<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FIPS mode algorithm decryption? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/fips-mode-algorithm-decryption/m-p/4343#M3209</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="color:#1F497D"&gt;For the SSL Decryption feature, in FIPS mode, we support the following cipher suites only:&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="color:#1F497D"&gt;RSA_&lt;/SPAN&gt; &lt;SPAN style="color:#1F497D"&gt;AES_256_CBC_SHA&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="color:#1F497D"&gt;RSA_AES_128_CBC_SHA&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="color:#1F497D"&gt;RSA_3DES_EDE_CBC_SHA&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="color:#1F497D"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="color:#1F497D"&gt;For normal mode, we support the above suites plus:&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="color:#1F497D"&gt;RSA_RC4_128_MD5&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="color:#1F497D"&gt;RSA_RC4_128_SHA&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 16 Aug 2011 00:28:32 GMT</pubDate>
    <dc:creator>SRA</dc:creator>
    <dc:date>2011-08-16T00:28:32Z</dc:date>
    <item>
      <title>FIPS mode algorithm decryption?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/fips-mode-algorithm-decryption/m-p/4342#M3208</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The FIPS Mode notes state:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"Non-FIPS approved algorithms are not decrypted and are thus ignored during decryption"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can someone clearify what exactly this applies to, and what is not decrypted?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Aug 2011 07:12:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/fips-mode-algorithm-decryption/m-p/4342#M3208</guid>
      <dc:creator>KatanaNZ</dc:creator>
      <dc:date>2011-08-11T07:12:43Z</dc:date>
    </item>
    <item>
      <title>Re: FIPS mode algorithm decryption?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/fips-mode-algorithm-decryption/m-p/4343#M3209</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="color:#1F497D"&gt;For the SSL Decryption feature, in FIPS mode, we support the following cipher suites only:&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="color:#1F497D"&gt;RSA_&lt;/SPAN&gt; &lt;SPAN style="color:#1F497D"&gt;AES_256_CBC_SHA&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="color:#1F497D"&gt;RSA_AES_128_CBC_SHA&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="color:#1F497D"&gt;RSA_3DES_EDE_CBC_SHA&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="color:#1F497D"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="color:#1F497D"&gt;For normal mode, we support the above suites plus:&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="color:#1F497D"&gt;RSA_RC4_128_MD5&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="color:#1F497D"&gt;RSA_RC4_128_SHA&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Aug 2011 00:28:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/fips-mode-algorithm-decryption/m-p/4343#M3209</guid>
      <dc:creator>SRA</dc:creator>
      <dc:date>2011-08-16T00:28:32Z</dc:date>
    </item>
    <item>
      <title>Re: FIPS mode algorithm decryption?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/fips-mode-algorithm-decryption/m-p/4344#M3210</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;From what i'm reading FIPS mode specifically disables a number of less secure algorithms from even being used.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So therefor to me its logical the system wont decrypt something that I haven't even had enabled, or configured within the box.&lt;/P&gt;&lt;P&gt;Is the statement about non-decryption of algorithms therefor a redundant one, or referring to something else ( that's what I'm trying to confirm )&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Aug 2011 01:30:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/fips-mode-algorithm-decryption/m-p/4344#M3210</guid>
      <dc:creator>KatanaNZ</dc:creator>
      <dc:date>2011-08-16T01:30:36Z</dc:date>
    </item>
    <item>
      <title>Re: FIPS mode algorithm decryption?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/fips-mode-algorithm-decryption/m-p/4345#M3211</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi KatanaNZ,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For SSL decryption of host traffic, the firewall will proxy the SSL connection between the host and the server.&amp;nbsp; This comment is just a notification that the list of algorithms that can be negotiated between the firewall and the server will be limited further in FIPS mode.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Nick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Aug 2011 00:24:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/fips-mode-algorithm-decryption/m-p/4345#M3211</guid>
      <dc:creator>ncampagna</dc:creator>
      <dc:date>2011-08-17T00:24:28Z</dc:date>
    </item>
    <item>
      <title>Re: FIPS mode algorithm decryption?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/fips-mode-algorithm-decryption/m-p/4346#M3212</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok, thanks for that Nick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Aug 2011 01:14:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/fips-mode-algorithm-decryption/m-p/4346#M3212</guid>
      <dc:creator>KatanaNZ</dc:creator>
      <dc:date>2011-08-17T01:14:17Z</dc:date>
    </item>
  </channel>
</rss>

