<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Inbound Decryption Advice to overcome Decrypt error in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/inbound-decryption-advice-to-overcome-decrypt-error/m-p/193083#M57934</link>
    <description>&lt;P&gt;To complete the story: Soon after my post in August I was informed that a flaw in implementing Extended Master Secret would be fixed soon. An update issued soon thereafter fixed the issue.&lt;/P&gt;</description>
    <pubDate>Tue, 26 Dec 2017 23:08:07 GMT</pubDate>
    <dc:creator>SteveWright</dc:creator>
    <dc:date>2017-12-26T23:08:07Z</dc:date>
    <item>
      <title>Inbound Decryption Advice to overcome Decrypt error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/inbound-decryption-advice-to-overcome-decrypt-error/m-p/173288#M54569</link>
      <description>&lt;P&gt;I am asking for help to get SSL Inbound decryption working. I have read all the posts and tried everything I can think of but I keep getting the decrypt error status so I may have a basic misunderstanding. If someone has an insight into what I am doing wrong after reading the information below I would be grateful to receive it.&lt;/P&gt;&lt;P&gt;The web server is restricted by group policy to a few encryption algorithms that the Palo Alto firewall supports being:&lt;/P&gt;&lt;P&gt;• TLS_RSA_WITH_AES_128_CBC_SHA256&lt;/P&gt;&lt;P&gt;• TLS_RSA_WITH_AES_256_CBC_SHA256&lt;/P&gt;&lt;P&gt;• TLS_RSA_WITH_AES_128_GCM_SHA256 (0x009c)&lt;/P&gt;&lt;P&gt;• TLS_RSA_WITH_AES_256_GCM_SHA384 (0x009d)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have tried a certificate issued by “GoDaddy” and also a certificate issued by my internal CA but I get the same result from each. The clients trust both certificate authorities. When the client connects, one packet appears to be decrypted but the rest produce a Decrypt error. A capture shows no errors.&lt;/P&gt;&lt;P&gt;The “Client Hello” appears normal listing its supported encryption algorithms followed by a “Server hello, Change Cipher Spec” which looks like it sets the Encryption algorithm to “TLS_RSA_with_AES_128_CBC_SHA256”. This is followed by a “Change Cipher Spec, Encrypted Handshake Message” which I am unsure what this does. These all appear below.&lt;/P&gt;&lt;P&gt;Client Hello&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Client hello" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/10927iB199C50F1C78F2A1/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="ClientHello.jpg" alt="Client hello" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Client hello&lt;/span&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Server Hello" style="width: 606px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/10928i8019BB80970512AF/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="ServerHello.jpg" alt="Server Hello" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Server Hello&lt;/span&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Change Cipher" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/10929iB7BB5BCA511573D9/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="ChangeCipher.png" alt="Change Cipher" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Change Cipher&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 26 Aug 2017 11:50:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/inbound-decryption-advice-to-overcome-decrypt-error/m-p/173288#M54569</guid>
      <dc:creator>SteveWright</dc:creator>
      <dc:date>2017-08-26T11:50:38Z</dc:date>
    </item>
    <item>
      <title>Re: Inbound Decryption Advice to overcome Decrypt error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/inbound-decryption-advice-to-overcome-decrypt-error/m-p/173314#M54576</link>
      <description>&lt;P&gt;I kept researching and found a post by Anil Kumar that indicated the issue may be the TLS Extension "&lt;SPAN&gt;Extended Master Secret&lt;/SPAN&gt;". If I disable this on the server ad the client, decryption works. Disabling this only on the server seems to be insufficient for decryption to work. The problem now is what to do. Do I downgrade from TLS to SSL or do I forgo decryption. I would be interested in your comment on these options.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does anyone know if/when Palo Alto will support this Extension for decryption?&lt;/P&gt;</description>
      <pubDate>Sat, 26 Aug 2017 21:49:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/inbound-decryption-advice-to-overcome-decrypt-error/m-p/173314#M54576</guid>
      <dc:creator>SteveWright</dc:creator>
      <dc:date>2017-08-26T21:49:22Z</dc:date>
    </item>
    <item>
      <title>Re: Inbound Decryption Advice to overcome Decrypt error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/inbound-decryption-advice-to-overcome-decrypt-error/m-p/193083#M57934</link>
      <description>&lt;P&gt;To complete the story: Soon after my post in August I was informed that a flaw in implementing Extended Master Secret would be fixed soon. An update issued soon thereafter fixed the issue.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Dec 2017 23:08:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/inbound-decryption-advice-to-overcome-decrypt-error/m-p/193083#M57934</guid>
      <dc:creator>SteveWright</dc:creator>
      <dc:date>2017-12-26T23:08:07Z</dc:date>
    </item>
  </channel>
</rss>

