<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSL decryption error in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-error/m-p/188679#M57226</link>
    <description>&lt;P&gt;It seems when you have the decryption rule enabled, firewall is failing to decrypt the session and ending with cert validation error.&lt;/P&gt;&lt;P&gt;Open up a case with TAC to check why the decryption is failing.&lt;/P&gt;&lt;P&gt;There was a bug reported on 7.1.4 code for 3k devices where the decryption failed to proxy memory pool exhaustion and was fixed on 7.1.11 or 8.0.3&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But getting a validation from TAC engineer would be the first step here.&lt;/P&gt;</description>
    <pubDate>Fri, 24 Nov 2017 17:29:52 GMT</pubDate>
    <dc:creator>mgarg</dc:creator>
    <dc:date>2017-11-24T17:29:52Z</dc:date>
    <item>
      <title>SSL decryption error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-error/m-p/188627#M57217</link>
      <description>&lt;P&gt;&lt;SPAN&gt;I had configured SSL decryption on PaloAlto VM-50 before 6-7 months ago. There was working normally till today. Today some users get below error when they want to enter site. There is shown “decrypt-cert-validation” message on PaloAlto traffic logs. There isn’t shown any error on PaloAlto and on user computer When I disable SSL decryption rule.&lt;/SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image005.jpg" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/12609i2E15CAE2197A0F6B/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image005.jpg" alt="image005.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Nov 2017 10:22:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-error/m-p/188627#M57217</guid>
      <dc:creator>Radmin_85</dc:creator>
      <dc:date>2017-11-24T10:22:04Z</dc:date>
    </item>
    <item>
      <title>Re: SSL decryption error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-error/m-p/188679#M57226</link>
      <description>&lt;P&gt;It seems when you have the decryption rule enabled, firewall is failing to decrypt the session and ending with cert validation error.&lt;/P&gt;&lt;P&gt;Open up a case with TAC to check why the decryption is failing.&lt;/P&gt;&lt;P&gt;There was a bug reported on 7.1.4 code for 3k devices where the decryption failed to proxy memory pool exhaustion and was fixed on 7.1.11 or 8.0.3&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But getting a validation from TAC engineer would be the first step here.&lt;/P&gt;</description>
      <pubDate>Fri, 24 Nov 2017 17:29:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-error/m-p/188679#M57226</guid>
      <dc:creator>mgarg</dc:creator>
      <dc:date>2017-11-24T17:29:52Z</dc:date>
    </item>
    <item>
      <title>Re: SSL decryption error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-error/m-p/188748#M57239</link>
      <description>&lt;P&gt;Any other suggestions? it was working until&amp;nbsp; 4 days ago&lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2017 05:50:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-error/m-p/188748#M57239</guid>
      <dc:creator>Radmin_85</dc:creator>
      <dc:date>2017-11-27T05:50:14Z</dc:date>
    </item>
    <item>
      <title>Re: SSL decryption error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-error/m-p/188862#M57257</link>
      <description>&lt;P&gt;As previously mentioned, have you contacted TAC?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Aside from that, what version of PAN-OS are you running?&amp;nbsp; On two seperate occurances my company ran into SSL decyption issues 5060 HA-pair running 7.1.6 where we hit a bug and needed to upgrade to 7.1.10.&amp;nbsp; Then again where we needed to upgrade to 7.1.12 from 7.1.10.&amp;nbsp; (We got the same log message you did in traffic logs)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It's very likely you could be running into the same bugs we did, but the only way to confirm is to open a TAC case.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In our case we simply failed to passive HA device and I think rebooted the previously active 5060.&amp;nbsp; But the end fix was upgrading out of the bug.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2017 22:21:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-error/m-p/188862#M57257</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2017-11-27T22:21:05Z</dc:date>
    </item>
    <item>
      <title>Re: SSL decryption error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-error/m-p/188875#M57265</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/70049"&gt;@Radmin_85&lt;/a&gt; wrote:&lt;BR /&gt;&lt;P&gt;Any other suggestions? it was working until&amp;nbsp; 4 days ago&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I looked through my old cases...Just for clarity the bugs were in 7.1.6 and 7.1.10:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;7.1.10 - Bug - PAN‐75337&lt;BR /&gt;7.1.6&amp;nbsp; &amp;nbsp;- Bug - PAN-76535&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;*Edit* --&amp;nbsp; (I'd still suggest a case with TAC)&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'll bet you're hitting &lt;SPAN&gt;Bug - PAN-76535.&amp;nbsp; The summary of my case on 7.1.6 is below:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"&lt;SPAN&gt;&amp;nbsp;Session end-reason "decrypt-cert-validation". Client browser receives "ERR_SSL_VERSION_OR_CIPHER_MISMATCH".&amp;nbsp;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Reboot fixes the issue."&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2017 22:29:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-error/m-p/188875#M57265</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2017-11-27T22:29:15Z</dc:date>
    </item>
  </channel>
</rss>

