<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SSL Decryption - log for SSL certificate errors? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-log-for-ssl-certificate-errors/m-p/69224#M40214</link>
    <description>&lt;P&gt;Hi all,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We are using PANOS URL Filtering and SSL Decryption, and we reject a variety of SSL certificate problems such as expired certificates, SHA-1 signing, etc.&amp;nbsp; When one of our users hits one of these web sites, they get a "block" page.&amp;nbsp; This invariably leads them to submit a request to have the site unblocked, without any additional information.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have been unable to find any log on the Monitor tab of the firewall console that will give us the reason why the certificate was rejected.&amp;nbsp; At most we get traffic logs with "aged-out."&amp;nbsp; Is this information being collected by PANOS?&amp;nbsp; Is it available anywhere in the console?&amp;nbsp; How do other people diagnose these blocks?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;- Steve&lt;/P&gt;</description>
    <pubDate>Tue, 08 Dec 2015 21:34:43 GMT</pubDate>
    <dc:creator>RSKadish</dc:creator>
    <dc:date>2015-12-08T21:34:43Z</dc:date>
    <item>
      <title>SSL Decryption - log for SSL certificate errors?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-log-for-ssl-certificate-errors/m-p/69224#M40214</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We are using PANOS URL Filtering and SSL Decryption, and we reject a variety of SSL certificate problems such as expired certificates, SHA-1 signing, etc.&amp;nbsp; When one of our users hits one of these web sites, they get a "block" page.&amp;nbsp; This invariably leads them to submit a request to have the site unblocked, without any additional information.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have been unable to find any log on the Monitor tab of the firewall console that will give us the reason why the certificate was rejected.&amp;nbsp; At most we get traffic logs with "aged-out."&amp;nbsp; Is this information being collected by PANOS?&amp;nbsp; Is it available anywhere in the console?&amp;nbsp; How do other people diagnose these blocks?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;- Steve&lt;/P&gt;</description>
      <pubDate>Tue, 08 Dec 2015 21:34:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-log-for-ssl-certificate-errors/m-p/69224#M40214</guid>
      <dc:creator>RSKadish</dc:creator>
      <dc:date>2015-12-08T21:34:43Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption - log for SSL certificate errors?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-log-for-ssl-certificate-errors/m-p/69246#M40225</link>
      <description>&lt;P&gt;Try this:&lt;/P&gt;
&lt;P&gt;show system setting ssl-decrypt exclude-cache&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;or&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;show counter global filter delta yes | match ssl_sess_id_resume_drop&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here is a link with even more detail which may be helpful, though not as helpful as just adding this in the traffic log detail, which unfortuneately is not currently a supported feature. Reach out to you sales engineer and request this be added as a feature in a future release.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/SSL-Decryption-Not-Working-due-to-Unsupported-Cipher-Suites/ta-p/55543" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/SSL-Decryption-Not-Working-due-to-Unsupported-Cipher-Suites/ta-p/55543&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Dec 2015 07:22:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-log-for-ssl-certificate-errors/m-p/69246#M40225</guid>
      <dc:creator>jpeters</dc:creator>
      <dc:date>2015-12-09T07:22:09Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption - log for SSL certificate errors?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-log-for-ssl-certificate-errors/m-p/69258#M40235</link>
      <description>&lt;P&gt;Palo does provide a response page for SOME cert issues:&lt;BR /&gt;&lt;BR /&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/1555iEAD3556BCE18CE4D/image-size/original?v=mpbl-1&amp;amp;px=-1" border="0" alt="SSL_Error.JPG" title="SSL_Error.JPG" /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Specifically for things like an expired certificate I've seen this page come up. &amp;nbsp;However for things like certificate negotiation issues I've only ever seen a "Page Can't Be Displayed" browser page. &amp;nbsp;The only way I've found to diagnose the issue is to perform a packet capture. &amp;nbsp;Doing this you can see a "Fatal Certificate Error" in the SSL/TLS negotiation.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When things like the later occur it's very frustating because for one users tend to think there's a problem with a distant end...and/or when the ticket comes to a less experienced technician they don't even think about certificate issues and performing such in-depth analysis.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Dec 2015 14:48:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-log-for-ssl-certificate-errors/m-p/69258#M40235</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2015-12-09T14:48:37Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption - log for SSL certificate errors?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-log-for-ssl-certificate-errors/m-p/69263#M40239</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks to both of you for the suggestions.&amp;nbsp; I did reach out to our sales engineer to request the log as a feature.&amp;nbsp; A custom response page is probably going to be our best bet.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;- Steve&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Dec 2015 15:48:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-log-for-ssl-certificate-errors/m-p/69263#M40239</guid>
      <dc:creator>RSKadish</dc:creator>
      <dc:date>2015-12-09T15:48:46Z</dc:date>
    </item>
  </channel>
</rss>

