<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SSL Decryption for Chrome Browser in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-for-chrome-browser/m-p/166453#M53339</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Below is our Decryption Policy. Using latest Chrome version.&lt;/P&gt;&lt;P&gt;Security certificate used by the Palo is from the Windows domain PKI and is already implicitly trusted as this testing is from a domain connected Windows 10 device over Ethernet.&lt;/P&gt;&lt;P&gt;It is working fine for IE but in Chrome it is showing like this:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Decryption.jpg" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/10378i2A065C55CD56B1F0/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Decryption.jpg" alt="Decryption.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SSLDecryption.jpg" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/10379iEF4C4FB5832AA035/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="SSLDecryption.jpg" alt="SSLDecryption.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If I set the URL Category of Computers and Internet information to no-decrypt the error stops for this web site but continues for others, including the main Palo support pages.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Any idea how to stop this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 14 Jul 2017 04:41:09 GMT</pubDate>
    <dc:creator>Farzana</dc:creator>
    <dc:date>2017-07-14T04:41:09Z</dc:date>
    <item>
      <title>SSL Decryption for Chrome Browser</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-for-chrome-browser/m-p/166453#M53339</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Below is our Decryption Policy. Using latest Chrome version.&lt;/P&gt;&lt;P&gt;Security certificate used by the Palo is from the Windows domain PKI and is already implicitly trusted as this testing is from a domain connected Windows 10 device over Ethernet.&lt;/P&gt;&lt;P&gt;It is working fine for IE but in Chrome it is showing like this:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Decryption.jpg" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/10378i2A065C55CD56B1F0/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Decryption.jpg" alt="Decryption.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SSLDecryption.jpg" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/10379iEF4C4FB5832AA035/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="SSLDecryption.jpg" alt="SSLDecryption.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If I set the URL Category of Computers and Internet information to no-decrypt the error stops for this web site but continues for others, including the main Palo support pages.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Any idea how to stop this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jul 2017 04:41:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-for-chrome-browser/m-p/166453#M53339</guid>
      <dc:creator>Farzana</dc:creator>
      <dc:date>2017-07-14T04:41:09Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption for Chrome Browser</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-for-chrome-browser/m-p/168049#M53602</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are you getting any decrypt-error end reason in traffic logs?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you use the service in the Security Rule as 'any' (in case you are using application-default).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also you may block quic application as its mainly used by Chrome.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Sharief&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jul 2017 08:10:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-for-chrome-browser/m-p/168049#M53602</guid>
      <dc:creator>MohamedSharief</dc:creator>
      <dc:date>2017-07-25T08:10:19Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption for Chrome Browser</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-for-chrome-browser/m-p/168266#M53638</link>
      <description>&lt;P&gt;Thanks M.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We noticed that&amp;nbsp;if the certificate used for forward proxy SSL is not SHA 256 then the Google Chrome browser will not behave. Our Windows PKI is still producing SHA 1 certificates and would need to be updated to be of any use for issuing these certs to the Palo.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Once the SHA 256 cert generated from the Palo is imported to the test PC’s then Google Chrome immediately sees it in the store and is happy to use this for SSL inspection.&amp;nbsp; A SHA1 cert from our Windows PKI does not show up in Chrome and is ignored for SSL decryption, which was the start of&amp;nbsp;this issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It would seem that Google is on the fast track to make SHA 1 a bit of history, while IE11 is still happy to use SHA1 for security.&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jul 2017 22:48:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-for-chrome-browser/m-p/168266#M53638</guid>
      <dc:creator>Farzana</dc:creator>
      <dc:date>2017-07-25T22:48:37Z</dc:date>
    </item>
  </channel>
</rss>

