<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic OCSP App-ID fail in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ocsp-app-id-fail/m-p/189831#M57412</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;is anyone using ocsp as single app in a rule ? It's sometimes failing to match, seen as "web-browsing" although on very easy to recognize URLs such as ocsp.comodoca.com. Quite annoying when you debug a third-party software failing to setup because of this but only mentionning "cert chain failed".&lt;/P&gt;&lt;P&gt;App version 752-4343 on v8.0.5.&lt;/P&gt;&lt;P&gt;thanks !&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 04 Dec 2017 16:27:01 GMT</pubDate>
    <dc:creator>prospectfr</dc:creator>
    <dc:date>2017-12-04T16:27:01Z</dc:date>
    <item>
      <title>OCSP App-ID fail</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ocsp-app-id-fail/m-p/189831#M57412</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;is anyone using ocsp as single app in a rule ? It's sometimes failing to match, seen as "web-browsing" although on very easy to recognize URLs such as ocsp.comodoca.com. Quite annoying when you debug a third-party software failing to setup because of this but only mentionning "cert chain failed".&lt;/P&gt;&lt;P&gt;App version 752-4343 on v8.0.5.&lt;/P&gt;&lt;P&gt;thanks !&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Dec 2017 16:27:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ocsp-app-id-fail/m-p/189831#M57412</guid>
      <dc:creator>prospectfr</dc:creator>
      <dc:date>2017-12-04T16:27:01Z</dc:date>
    </item>
    <item>
      <title>Re: OCSP App-ID fail</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ocsp-app-id-fail/m-p/189899#M57415</link>
      <description>&lt;P&gt;The domain name itself is not used for App-ID, as the domain doesn't necessarily dictate what is there. There could easily be non-OCSP content there despite the hostname.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That said, if you have (or can get) a packet capture of the issue happening, open up a support ticket so it can be given to the appropriate folks who handle the App-ID information. I've never seen that issue, but admittadly I am not blocking web-browsing so either way it would work in my environment.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Dec 2017 19:05:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ocsp-app-id-fail/m-p/189899#M57415</guid>
      <dc:creator>gwesson</dc:creator>
      <dc:date>2017-12-04T19:05:27Z</dc:date>
    </item>
  </channel>
</rss>

