:creator>networkadmin</dc:creator>
    <dc:date>2014-04-27T13:05:45Z</dc:date>
    <item>
      <title>SSL Decryption - What categories do you decrypt?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-what-categories-do-you-decrypt/m-p/34599#M25390</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Right now we have a policy to never decrypt shopping and finance/banking sites, and we decrypt web based email and social networking.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I know there are issues with certain applications (Windows Update I believe?) if you try to decrypt so I wondered what your decryption/inspection policies are?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 27 Apr 2014 13:05:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-what-categories-do-you-decrypt/m-p/34599#M25390</guid>
      <dc:creator>networkadmin</dc:creator>
      <dc:date>2014-04-27T13:05:45Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption - What categories do you decrypt?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-what-categories-do-you-decrypt/m-p/34600#M25391</link>
      <description>&lt;P&gt;The tech note on configuring SSL decryption &lt;A href="https://live.paloaltonetworks.com/t5/ssl-decryption/ct-p/SSL_Decrypt" target="_self"&gt;Controlling SSL Decryption&lt;/A&gt; lists the default categories you should use as a start and some you should not.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You will always stumble on certain applications that don't cope well with SSL decryption, so you'll have to exclude those. Typical example is bank transaction software, they probably do extra checks on the certificate chain. Another very specific one is Java. Not because it's Java, but because it has its own certificate store (you'd have to import your intermediate CA separately if you have Java applications that use ssl).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But I wouldn't do exclusion on category level (you'll exclude way too much). Just do it per application, like the tech note says. We use a "decryption exception" rule that uses an address group (containing fqdn as well as ip address objects). Good application vendors will be able to supply you with a list of ip's and/or url's their application needs. If they don't you'll have to find out yourself (disable ssl decryption and monitor the logs).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Only way to find out is enabling SSL decryption, so be ready to take some time troubleshooting.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Jun 2023 15:55:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-what-categories-do-you-decrypt/m-p/34600#M25391</guid>
      <dc:creator>dieter_b</dc:creator>
      <dc:date>2023-06-26T15:55:22Z</dc:date>
    </item>
  </channel>
</rss>

