<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Panos 8 inbound ssl inspection in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/panos-8-inbound-ssl-inspection/m-p/183094#M56318</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have tried to turn this on and well...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My server site has server cert and 1 intermediary cert.&lt;/P&gt;&lt;P&gt;With decryption on it strips the int-ca from the reply ? I find that rather strange why it would do that.&lt;/P&gt;&lt;P&gt;So this makes any request to that site fail&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sat, 21 Oct 2017 21:21:08 GMT</pubDate>
    <dc:creator>Alex_Samad</dc:creator>
    <dc:date>2017-10-21T21:21:08Z</dc:date>
    <item>
      <title>Panos 8 inbound ssl inspection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panos-8-inbound-ssl-inspection/m-p/183094#M56318</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have tried to turn this on and well...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My server site has server cert and 1 intermediary cert.&lt;/P&gt;&lt;P&gt;With decryption on it strips the int-ca from the reply ? I find that rather strange why it would do that.&lt;/P&gt;&lt;P&gt;So this makes any request to that site fail&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 21 Oct 2017 21:21:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panos-8-inbound-ssl-inspection/m-p/183094#M56318</guid>
      <dc:creator>Alex_Samad</dc:creator>
      <dc:date>2017-10-21T21:21:08Z</dc:date>
    </item>
    <item>
      <title>Re: Panos 8 inbound ssl inspection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panos-8-inbound-ssl-inspection/m-p/183289#M56344</link>
      <description>&lt;P&gt;When you do the import of the cert from your web server to the firewall, make sure you're combining the server cert with the intermediate CA. Here are some steps to do so:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/How-to-Install-a-Chained-Certificate-Signed-by-a-Public-CA/ta-p/55523" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/How-to-Install-a-Chained-Certificate-Signed-by-a-Public-CA/ta-p/55523&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Prior to PAN-OS 8.0, inbound inspection was completely passive. In 8.0, with ECC and DHE support it takes a more active role, so you need to import the full chain (not the root CA though).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that helps!&lt;/P&gt;</description>
      <pubDate>Mon, 23 Oct 2017 17:33:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panos-8-inbound-ssl-inspection/m-p/183289#M56344</guid>
      <dc:creator>gwesson</dc:creator>
      <dc:date>2017-10-23T17:33:47Z</dc:date>
    </item>
  </channel>
</rss>

