<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Decryption with Elliptical Curve DSA PAN -OS 8.0.x in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/decryption-with-elliptical-curve-dsa-pan-os-8-0-x/m-p/178443#M55527</link>
    <description>&lt;P&gt;Hi Team,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;New features and improvement in version 8 allows for additional cipher algorithms to be decrypted and the re-encrypted to check for malicious content.&lt;/P&gt;&lt;P&gt;Can generate a self-signed or a cert off MS Certificate Authority.&lt;/P&gt;&lt;P&gt;Many customers have the decryption cert with the RSA Algorithm already configured. Need to set up the additional one as below to take advantage of the new feature. So will have two forward trust and two forward untrust.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;The ECDSA one is then preferred and the PAN device will fail back to the RSA one if required.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="RSA.GIF" style="width: 500px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/11466i05EA8DC7F9C2E5B9/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="RSA.GIF" alt="RSA.GIF" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ED.GIF" style="width: 500px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/11467i4798D4BC817F71FD/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="ED.GIF" alt="ED.GIF" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To generate a self signed one, is simple enough, just select the different algorithm as below.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="generate.GIF" style="width: 262px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/11468i448FF9CAC78E51DF/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="generate.GIF" alt="generate.GIF" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Done some tests with same recently and seems to be working ok, if any trouble with same contact your support provider,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rob&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 25 Sep 2017 08:49:01 GMT</pubDate>
    <dc:creator>DonohoeRobert</dc:creator>
    <dc:date>2017-09-25T08:49:01Z</dc:date>
    <item>
      <title>Decryption with Elliptical Curve DSA PAN -OS 8.0.x</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/decryption-with-elliptical-curve-dsa-pan-os-8-0-x/m-p/178443#M55527</link>
      <description>&lt;P&gt;Hi Team,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;New features and improvement in version 8 allows for additional cipher algorithms to be decrypted and the re-encrypted to check for malicious content.&lt;/P&gt;&lt;P&gt;Can generate a self-signed or a cert off MS Certificate Authority.&lt;/P&gt;&lt;P&gt;Many customers have the decryption cert with the RSA Algorithm already configured. Need to set up the additional one as below to take advantage of the new feature. So will have two forward trust and two forward untrust.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;The ECDSA one is then preferred and the PAN device will fail back to the RSA one if required.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="RSA.GIF" style="width: 500px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/11466i05EA8DC7F9C2E5B9/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="RSA.GIF" alt="RSA.GIF" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ED.GIF" style="width: 500px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/11467i4798D4BC817F71FD/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="ED.GIF" alt="ED.GIF" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To generate a self signed one, is simple enough, just select the different algorithm as below.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="generate.GIF" style="width: 262px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/11468i448FF9CAC78E51DF/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="generate.GIF" alt="generate.GIF" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Done some tests with same recently and seems to be working ok, if any trouble with same contact your support provider,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rob&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Sep 2017 08:49:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/decryption-with-elliptical-curve-dsa-pan-os-8-0-x/m-p/178443#M55527</guid>
      <dc:creator>DonohoeRobert</dc:creator>
      <dc:date>2017-09-25T08:49:01Z</dc:date>
    </item>
    <item>
      <title>Re: Decryption with Elliptical Curve DSA PAN -OS 8.0.x</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/decryption-with-elliptical-curve-dsa-pan-os-8-0-x/m-p/178482#M55537</link>
      <description>&lt;P&gt;FYI: There is no need to generate a new Root Cert with an EC Key. PAN-OS 8 allows you to decrypt connections to websites with ECDSA certs also with an RSA Decryption certificate.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;--&amp;gt; For example: &lt;A href="https://ecdsa.scotthelme.co.uk/" target="_blank"&gt;https://ecdsa.scotthelme.co.uk/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Sep 2017 10:02:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/decryption-with-elliptical-curve-dsa-pan-os-8-0-x/m-p/178482#M55537</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2017-09-25T10:02:27Z</dc:date>
    </item>
  </channel>
</rss>

