<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: About SHA1 when admin access Web-UI in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/about-sha1-when-admin-access-web-ui/m-p/70291#M40482</link>
    <description>&lt;P&gt;Hi syadav,&lt;/P&gt;
&lt;P&gt;Thanks for your comment.&lt;/P&gt;
&lt;P&gt;I have read a google blog page what you suggest.&lt;/P&gt;
&lt;P&gt;This blog mentioned the following,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV&gt;&lt;STRONG&gt;Step 2: Blocking all SHA-1 certificates&lt;/STRONG&gt;&lt;/DIV&gt;
&lt;DIV&gt;Starting January 1, 2017 at the latest, Chrome will completely stop supporting SHA-1 certificates. At this point, sites that have a SHA-1-based signature as part of the certificate chain (not including the self-signature on the root certificate) will trigger a fatal network error. This includes certificate chains that end in a local trust anchor as well as those that end at a public CA.&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The Issuer is localhost for certificate when accessing Web-UI.&lt;/P&gt;
&lt;P&gt;Chorme could not block SHA-1 certificate that issuer is localhost(self-generated) when accessing Web-UI after 2017. RIGHT?&lt;/P&gt;
&lt;P&gt;Do I understand correct it?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Tue, 05 Jan 2016 04:24:33 GMT</pubDate>
    <dc:creator>KiCheon.Lee</dc:creator>
    <dc:date>2016-01-05T04:24:33Z</dc:date>
    <item>
      <title>About SHA1 when admin access Web-UI</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/about-sha1-when-admin-access-web-ui/m-p/70164#M40464</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I knew SHA1&amp;nbsp;is going to be expired on all internet browser in 2016.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;All FWs of Paloalto are using SHA1 when access Web-UI.&lt;/P&gt;
&lt;P&gt;I think if PA keep using it on, administrator could not access Web-UI by browser bloking.&lt;/P&gt;
&lt;P&gt;So It has to change from SHA1 to SHA256.&lt;/P&gt;
&lt;P&gt;I just want to know plan when chainging it.&lt;/P&gt;
&lt;P&gt;Please someone let me know it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you do not have a plan for it.&lt;/P&gt;
&lt;P&gt;Do I have to make self-generated certificate with SHA256 and then enable "certificate for Secure Web GUI"?&lt;/P&gt;
&lt;P&gt;Is there another way?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;KC Lee&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 31 Dec 2015 06:35:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/about-sha1-when-admin-access-web-ui/m-p/70164#M40464</guid>
      <dc:creator>KiCheon.Lee</dc:creator>
      <dc:date>2015-12-31T06:35:01Z</dc:date>
    </item>
    <item>
      <title>Re: About SHA1 when admin access Web-UI</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/about-sha1-when-admin-access-web-ui/m-p/70216#M40472</link>
      <description>&lt;P&gt;Hi KC,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The deprecation of SHA-1 is completely browser dependent, though most of the major browsers (like firefox,chrome) are&lt;/P&gt;
&lt;P&gt;contemplating to completely block the pages secured through SHA1. Please look for official announcements from the organizations who develop these browsers to keep a track of the timeline.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Following is a good read :&lt;/P&gt;
&lt;P&gt;&lt;A href="https://googleonlinesecurity.blogspot.sg/" target="_blank"&gt;https://googleonlinesecurity.blogspot.sg/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As for PA ,WebGUI access or SSL decryption (forward-proxy) certificate, you can create a new certificate using a more secure&amp;nbsp;hashing algorithm like SHA-256 which is acceptable for the browser hence would not block or through error.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps !&lt;/P&gt;</description>
      <pubDate>Mon, 04 Jan 2016 14:04:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/about-sha1-when-admin-access-web-ui/m-p/70216#M40472</guid>
      <dc:creator>syadav</dc:creator>
      <dc:date>2016-01-04T14:04:05Z</dc:date>
    </item>
    <item>
      <title>Re: About SHA1 when admin access Web-UI</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/about-sha1-when-admin-access-web-ui/m-p/70291#M40482</link>
      <description>&lt;P&gt;Hi syadav,&lt;/P&gt;
&lt;P&gt;Thanks for your comment.&lt;/P&gt;
&lt;P&gt;I have read a google blog page what you suggest.&lt;/P&gt;
&lt;P&gt;This blog mentioned the following,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV&gt;&lt;STRONG&gt;Step 2: Blocking all SHA-1 certificates&lt;/STRONG&gt;&lt;/DIV&gt;
&lt;DIV&gt;Starting January 1, 2017 at the latest, Chrome will completely stop supporting SHA-1 certificates. At this point, sites that have a SHA-1-based signature as part of the certificate chain (not including the self-signature on the root certificate) will trigger a fatal network error. This includes certificate chains that end in a local trust anchor as well as those that end at a public CA.&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The Issuer is localhost for certificate when accessing Web-UI.&lt;/P&gt;
&lt;P&gt;Chorme could not block SHA-1 certificate that issuer is localhost(self-generated) when accessing Web-UI after 2017. RIGHT?&lt;/P&gt;
&lt;P&gt;Do I understand correct it?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jan 2016 04:24:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/about-sha1-when-admin-access-web-ui/m-p/70291#M40482</guid>
      <dc:creator>KiCheon.Lee</dc:creator>
      <dc:date>2016-01-05T04:24:33Z</dc:date>
    </item>
  </channel>
</rss>

