<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSL Inbound Inspection not working with decrypt-error message in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-inbound-inspection-not-working-with-decrypt-error-message/m-p/130561#M46849</link>
    <description>&lt;P&gt;also make sure the server is using a cupher suite that's supported by the firewall : &lt;A title=" PAN-OS 7.1 Supported ciphers" href="https://live.paloaltonetworks.com/t5/PAN-OS-7-1-Articles/PAN-OS-7-1-Supported-ciphers/ta-p/71969" target="_blank"&gt; PAN-OS 7.1 Supported ciphers&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 02 Dec 2016 10:38:50 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2016-12-02T10:38:50Z</dc:date>
    <item>
      <title>SSL Inbound Inspection not working with decrypt-error message</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-inbound-inspection-not-working-with-decrypt-error-message/m-p/130529#M46844</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm trying to setup, for the first time, our&amp;nbsp;SSL Inbound Inspection, but I've some difficulties to achieve the setup.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The configuration seems really simple, and I followed this guide:&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/71/pan-os/pan-os/decryption/configure-ssl-inbound-inspection#34438" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/71/pan-os/pan-os/decryption/configure-ssl-inbound-inspection#34438&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'd imported the certificate and intermediate certificate, checked that the root CA exists in the in the Trusted Certificate Authorities (Quovadis Root CA 2) and create a decryption rule.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When checking the traffic log, all entries matching the decryption rule returns a decrypt-error as the session end reason.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How I can debug this kind of error?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Fri, 02 Dec 2016 09:44:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-inbound-inspection-not-working-with-decrypt-error-message/m-p/130529#M46844</guid>
      <dc:creator>FTBZ</dc:creator>
      <dc:date>2016-12-02T09:44:36Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Inbound Inspection not working with decrypt-error message</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-inbound-inspection-not-working-with-decrypt-error-message/m-p/130541#M46845</link>
      <description>&lt;P&gt;Hi FTBZ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When you're configuring Inbound inspection you're looking to decrypt traffic that is incoming to a server providing encrypted services, like a HTTPS enabled web-server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To get Inbound inspection to work you'll need to use the same certificate on the firewall (with private key) that you use&amp;nbsp;on the server. You don't need an intermediate certificate for inbound inspection.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;hope this helps,&lt;/P&gt;&lt;P&gt;Ben&lt;/P&gt;</description>
      <pubDate>Fri, 02 Dec 2016 09:54:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-inbound-inspection-not-working-with-decrypt-error-message/m-p/130541#M46845</guid>
      <dc:creator>bmorris1</dc:creator>
      <dc:date>2016-12-02T09:54:28Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Inbound Inspection not working with decrypt-error message</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-inbound-inspection-not-working-with-decrypt-error-message/m-p/130561#M46849</link>
      <description>&lt;P&gt;also make sure the server is using a cupher suite that's supported by the firewall : &lt;A title=" PAN-OS 7.1 Supported ciphers" href="https://live.paloaltonetworks.com/t5/PAN-OS-7-1-Articles/PAN-OS-7-1-Supported-ciphers/ta-p/71969" target="_blank"&gt; PAN-OS 7.1 Supported ciphers&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Dec 2016 10:38:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-inbound-inspection-not-working-with-decrypt-error-message/m-p/130561#M46849</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2016-12-02T10:38:50Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Inbound Inspection not working with decrypt-error message</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-inbound-inspection-not-working-with-decrypt-error-message/m-p/131880#M46987</link>
      <description>&lt;P&gt;Sorry for the late response, didn't get the notification about new message.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;P&gt;To get Inbound inspection to work you'll need to use the same certificate on the firewall (with private key) that you use&amp;nbsp;on the server. You don't need an intermediate certificate for inbound inspection.&amp;nbsp;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Exactly what I've done, but thanks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;P&gt;also make sure the server is using a cupher suite that's supported by the firewall : &lt;A title=" PAN-OS 7.1 Supported ciphers" href="https://live.paloaltonetworks.com/t5/PAN-OS-7-1-Articles/PAN-OS-7-1-Supported-ciphers/ta-p/71969" target="_blank"&gt;PAN-OS 7.1 Supported ciphers&lt;/A&gt;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&amp;nbsp;Oh, thanks. Perhaps my problem can be here, our Apache configurations have a lot of cipher fine-tuning.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Dec 2016 19:51:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-inbound-inspection-not-working-with-decrypt-error-message/m-p/131880#M46987</guid>
      <dc:creator>FTBZ</dc:creator>
      <dc:date>2016-12-07T19:51:14Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Inbound Inspection not working with decrypt-error message</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-inbound-inspection-not-working-with-decrypt-error-message/m-p/131962#M46994</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt; wrote:&lt;BR /&gt;&lt;P&gt;also make sure the server is using a cupher suite that's supported by the firewall : &lt;A title=" PAN-OS 7.1 Supported ciphers" href="https://live.paloaltonetworks.com/t5/PAN-OS-7-1-Articles/PAN-OS-7-1-Supported-ciphers/ta-p/71969" target="_blank"&gt;PAN-OS 7.1 Supported ciphers&lt;/A&gt;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I checked the cipher used during my tests and it's one that's supported by PAN-OS 7.1 (TLS-ECDHE-RSA-WITH-AES-128-GCM-SHA256).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We're using Quovadis certificates that need an intermediate one. Someone knows the correct steps to use it? The default CA root exists in the Default Trusted Certificate Autorities. Need I to reupload it to the Device Certificate for using intermediate? The&amp;nbsp;Trusted Root CA checkbox needs to be used for an intermediate? &lt;span class="lia-unicode-emoji" title=":thinking_face:"&gt;🤔&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Dec 2016 05:49:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-inbound-inspection-not-working-with-decrypt-error-message/m-p/131962#M46994</guid>
      <dc:creator>FTBZ</dc:creator>
      <dc:date>2016-12-08T05:49:49Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Inbound Inspection not working with decrypt-error message</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-inbound-inspection-not-working-with-decrypt-error-message/m-p/139293#M48087</link>
      <description>&lt;P&gt;&lt;SPAN class="sac"&gt;Finally&lt;/SPAN&gt;&lt;SPAN&gt;, figured it out. For SSL Inbound Inspection only RSA key exchange is supported... Found this&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="sac"&gt;information&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;in small in the Decryption Profile. Didn't see it before because I used the default one. This information needs really to be added to&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="sac"&gt;the documentation&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;and to the page "PAN-OS 7.1 Supported ciphers".&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;SPAN&gt;Don't think that disabling ECDHE and using RSA on our&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="sac"&gt;web servers&lt;/SPAN&gt;&lt;SPAN&gt;is a good choice. Any idea?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2017 13:09:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-inbound-inspection-not-working-with-decrypt-error-message/m-p/139293#M48087</guid>
      <dc:creator>FTBZ</dc:creator>
      <dc:date>2017-01-25T13:09:05Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Inbound Inspection not working with decrypt-error message</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-inbound-inspection-not-working-with-decrypt-error-message/m-p/139313#M48091</link>
      <description>&lt;P&gt;it is important that your webserver is offering the same of what is supported by palo alto. take a look here:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="cipher.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/7401i30EFF7EF0FCB3F96/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="cipher.PNG" alt="cipher.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2017 13:39:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-inbound-inspection-not-working-with-decrypt-error-message/m-p/139313#M48091</guid>
      <dc:creator>kdd</dc:creator>
      <dc:date>2017-01-25T13:39:53Z</dc:date>
    </item>
  </channel>
</rss>

