<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SSL Decryption in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption/m-p/77828#M42724</link>
    <description>&lt;P&gt;We do SSL Decryption on our PA.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Recently we have been seeing a lot of sites that do not decrypt&lt;/P&gt;
&lt;P&gt;Chrome comes up with &lt;SPAN style="color: #222222; font-family: Roboto, Arial, sans-serif; font-size: 13px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 1; word-spacing: 0px; -webkit-text-stroke-width: 0px; display: inline !important; float: none; background-color: #ffffff;"&gt;&lt;SPAN style="font-size: 10.0pt; font-family: 'Arial','sans-serif'; color: #222222; background: white;"&gt;ERR_SSL_FALLBACK_BEYOND_&lt;/SPAN&gt;&lt;WBR style="color: #222222; font-family: Roboto, Arial, sans-serif; font-size: 13px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 1; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: #ffffff;" /&gt;&lt;SPAN style="color: #222222; font-family: Roboto, Arial, sans-serif; font-size: 13px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 1; word-spacing: 0px; -webkit-text-stroke-width: 0px; display: inline !important; float: none; background-color: #ffffff;"&gt;MINIMUM_VERSION&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Firefox does not have any meaning full error message&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;A quick google shows that it is to do with disabling of SSL v3.&lt;/P&gt;
&lt;P&gt;When the site is added to no decryption policy it works, so obviously the issue is to do with SSL Decryption&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But I do not understand what is forcing the browser back to SSL v3.&lt;/P&gt;
&lt;P&gt;Can anyone please point me in the right direction. Is it the SSL cert that is installed on the PA ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 10 May 2016 16:10:40 GMT</pubDate>
    <dc:creator>RC-BHF</dc:creator>
    <dc:date>2016-05-10T16:10:40Z</dc:date>
    <item>
      <title>SSL Decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption/m-p/77828#M42724</link>
      <description>&lt;P&gt;We do SSL Decryption on our PA.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Recently we have been seeing a lot of sites that do not decrypt&lt;/P&gt;
&lt;P&gt;Chrome comes up with &lt;SPAN style="color: #222222; font-family: Roboto, Arial, sans-serif; font-size: 13px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 1; word-spacing: 0px; -webkit-text-stroke-width: 0px; display: inline !important; float: none; background-color: #ffffff;"&gt;&lt;SPAN style="font-size: 10.0pt; font-family: 'Arial','sans-serif'; color: #222222; background: white;"&gt;ERR_SSL_FALLBACK_BEYOND_&lt;/SPAN&gt;&lt;WBR style="color: #222222; font-family: Roboto, Arial, sans-serif; font-size: 13px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 1; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: #ffffff;" /&gt;&lt;SPAN style="color: #222222; font-family: Roboto, Arial, sans-serif; font-size: 13px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 1; word-spacing: 0px; -webkit-text-stroke-width: 0px; display: inline !important; float: none; background-color: #ffffff;"&gt;MINIMUM_VERSION&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Firefox does not have any meaning full error message&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;A quick google shows that it is to do with disabling of SSL v3.&lt;/P&gt;
&lt;P&gt;When the site is added to no decryption policy it works, so obviously the issue is to do with SSL Decryption&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But I do not understand what is forcing the browser back to SSL v3.&lt;/P&gt;
&lt;P&gt;Can anyone please point me in the right direction. Is it the SSL cert that is installed on the PA ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 10 May 2016 16:10:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption/m-p/77828#M42724</guid>
      <dc:creator>RC-BHF</dc:creator>
      <dc:date>2016-05-10T16:10:40Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption/m-p/77844#M42728</link>
      <description>&lt;P&gt;If I had to guess, you're probably running PAN-OS 7.0 or older, so the list of ciphers supported by the decryption is limited to lower security ciphers (nothing using DHE or EC). If I'm wrong about the OS version, you can discard the rest of this message because I have no idea other than that.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If the site you're going to only supports high-encryption ciphers within TLS 1.0 and greater, the only option left to the firewall's decryption mechanism is to use SSLv3. Since SSLv3 is pretty much not supported by most current browsers unless you force it the error you see will happen (it can't negotiate any ciphers that it has in TLS, and the downgrade to SSLv3 fails).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;PAN-OS 7.1 introduces a huge amount of additional ciphers within SSL forward decryption. If you are unable to upgrade to 7.1 yet, the only options would be to block the site or exclude it from your decryption policy.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best regards,&lt;/P&gt;
&lt;P&gt;Greg Wesson&lt;/P&gt;</description>
      <pubDate>Tue, 10 May 2016 18:20:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption/m-p/77844#M42728</guid>
      <dc:creator>gwesson</dc:creator>
      <dc:date>2016-05-10T18:20:53Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption/m-p/77914#M42746</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I had a feeling it might be do with the PANOS , we run 6.1.x.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have been holding off upgrading to 7.x since there were a lot of discussion on this forum about SSL Decryption bugs related to the PAN OS 7&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Anyone else running PAN OS 6.x having these issues.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 11 May 2016 08:32:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption/m-p/77914#M42746</guid>
      <dc:creator>RC-BHF</dc:creator>
      <dc:date>2016-05-11T08:32:43Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption/m-p/77916#M42748</link>
      <description>&lt;P&gt;We have the same issue (PAN-OS&amp;nbsp;&lt;SPAN&gt;6.1.7)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Problem statrted in the last few days, after Chrome got an update to a&amp;nbsp;new v&lt;SPAN&gt;ersion: 50.0.2661.94&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I tried to create a new certificate but it didn't solve the problem.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I understand that the only way to address this issue is to upgrade to 7.1.* ?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="11.jpg" style="width: 600px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/4000iACEAF956D66BE50F/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="11.jpg" alt="11.jpg" /&gt;&lt;/span&gt;﻿&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 11 May 2016 09:29:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption/m-p/77916#M42748</guid>
      <dc:creator>iChen78</dc:creator>
      <dc:date>2016-05-11T09:29:41Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption/m-p/77925#M42751</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/32033"&gt;@RC-BHF﻿&lt;/a&gt;&amp;nbsp;as&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/28203"&gt;@gwesson﻿&lt;/a&gt;&amp;nbsp;stated it's because the PAN-OS version you're running doesn't support the cipher the website is using.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Further compounding the problem I know PAN-OS 6.X.X had a bug where allowing "unsupported ciphers" didn't matter:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;(Screen shot is of 7.0.X - So formatting may be a bit off for you)&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Decryption_Profile.JPG" style="width: 338px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/4003iC937BBF564BCAD21/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Decryption_Profile.JPG" alt="Decryption_Profile.JPG" /&gt;&lt;/span&gt;﻿&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In theory you should be able to have this unchecked and the session should be allowed, but that isn't the case and the only way out is 1 of 3 options.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Turn off SSL Interception completely&lt;/P&gt;
&lt;P&gt;Handle URLs on a case by case basis&lt;/P&gt;
&lt;P&gt;Upgrade to 7.1.X (as 7.1.X has the huge bump in cipher support)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Back when i was running 7.0.3 we were still running into issues where unsupported ciphers still needed to be bypassed eventhough our decryption profile is built to avoid this issue.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The TAC case I had at the time the support tech said, while it *SHOULD* not be a problem they couldn't gurantee it wouldn't cause the problem.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Since we've been running 7.0.5-h2 I haven't had a single case where an unsupported cipher site needed to be bypassed. &amp;nbsp;So maybe that issue has been solved.&lt;/P&gt;</description>
      <pubDate>Wed, 11 May 2016 13:27:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption/m-p/77925#M42751</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2016-05-11T13:27:04Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption/m-p/78316#M42903</link>
      <description>&lt;P&gt;Just a quick update - we solved the problem by upgrading to 7.0.6.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 18 May 2016 15:19:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption/m-p/78316#M42903</guid>
      <dc:creator>iChen78</dc:creator>
      <dc:date>2016-05-18T15:19:52Z</dc:date>
    </item>
  </channel>
</rss>

