<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Google disclaimer and SSL Decryption in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/google-disclaimer-and-ssl-decryption/m-p/111340#M45100</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/46085"&gt;@Laurent_Dormond﻿&lt;/a&gt;&amp;nbsp;From the PCAP you should have been able to see an "untrusted certificate" alert&lt;/P&gt;</description>
    <pubDate>Wed, 07 Sep 2016 16:05:50 GMT</pubDate>
    <dc:creator>Brandon_Wertz</dc:creator>
    <dc:date>2016-09-07T16:05:50Z</dc:date>
    <item>
      <title>Google disclaimer and SSL Decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/google-disclaimer-and-ssl-decryption/m-p/111160#M45086</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have enabled SSL decryption on a PA-500 running PanOS 7.0.9 for testing purposes (before enabling in prod environment).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;All seems to be working fine, except with the Google Disclaimer that randomly occurs and that you have to agree with in order to go ahead with your google searches...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Without SSL decryption it displays normally, but with SSL decryption enabled, it only displays a empty (white) frame and the end user can't agree and thus stucks on this page...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There is nothing denied or blocked by any PanOS feature, test policy is "any any allow".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is occuring with IE 11 (not tested with another browser).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does anymone ever experienced this issue ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Laurent&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Sep 2016 08:57:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/google-disclaimer-and-ssl-decryption/m-p/111160#M45086</guid>
      <dc:creator>Laurent_Dormond</dc:creator>
      <dc:date>2016-09-07T08:57:19Z</dc:date>
    </item>
    <item>
      <title>Re: Google disclaimer and SSL Decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/google-disclaimer-and-ssl-decryption/m-p/111231#M45089</link>
      <description>&lt;P&gt;Not for me.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Running IE 11.0.9600&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Maybe try a PCAP from the palo and see what's happening. &amp;nbsp;That's really only been my recourse when technical SSL issues like you're having.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Sep 2016 12:17:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/google-disclaimer-and-ssl-decryption/m-p/111231#M45089</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2016-09-07T12:17:41Z</dc:date>
    </item>
    <item>
      <title>Re: Google disclaimer and SSL Decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/google-disclaimer-and-ssl-decryption/m-p/111300#M45091</link>
      <description>&lt;P&gt;Sounds like maybe your SSL cert is not loaded on your computers as a "Trusted Root Certification Authority"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I decrypt all our Google traffic so I can enforce safe search, youtube safety-mode, and others. We don't have any problems in Chrome or IE, but Firefox has it's own certificate store and doesn't use Windows.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Sep 2016 13:59:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/google-disclaimer-and-ssl-decryption/m-p/111300#M45091</guid>
      <dc:creator>bbilut</dc:creator>
      <dc:date>2016-09-07T13:59:40Z</dc:date>
    </item>
    <item>
      <title>Re: Google disclaimer and SSL Decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/google-disclaimer-and-ssl-decryption/m-p/111332#M45095</link>
      <description>&lt;P&gt;Hi Brad,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;indeed, my ssl cert is not loaded as "Trusted Root CA cert", since it is just SSL decrypt test purposes.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also I have the "untrusted issuer warning" message in the browser for each decrypted HTTPS website, but it is not a problem for the instance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To add some more visual description of the problem, here are two screenshot with and without ssl decrpytion :&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;Here with SSL decryption deactivated&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SSl decryption rule deactivated" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/5482i657D0A1140978A6E/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="no_ssl_decrypt.png" alt="no_ssl_decrypt.png" /&gt;&lt;/span&gt;﻿&amp;nbsp;Here with SSL decryption enabled&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SSL decryption rule enabled" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/5483i12EEEA927AB79D07/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="ssl_decrypt.png" alt="ssl_decrypt.png" /&gt;&lt;/span&gt;﻿&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Sep 2016 15:00:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/google-disclaimer-and-ssl-decryption/m-p/111332#M45095</guid>
      <dc:creator>Laurent_Dormond</dc:creator>
      <dc:date>2016-09-07T15:00:33Z</dc:date>
    </item>
    <item>
      <title>Re: Google disclaimer and SSL Decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/google-disclaimer-and-ssl-decryption/m-p/111333#M45096</link>
      <description>&lt;P&gt;So I'm just going to take an educated guess here after seeing your screen but without your ssl decryption cert being trusted you would have to 'allow' the connection to continue. Since Google isn't pulling that resource from the same server (you can test this with the dev tools network monitoring) it isn't loading the resource because you haven't actually allowed that action to continue with the untrusted cert. If you add that cert into your trusted store then you should see this issue go away.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Sep 2016 15:07:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/google-disclaimer-and-ssl-decryption/m-p/111333#M45096</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2016-09-07T15:07:48Z</dc:date>
    </item>
    <item>
      <title>Re: Google disclaimer and SSL Decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/google-disclaimer-and-ssl-decryption/m-p/111335#M45097</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That sounds good indeed, I will try out and let you know the result.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I remember in the PCAP captures that there were a lots of SSL handshakes (client hello, server hello, ...) that probably means that there are multiple SSL connexions to different resources.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the advice.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Wed, 07 Sep 2016 15:23:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/google-disclaimer-and-ssl-decryption/m-p/111335#M45097</guid>
      <dc:creator>Laurent_Dormond</dc:creator>
      <dc:date>2016-09-07T15:23:46Z</dc:date>
    </item>
    <item>
      <title>Re: Google disclaimer and SSL Decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/google-disclaimer-and-ssl-decryption/m-p/111338#M45098</link>
      <description>&lt;P&gt;What you're decryption profile look like? This is how I have mine set (it's pretty loose).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2016-09-07 10_28_25-Panorama.png" style="width: 778px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/5484iAA0DE8D55CF833AC/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="2016-09-07 10_28_25-Panorama.png" alt="2016-09-07 10_28_25-Panorama.png" /&gt;&lt;/span&gt;﻿&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2016-09-07 10_28_38-Panorama.png" style="width: 783px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/5485i8F7D39C4AAE82029/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="2016-09-07 10_28_38-Panorama.png" alt="2016-09-07 10_28_38-Panorama.png" /&gt;&lt;/span&gt;﻿&lt;/P&gt;</description>
      <pubDate>Wed, 07 Sep 2016 15:31:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/google-disclaimer-and-ssl-decryption/m-p/111338#M45098</guid>
      <dc:creator>bbilut</dc:creator>
      <dc:date>2016-09-07T15:31:32Z</dc:date>
    </item>
    <item>
      <title>Re: Google disclaimer and SSL Decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/google-disclaimer-and-ssl-decryption/m-p/111339#M45099</link>
      <description>&lt;P&gt;Ok adding the self-signed cert to the Trusted root CA cert store fixed this issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Many thanks for your help.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Wed, 07 Sep 2016 15:42:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/google-disclaimer-and-ssl-decryption/m-p/111339#M45099</guid>
      <dc:creator>Laurent_Dormond</dc:creator>
      <dc:date>2016-09-07T15:42:46Z</dc:date>
    </item>
    <item>
      <title>Re: Google disclaimer and SSL Decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/google-disclaimer-and-ssl-decryption/m-p/111340#M45100</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/46085"&gt;@Laurent_Dormond﻿&lt;/a&gt;&amp;nbsp;From the PCAP you should have been able to see an "untrusted certificate" alert&lt;/P&gt;</description>
      <pubDate>Wed, 07 Sep 2016 16:05:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/google-disclaimer-and-ssl-decryption/m-p/111340#M45100</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2016-09-07T16:05:50Z</dc:date>
    </item>
    <item>
      <title>Re: Google disclaimer and SSL Decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/google-disclaimer-and-ssl-decryption/m-p/111343#M45103</link>
      <description>&lt;P&gt;FYI: We push our cert out to Windows machines with group policy, iOS devices with our MDM solution (Airwatch), and to our Chromebooks with the Google Mgmt console. That only leaves personal devices (byod), so we put the cert up on our web site with instructions on who to install it.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Sep 2016 16:08:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/google-disclaimer-and-ssl-decryption/m-p/111343#M45103</guid>
      <dc:creator>bbilut</dc:creator>
      <dc:date>2016-09-07T16:08:18Z</dc:date>
    </item>
  </channel>
</rss>

