<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSL Decryption in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption/m-p/165816#M53226</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;try to open VMware website:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.vmware.com" target="_blank"&gt;https://www.vmware.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Most likely it is all due to&amp;nbsp;HTTP Public Key Pinning:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://en.wikipedia.org/wiki/HTTP_Public_Key_Pinning" target="_blank"&gt;https://en.wikipedia.org/wiki/HTTP_Public_Key_Pinning&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://androidtechieblog.wordpress.com/2016/07/21/ssl-pinning-to-prevent-a-man-in-the-middle-mitm-attack-on-androidios-application-part-1/" target="_blank"&gt;https://androidtechieblog.wordpress.com/2016/07/21/ssl-pinning-to-prevent-a-man-in-the-middle-mitm-attack-on-androidios-application-part-1/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 11 Jul 2017 13:32:40 GMT</pubDate>
    <dc:creator>TranceforLife</dc:creator>
    <dc:date>2017-07-11T13:32:40Z</dc:date>
    <item>
      <title>SSL Decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption/m-p/165513#M53190</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a PA-VM running on a ESX server.&lt;/P&gt;&lt;P&gt;I want to set up SSL Decryption on it using a SUBCA certificate chain signed by a PKI (windows server).&lt;/P&gt;&lt;P&gt;I check boxes "Forward to trust/untrusted certifcate"&lt;/P&gt;&lt;P&gt;I export the SUBCA to store it on a client machine (to avoid warning message)&lt;/P&gt;&lt;P&gt;The network is OK&lt;/P&gt;&lt;P&gt;The policy is Any any permit&lt;/P&gt;&lt;P&gt;The SSL decryption policy is set up to decrypt everything&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The main issue is the Following :&lt;/P&gt;&lt;P&gt;On the client machine, I not allowed to reach any website using HTTPS, the brower is telling me that the connection has been reset... whatever the browser (chrome, IE etc)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can't find anything to solve my issue...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jul 2017 15:38:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption/m-p/165513#M53190</guid>
      <dc:creator>SERMA-NES</dc:creator>
      <dc:date>2017-07-10T15:38:54Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption/m-p/165539#M53193</link>
      <description>&lt;P&gt;It doesn't sound like SSL decryption was setup properly. Did you follow any of the guides when you were setting this up? Generally you should at least be getting a message about the certificate not being trusted. I would personally delete the setup that you have currently and follow the guide found here to verify that everything is setup correctly.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Tutorials/How-to-Configure-SSL-Decryption/ta-p/65073#TopicC" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Tutorials/How-to-Configure-SSL-Decryption/ta-p/65073#TopicC&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jul 2017 16:22:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption/m-p/165539#M53193</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-07-10T16:22:36Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption/m-p/165541#M53195</link>
      <description>&lt;P&gt;The traffic logs session end reason? What can you see there?&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jul 2017 16:23:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption/m-p/165541#M53195</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-07-10T16:23:15Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption/m-p/165807#M53225</link>
      <description>&lt;P&gt;Thanks for your answers.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I followed several guides to set up SSL Decryption (including the one you provide).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;192.168.116.191 is the internal IP (default gateway of the users)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I configure it again, using self certifcate, the problem is still there...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="V1.png" style="width: 404px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/10313i4CA5898AEAAB0B78/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="V1.png" alt="V1.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="V2.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/10314i95F77DCE9CFEB7A0/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="V2.png" alt="V2.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="V3.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/10315i95A5FB39C99606DC/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="V3.png" alt="V3.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="V4.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/10321i4866D0E81DF778C4/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="V4.png" alt="V4.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="V5.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/10319iDEB39DB23A6A89F1/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="V5.png" alt="V5.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="V6.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/10320iD88648197866FE0A/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="V6.png" alt="V6.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jul 2017 13:10:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption/m-p/165807#M53225</guid>
      <dc:creator>SERMA-NES</dc:creator>
      <dc:date>2017-07-11T13:10:01Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption/m-p/165816#M53226</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;try to open VMware website:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.vmware.com" target="_blank"&gt;https://www.vmware.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Most likely it is all due to&amp;nbsp;HTTP Public Key Pinning:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://en.wikipedia.org/wiki/HTTP_Public_Key_Pinning" target="_blank"&gt;https://en.wikipedia.org/wiki/HTTP_Public_Key_Pinning&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://androidtechieblog.wordpress.com/2016/07/21/ssl-pinning-to-prevent-a-man-in-the-middle-mitm-attack-on-androidios-application-part-1/" target="_blank"&gt;https://androidtechieblog.wordpress.com/2016/07/21/ssl-pinning-to-prevent-a-man-in-the-middle-mitm-attack-on-androidios-application-part-1/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jul 2017 13:32:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption/m-p/165816#M53226</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-07-11T13:32:40Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption/m-p/165819#M53227</link>
      <description>&lt;P&gt;I can't access to &lt;A href="https://www.vmware.com" target="_blank"&gt;https://www.vmware.com&lt;/A&gt; too &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For your information, I try to set up SSL Decryption on a new PA-820 PANOS8.0, with the same configuration, the problem is the same...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What should I do to make it functionnal ?&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jul 2017 13:57:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption/m-p/165819#M53227</guid>
      <dc:creator>SERMA-NES</dc:creator>
      <dc:date>2017-07-11T13:57:52Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption/m-p/165822#M53229</link>
      <description>&lt;P&gt;Did you actually click on the "confirm security exception" button?&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jul 2017 14:08:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption/m-p/165822#M53229</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-07-11T14:08:39Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption/m-p/165823#M53230</link>
      <description>&lt;P&gt;Yes I did &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I very surprised about this issue... the configuration is pretty simple but the troubleshooting is not so easy&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jul 2017 14:14:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption/m-p/165823#M53230</guid>
      <dc:creator>SERMA-NES</dc:creator>
      <dc:date>2017-07-11T14:14:09Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption/m-p/165824#M53231</link>
      <description>&lt;P&gt;Yeah, the&amp;nbsp;only one thing l have different is on my SSL self gen cert l have &amp;nbsp;CN as a name, &amp;nbsp;not ip. Can you test with self-signed certs?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jul 2017 14:16:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption/m-p/165824#M53231</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-07-11T14:16:35Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption/m-p/165832#M53232</link>
      <description>&lt;P&gt;Yeah I have tested with self signed certificate, please refer to my previous post (screenshots have been posted)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;CN or IP doesn't matter... right ?&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jul 2017 14:28:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption/m-p/165832#M53232</guid>
      <dc:creator>SERMA-NES</dc:creator>
      <dc:date>2017-07-11T14:28:23Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption/m-p/165834#M53233</link>
      <description>&lt;P&gt;Ohh, blind me :D. Should not really in our case.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;EDIT: FYI&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="FYI.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/10322i8DF71E47573DEF15/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="FYI.PNG" alt="FYI.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jul 2017 14:49:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption/m-p/165834#M53233</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-07-11T14:49:47Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption/m-p/165838#M53234</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/12123"&gt;@SERMA-NES&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Stupid question but did you actually import the cert onto the local machine, it doesn't look like you did and if you are utilizing a self sign then you need to accept the cert that you are using to actively decrypt the traffic. From your provided screenshots it doesn't look like this is actually done which would cause a hole heap of security errors from pretty much any browser.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jul 2017 14:52:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption/m-p/165838#M53234</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-07-11T14:52:21Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption/m-p/165855#M53238</link>
      <description>&lt;P&gt;I didn't import it during my first screenshots, but I did it after, the problem is still here.&lt;/P&gt;&lt;P&gt;With the certificat in the client's store, I don't have anymore warnings from the browser, but directly the "reset" message.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have the same certificate when I try to reach VMWARE website :&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="V7.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/10326i43DD4E9C5D920970/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="V7.png" alt="V7.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jul 2017 15:17:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption/m-p/165855#M53238</guid>
      <dc:creator>SERMA-NES</dc:creator>
      <dc:date>2017-07-11T15:17:27Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption/m-p/165856#M53239</link>
      <description>&lt;P&gt;Miracle. What can you see in the traffic logs (session-end reason)?&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jul 2017 15:19:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption/m-p/165856#M53239</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-07-11T15:19:32Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption/m-p/166049#M53263</link>
      <description>&lt;P&gt;hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;tcp reset from client...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I downgrade PANOS to 7.1.0 and now, the browser try to reach the website (perpetualy) but this time without Reset message&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jul 2017 09:33:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption/m-p/166049#M53263</guid>
      <dc:creator>SERMA-NES</dc:creator>
      <dc:date>2017-07-12T09:33:51Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption/m-p/166127#M53274</link>
      <description>&lt;P&gt;You need to do a packet capture on the client system and see what is going on. &amp;nbsp;With that you will likely be able to find out why the client is terminating the session.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You may also want to try Chrome on your Ubuntu machine, or another operating system all together. &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jul 2017 15:18:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption/m-p/166127#M53274</guid>
      <dc:creator>it-thomas</dc:creator>
      <dc:date>2017-07-12T15:18:53Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption/m-p/166172#M53280</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/12123"&gt;@SERMA-NES&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I agree with&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/67436"&gt;@it-thomas&lt;/a&gt;, the client is clearly resetting the traffic.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;What we know (or think we know)&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;- Traffic is being reset by the client, so it's not specifically a decryption issue.&amp;nbsp;&lt;/P&gt;&lt;P&gt;- The client believes the cert is not valid, which would be common for self-signed certs as you need to import the cert which you have.&lt;/P&gt;&lt;P&gt;- The issue persists even if you move off of 8.0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would try this on Chrome and see where that gets you, I would also try this on a Windows machine with Internet Explorer or Edge as they are less prone to trigger on security issues.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jul 2017 18:05:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption/m-p/166172#M53280</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-07-12T18:05:49Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption/m-p/166206#M53291</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&lt;/P&gt;&lt;P&gt;"&lt;SPAN&gt;try this on a Windows machine with Internet Explorer or Edge as they are less prone to trigger on security issues. "&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;^&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;That statement is funny because it is true.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Remember for certs it checks 3 things, if any of those things fail it doesnt play well:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;-Who you are&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;-- i.e. does the cert match the website, if it doesnt it will fail&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;-When you are good&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;-- outside of the valid cert period it will&amp;nbsp;fail&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;-Who says I can trust you&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;-- If your root CA is not trusted, it will not trust anything below it in the chain. &amp;nbsp;That being said, make sure that you import the Root CA into the correct spot in your browser or it will fail.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It is possible that your TCP and/or SSL handshakes are getting all buggered up due to issues with your cer/decrypt. &amp;nbsp;In turn your client is killing the connection&amp;nbsp;since it doesn't trust it. &amp;nbsp;The packet capture will tell you all of that information and help you pin down the failure point.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This also hasnt been asked yet, is HTTP working correctly?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.bing.com" target="_blank"&gt;http://www.bing.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;vs&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.bing.com" target="_blank"&gt;https://www.bing.com&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jul 2017 20:40:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption/m-p/166206#M53291</guid>
      <dc:creator>it-thomas</dc:creator>
      <dc:date>2017-07-12T20:40:57Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption/m-p/166440#M53336</link>
      <description>&lt;P&gt;Try taking a simultaneous pcap on the ubuntu box and the firewall and compare them if the client generates a rst packet&lt;/P&gt;&lt;P&gt;Move over you can take the global counters during the test&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the command line run &lt;EM&gt;show counter global filter packet-filter yes delta&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;Just make sure your &amp;nbsp;filters are setup to include only the source machine from where you are testing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you can please share the output of counters&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jul 2017 02:49:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption/m-p/166440#M53336</guid>
      <dc:creator>mgarg</dc:creator>
      <dc:date>2017-07-14T02:49:41Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption/m-p/173244#M54561</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks everybody for your implication.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I solved my issue several weeks ago : Since PANOS 7, to make SSL decryption works, we have to configure "Any" on the service column and not "application default" on our policy&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It works fine now !&lt;/P&gt;</description>
      <pubDate>Fri, 25 Aug 2017 15:20:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption/m-p/173244#M54561</guid>
      <dc:creator>SERMA-NES</dc:creator>
      <dc:date>2017-08-25T15:20:22Z</dc:date>
    </item>
  </channel>
</rss>

