<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to properly disable 3DES encryption algorithm? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-properly-disable-3des-encryption-algorithm/m-p/121141#M46021</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, the GUI is showing it as disabled, yet the firewall will still offer 3DES to clients, so this is not just a cosmetic issue.&lt;/P&gt;</description>
    <pubDate>Tue, 25 Oct 2016 12:08:09 GMT</pubDate>
    <dc:creator>arvesynd</dc:creator>
    <dc:date>2016-10-25T12:08:09Z</dc:date>
    <item>
      <title>How to properly disable 3DES encryption algorithm?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-properly-disable-3des-encryption-algorithm/m-p/121115#M46015</link>
      <description>&lt;P&gt;We are currently being required to disable 3DES in order to pass PCI compliance (due to the Sweet32 exploit).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have a decryption profile for all incoming traffic hitting our firewall and services behind it, where I have tried disabling 3DES.&lt;/P&gt;&lt;P&gt;However, the firewall will still accept 3DES after doing a commit. When opening the decryption profile again. 3DES will be shown as enabled again.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As you can see in the picture, 3DES seems to be disabled in the decryption profile list, but when opening the specified decryption profile it shows up as enabled.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="3DES.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/6045i3EE0632F26C816B4/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="3DES.png" alt="3DES.png" /&gt;&lt;/span&gt;﻿&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does anyone know how to properly disable 3DES on PANOS 7.1.x?&lt;/P&gt;</description>
      <pubDate>Tue, 25 Oct 2016 10:27:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-properly-disable-3des-encryption-algorithm/m-p/121115#M46015</guid>
      <dc:creator>arvesynd</dc:creator>
      <dc:date>2016-10-25T10:27:55Z</dc:date>
    </item>
    <item>
      <title>Re: How to properly disable 3DES encryption algorithm?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-properly-disable-3des-encryption-algorithm/m-p/121129#M46017</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Seems odd, can you try changing this via the CLI?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;gt;configure&lt;/P&gt;&lt;P&gt;#edit profiles decryption "name of decryption profile" ssl-protocol-settings&lt;/P&gt;&lt;P&gt;#set enc-algo-3des no&lt;/P&gt;&lt;P&gt;#commit&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;let us know if this resolves the issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ben&lt;/P&gt;</description>
      <pubDate>Tue, 25 Oct 2016 10:45:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-properly-disable-3des-encryption-algorithm/m-p/121129#M46017</guid>
      <dc:creator>bmorris1</dc:creator>
      <dc:date>2016-10-25T10:45:05Z</dc:date>
    </item>
    <item>
      <title>Re: How to properly disable 3DES encryption algorithm?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-properly-disable-3des-encryption-algorithm/m-p/121131#M46018</link>
      <description>&lt;P&gt;Hi Ben,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This did not resolve the issue, but it should be disabled.&lt;/P&gt;&lt;P&gt;The firewall still provides&amp;nbsp;&lt;SPAN&gt;TLS_RSA_WITH_3DES_EDE_CBC_SHA for clients.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here's the output from show of ssl-protocol-settings for the decryption profile:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;(active)# show
ssl-protocol-settings {
  keyxchg-algo-dhe yes;
  keyxchg-algo-ecdhe yes;
  min-version tls1-1;
  keyxchg-algo-rsa yes;
  enc-algo-3des no;
  enc-algo-rc4 no;
  enc-algo-aes-128-cbc yes;
  enc-algo-aes-256-cbc yes;
  enc-algo-aes-128-gcm yes;
  enc-algo-aes-256-gcm yes;
  auth-algo-sha1 yes;
  auth-algo-sha256 yes;
  auth-algo-sha384 yes;
}&lt;/PRE&gt;</description>
      <pubDate>Tue, 25 Oct 2016 11:20:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-properly-disable-3des-encryption-algorithm/m-p/121131#M46018</guid>
      <dc:creator>arvesynd</dc:creator>
      <dc:date>2016-10-25T11:20:41Z</dc:date>
    </item>
    <item>
      <title>Re: How to properly disable 3DES encryption algorithm?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-properly-disable-3des-encryption-algorithm/m-p/121132#M46019</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I see the same thing in my lab (running PAN-OS 7.1.3 on a VM-100).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It might just be&amp;nbsp;a cosmetic bug because the CLI command indicates it is disabled :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;admin@PA-VM# show profiles decryption test ssl-protocol-settings&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;ssl-protocol-settings {&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;enc-algo-3des no;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;enc-algo-rc4 no;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;}&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;I'd recommend to open a bug report with support so they can get this GUI bug fixed.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Cheers,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;-Kim.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Oct 2016 11:29:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-properly-disable-3des-encryption-algorithm/m-p/121132#M46019</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2016-10-25T11:29:44Z</dc:date>
    </item>
    <item>
      <title>Re: How to properly disable 3DES encryption algorithm?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-properly-disable-3des-encryption-algorithm/m-p/121141#M46021</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, the GUI is showing it as disabled, yet the firewall will still offer 3DES to clients, so this is not just a cosmetic issue.&lt;/P&gt;</description>
      <pubDate>Tue, 25 Oct 2016 12:08:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-properly-disable-3des-encryption-algorithm/m-p/121141#M46021</guid>
      <dc:creator>arvesynd</dc:creator>
      <dc:date>2016-10-25T12:08:09Z</dc:date>
    </item>
    <item>
      <title>Re: How to properly disable 3DES encryption algorithm?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-properly-disable-3des-encryption-algorithm/m-p/121659#M46069</link>
      <description>&lt;P&gt;Kim This command is working on 6.0 ?&lt;/P&gt;</description>
      <pubDate>Thu, 27 Oct 2016 07:37:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-properly-disable-3des-encryption-algorithm/m-p/121659#M46069</guid>
      <dc:creator>Fahad-Khan</dc:creator>
      <dc:date>2016-10-27T07:37:22Z</dc:date>
    </item>
    <item>
      <title>Re: How to properly disable 3DES encryption algorithm?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-properly-disable-3des-encryption-algorithm/m-p/121660#M46070</link>
      <description>&lt;P&gt;I finally managed to disable 3DES, but it was not as straight forward as disabling 3DES on the decryption profile for inbound SSL.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To make this work, I set min. protocol&amp;nbsp;version of the decryption profile to TLS 1.2, and then I had to do the same for the SSL/TLS Service Profile for each of the certificates used for inbound SSL inspection.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now the firewall will only use TLS 1.2 and 3DES is disabled across the board.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Oct 2016 07:40:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-properly-disable-3des-encryption-algorithm/m-p/121660#M46070</guid>
      <dc:creator>arvesynd</dc:creator>
      <dc:date>2016-10-27T07:40:24Z</dc:date>
    </item>
  </channel>
</rss>

