<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSL Decryption not working in chrome in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-not-working-in-chrome/m-p/160302#M52276</link>
    <description>&lt;P&gt;&lt;SPAN&gt;RSA2048 is the key algorithm used for the private/public key pair. The signature is another dropdown field in the PA WebUI. And because SHA1 is no longer a secure algorithm because it was sucessfully cracked about 2 months ago chrome does not let you open this website.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Theoretically this algorithm was already known unsecure many years ago ... but there was no (known) successful attack till this year&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 08 Jun 2017 21:51:59 GMT</pubDate>
    <dc:creator>Remo</dc:creator>
    <dc:date>2017-06-08T21:51:59Z</dc:date>
    <item>
      <title>SSL Decryption not working in chrome</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-not-working-in-chrome/m-p/160284#M52268</link>
      <description>&lt;P&gt;Trying to configure SSL Decryption and googled this to no end.&lt;BR /&gt;&lt;BR /&gt;I have an Enterprise CA, created the cert with that, I can see that the GPO's have deployed to the cert to the users.&lt;BR /&gt;In my testing I only have decryption turned on for one user.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Internet Explorer works fine as best I can tell it's not even noticing.&lt;/P&gt;&lt;P&gt;Chrome on the other hand is not amuzed. I cannot go to a single https site they all seem to give the same error&amp;nbsp;&lt;SPAN&gt;NET::ERR_CERT_WEAK_SIGNATURE_ALGORITHM&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="debugging-content"&gt;&lt;SPAN class="debugging-title"&gt;Subject: &lt;/SPAN&gt;&lt;SPAN class="debugging-content"&gt;*.facebook.com&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="debugging-content"&gt;&lt;SPAN class="debugging-title"&gt;Issuer: &lt;/SPAN&gt;&lt;SPAN class="debugging-content"&gt;192.168.15.10&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="debugging-content"&gt;&lt;SPAN class="debugging-title"&gt;Expires on: &lt;/SPAN&gt;&lt;SPAN class="debugging-content"&gt;Jun 22, 2018&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="debugging-content"&gt;&lt;SPAN class="debugging-title"&gt;Current date: &lt;/SPAN&gt;&lt;SPAN class="debugging-content"&gt;Jun 8, 2017&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="debugging-content"&gt;&lt;SPAN class="debugging-title"&gt;PEM encoded chain:&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="debugging-content"&gt;&lt;SPAN class="debugging-content debugging-content-fixed-width"&gt;-----BEGIN CERTIFICATE-----&lt;BR /&gt;... &amp;lt;assuming this is the cert from the site&amp;gt;...&lt;BR /&gt;-----END CERTIFICATE-----&lt;BR /&gt;-----BEGIN CERTIFICATE-----&lt;BR /&gt;... &amp;lt;cert from the PA&amp;gt;...&lt;BR /&gt;-----END CERTIFICATE-----&lt;BR /&gt;-----BEGIN CERTIFICATE-----&lt;BR /&gt;... &amp;lt;cert from the CA&amp;gt;...&lt;BR /&gt;-----END CERTIFICATE-----&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="debugging-content"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="debugging-content"&gt;&lt;SPAN class="debugging-content debugging-content-fixed-width"&gt;Banging my head against the wall here to trying to figure out what is missing&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jun 2017 20:35:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-not-working-in-chrome/m-p/160284#M52268</guid>
      <dc:creator>DaleK</dc:creator>
      <dc:date>2017-06-08T20:35:25Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption not working in chrome</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-not-working-in-chrome/m-p/160292#M52269</link>
      <description>&lt;P&gt;It sounds like your trying to use a SHA-1 cert. IE isn't going to explain but pretty much everything else at this point is.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jun 2017 20:57:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-not-working-in-chrome/m-p/160292#M52269</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-06-08T20:57:52Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption not working in chrome</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-not-working-in-chrome/m-p/160293#M52270</link>
      <description>&lt;P&gt;The CA cert, which you imported to the firewall, could it possibly be that this is an SHA1 certificate?&lt;/P&gt;&lt;P&gt;--&amp;gt; you need a cert with SHA256 signature algorithm&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Edit: too late ...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jun 2017 21:01:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-not-working-in-chrome/m-p/160293#M52270</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2017-06-08T21:01:38Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption not working in chrome</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-not-working-in-chrome/m-p/160300#M52275</link>
      <description>&lt;P&gt;Ok so i double checked when i made the request on the PA i left it with the defaults that were not sha1 i think it was 2048... So is it something on the CA and the template it used that would have done that?&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jun 2017 21:32:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-not-working-in-chrome/m-p/160300#M52275</guid>
      <dc:creator>DaleK</dc:creator>
      <dc:date>2017-06-08T21:32:34Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption not working in chrome</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-not-working-in-chrome/m-p/160302#M52276</link>
      <description>&lt;P&gt;&lt;SPAN&gt;RSA2048 is the key algorithm used for the private/public key pair. The signature is another dropdown field in the PA WebUI. And because SHA1 is no longer a secure algorithm because it was sucessfully cracked about 2 months ago chrome does not let you open this website.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Theoretically this algorithm was already known unsecure many years ago ... but there was no (known) successful attack till this year&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jun 2017 21:51:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-not-working-in-chrome/m-p/160302#M52276</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2017-06-08T21:51:59Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption not working in chrome</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-not-working-in-chrome/m-p/160312#M52278</link>
      <description>&lt;P&gt;So I just tried another request and it still only gave me a sha1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;could my CA just be retarted somehow?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="request.PNG" style="width: 403px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/9600iA8CD654C68B656CC/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="request.PNG" alt="request.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="cert.PNG" style="width: 385px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/9601i7D9750DB0FE67038/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="cert.PNG" alt="cert.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jun 2017 22:13:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-not-working-in-chrome/m-p/160312#M52278</guid>
      <dc:creator>DaleK</dc:creator>
      <dc:date>2017-06-08T22:13:31Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption not working in chrome</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-not-working-in-chrome/m-p/160313#M52279</link>
      <description>&lt;P&gt;NM found it... yea never migrated my CA off sha1.... yay more fun...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you all for the help&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jun 2017 22:26:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-not-working-in-chrome/m-p/160313#M52279</guid>
      <dc:creator>DaleK</dc:creator>
      <dc:date>2017-06-08T22:26:12Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption not working in chrome</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-not-working-in-chrome/m-p/160398#M52290</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/65625"&gt;@DaleK&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Just FYI, we found that it was easier to spin up a specific SHA2 CA and keep the existing SHA1 CA around at the same time. If you issue certificates to your machines and/or users and can't easily migrate everything over to a new cert easily, that might be an 'effective' solution until everything that users a cert for authentication is gradually migrated.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Jun 2017 12:37:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-not-working-in-chrome/m-p/160398#M52290</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-06-09T12:37:14Z</dc:date>
    </item>
  </channel>
</rss>

