<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSL Decryption in PAN 4.1 fails - Firefox warns &amp;quot;ssl_error_rx_unexpected_new_session_ticket&amp;quot; in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-in-pan-4-1-fails-firefox-warns-quot-ssl-error-rx/m-p/362#M288</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Your device is obviously malfunctioning for some reason.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Did you file this as a bugreport and what did the support tell you?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A similar event regarding 2000-boxes and SSL was spring 2010 (3.0/3.1.something) where the SSL engine failed in mgmtplane which gave all sort of funny results (because the MITM cert is created on the fly by the mgmtplane and then cached in the dataplane if im not mistaken). That bug was fixed a few weeks later after being reported (and debugged).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 24 Sep 2012 09:22:46 GMT</pubDate>
    <dc:creator>mikand</dc:creator>
    <dc:date>2012-09-24T09:22:46Z</dc:date>
    <item>
      <title>SSL Decryption in PAN 4.1 fails - Firefox warns "ssl_error_rx_unexpected_new_session_ticket"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-in-pan-4-1-fails-firefox-warns-quot-ssl-error-rx/m-p/357#M283</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Since upgrading to Palo Alto Networks 4.1 we often have warnings in several firefox and thunderbird clients. &lt;/P&gt;&lt;P&gt;Then we get the error mesage "ssl_error_rx_unexpected_new_session_ticket". &lt;/P&gt;&lt;P&gt;This example is from thunderbird:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Warnung_2012-09-17_14-36-49.jpg" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/4048_Warnung_2012-09-17_14-36-49.jpg" width="450" /&gt;&lt;/P&gt;&lt;P&gt;Additionally the behaviour of the firewall to let some SSL communication undecrypted - for instance: on the first click &lt;A href="https://www.example.de/index.html" title="https://www.example.de/index.html"&gt;https://www.anyside.de/index.html&lt;/A&gt; will be decrypted, the second click on &lt;A href="https://www.example.de/index.html" title="https://www.example.de/index.html"&gt;https://www.anyside.de/anydoc.html&lt;/A&gt; will not - is a bit disturbing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;mfg&lt;/P&gt;&lt;P&gt;Manfred&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 17 Sep 2012 12:54:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-in-pan-4-1-fails-firefox-warns-quot-ssl-error-rx/m-p/357#M283</guid>
      <dc:creator>mhuels</dc:creator>
      <dc:date>2012-09-17T12:54:36Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption in PAN 4.1 fails - Firefox warns "ssl_error_rx_unexpected_new_session_ticket"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-in-pan-4-1-fails-firefox-warns-quot-ssl-error-rx/m-p/358#M284</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you try deleting the SSL decryption certificates on Paloalto and re-importing/regenerating them again and see if it makes any difference. My guess is that the SSL decryption certs might have got corrupted during the software upgrade.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 17 Sep 2012 17:07:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-in-pan-4-1-fails-firefox-warns-quot-ssl-error-rx/m-p/358#M284</guid>
      <dc:creator>sdurga</dc:creator>
      <dc:date>2012-09-17T17:07:41Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption in PAN 4.1 fails - Firefox warns "ssl_error_rx_unexpected_new_session_ticket"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-in-pan-4-1-fails-firefox-warns-quot-ssl-error-rx/m-p/359#M285</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi sdurga,&lt;/P&gt;&lt;P&gt;first i tried to disable device-&amp;gt;setup-&amp;gt;Server CRL/OCSP Settings.&lt;/P&gt;&lt;P&gt;&lt;IMG alt="mi1-pan1 - Mozilla Firefox_2012-09-19_16-03-41.jpg" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/4091_mi1-pan1 - Mozilla Firefox_2012-09-19_16-03-41.jpg" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;this works a bit. Now the SSL crypted websites will be mostly continuous decrypted.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With some rare exceptions: if we get an error message like this here&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Seiten-Ladefehler - Mozilla Firefox_2012-09-19_15-55-19.jpg" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/4092_Seiten-Ladefehler - Mozilla Firefox_2012-09-19_15-55-19.jpg" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i get an undecrypted website at next, if i click "Nochmals versuchen".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Next i will try your suggestion.&lt;/P&gt;&lt;P&gt;greets&lt;/P&gt;&lt;P&gt;Manfred&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Sep 2012 14:12:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-in-pan-4-1-fails-firefox-warns-quot-ssl-error-rx/m-p/359#M285</guid>
      <dc:creator>mhuels</dc:creator>
      <dc:date>2012-09-19T14:12:15Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption in PAN 4.1 fails - Firefox warns "ssl_error_rx_unexpected_new_session_ticket"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-in-pan-4-1-fails-firefox-warns-quot-ssl-error-rx/m-p/360#M286</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have reimported the certificate.&lt;/P&gt;&lt;P&gt;Unfortunately the problem is still going on. The SSL warning is not as usual as in the beginning, but it reappears frequently.&lt;/P&gt;&lt;P&gt;Guessing a performance problem with our hardware (PA 2050 from 2010), what can we do?&lt;/P&gt;&lt;P&gt;greets&lt;/P&gt;&lt;P&gt;Manfred &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Sep 2012 10:29:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-in-pan-4-1-fails-firefox-warns-quot-ssl-error-rx/m-p/360#M286</guid>
      <dc:creator>mhuels</dc:creator>
      <dc:date>2012-09-20T10:29:17Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption in PAN 4.1 fails - Firefox warns "ssl_error_rx_unexpected_new_session_ticket"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-in-pan-4-1-fails-firefox-warns-quot-ssl-error-rx/m-p/361#M287</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We can see another strange behaviour by the firewall, which shows in the same direction: &lt;/P&gt;&lt;P&gt;Especially if using the Firefox Browser will the third or fifth reload of a ssl-crypted website be undecrypted by the firewall.You simply have to click "reload" several times on any SSL Website. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Very strange behaviour by a security device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Manfred&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Sep 2012 09:11:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-in-pan-4-1-fails-firefox-warns-quot-ssl-error-rx/m-p/361#M287</guid>
      <dc:creator>mhuels</dc:creator>
      <dc:date>2012-09-24T09:11:15Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption in PAN 4.1 fails - Firefox warns "ssl_error_rx_unexpected_new_session_ticket"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-in-pan-4-1-fails-firefox-warns-quot-ssl-error-rx/m-p/362#M288</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Your device is obviously malfunctioning for some reason.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Did you file this as a bugreport and what did the support tell you?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A similar event regarding 2000-boxes and SSL was spring 2010 (3.0/3.1.something) where the SSL engine failed in mgmtplane which gave all sort of funny results (because the MITM cert is created on the fly by the mgmtplane and then cached in the dataplane if im not mistaken). That bug was fixed a few weeks later after being reported (and debugged).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Sep 2012 09:22:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-in-pan-4-1-fails-firefox-warns-quot-ssl-error-rx/m-p/362#M288</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-09-24T09:22:46Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption in PAN 4.1 fails - Firefox warns "ssl_error_rx_unexpected_new_session_ticket"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-in-pan-4-1-fails-firefox-warns-quot-ssl-error-rx/m-p/363#M289</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Till now, we didnt open a support request. But i will do so this morning.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Manfred&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Sep 2012 10:00:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-in-pan-4-1-fails-firefox-warns-quot-ssl-error-rx/m-p/363#M289</guid>
      <dc:creator>mhuels</dc:creator>
      <dc:date>2012-09-24T10:00:23Z</dc:date>
    </item>
  </channel>
</rss>

