<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Issue with Windows Insider Updates when using SSL Decrypt in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-windows-insider-updates-when-using-ssl-decrypt/m-p/214043#M62229</link>
    <description>&lt;P&gt;PAN-OS 8.0.x&lt;/P&gt;&lt;P&gt;We have users not receiving updates for Windows Insider Program builds when SSL decryption is enabled. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does anyone know what changes need to be made to make this work?&amp;nbsp; I've solved a few other SSL decryption issues where decrypt-exceptions needed to be added or the CA imported as a trusted CA in the PA, but so far I have been unable to identify what needs to be done for this.&amp;nbsp; I've seen&amp;nbsp;&lt;STRONG&gt;decrypt-error&lt;/STRONG&gt; and&amp;nbsp;&lt;STRONG&gt;decrypt-cert-validation&lt;/STRONG&gt; coming from this PC around the time of an update check so I know a cert probably needs to be added to the PA but have not yet been able to identify which one.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I temporarily used a decrypt profile that does not verify the CA but that alone did not fix it so we'll likely also need to add some exceptions as well.&amp;nbsp; This was for testing - I am not going to keep a decrypt profile that does not verify CA.&lt;/P&gt;</description>
    <pubDate>Fri, 11 May 2018 16:10:35 GMT</pubDate>
    <dc:creator>Demast</dc:creator>
    <dc:date>2018-05-11T16:10:35Z</dc:date>
    <item>
      <title>Issue with Windows Insider Updates when using SSL Decrypt</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-windows-insider-updates-when-using-ssl-decrypt/m-p/214043#M62229</link>
      <description>&lt;P&gt;PAN-OS 8.0.x&lt;/P&gt;&lt;P&gt;We have users not receiving updates for Windows Insider Program builds when SSL decryption is enabled. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does anyone know what changes need to be made to make this work?&amp;nbsp; I've solved a few other SSL decryption issues where decrypt-exceptions needed to be added or the CA imported as a trusted CA in the PA, but so far I have been unable to identify what needs to be done for this.&amp;nbsp; I've seen&amp;nbsp;&lt;STRONG&gt;decrypt-error&lt;/STRONG&gt; and&amp;nbsp;&lt;STRONG&gt;decrypt-cert-validation&lt;/STRONG&gt; coming from this PC around the time of an update check so I know a cert probably needs to be added to the PA but have not yet been able to identify which one.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I temporarily used a decrypt profile that does not verify the CA but that alone did not fix it so we'll likely also need to add some exceptions as well.&amp;nbsp; This was for testing - I am not going to keep a decrypt profile that does not verify CA.&lt;/P&gt;</description>
      <pubDate>Fri, 11 May 2018 16:10:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-with-windows-insider-updates-when-using-ssl-decrypt/m-p/214043#M62229</guid>
      <dc:creator>Demast</dc:creator>
      <dc:date>2018-05-11T16:10:35Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with Windows Insider Updates when using SSL Decrypt</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-windows-insider-updates-when-using-ssl-decrypt/m-p/214050#M62230</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I could be wrong, but I think it uses the same update sites?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://technet.microsoft.com/en-us/library/bb693717.aspx" target="_blank"&gt;https://technet.microsoft.com/en-us/library/bb693717.aspx&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;</description>
      <pubDate>Fri, 11 May 2018 16:16:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-with-windows-insider-updates-when-using-ssl-decrypt/m-p/214050#M62230</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-05-11T16:16:13Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with Windows Insider Updates when using SSL Decrypt</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-windows-insider-updates-when-using-ssl-decrypt/m-p/214054#M62233</link>
      <description>&lt;P&gt;I don't know in great detail about how it works, but I suspect it probably works differently.&amp;nbsp; Normal windows downloads the updates - Insider updates download the build updates to upgrade to the next build.&amp;nbsp; I believe this is more like an image then an update package.&lt;/P&gt;</description>
      <pubDate>Fri, 11 May 2018 16:33:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-with-windows-insider-updates-when-using-ssl-decrypt/m-p/214054#M62233</guid>
      <dc:creator>Demast</dc:creator>
      <dc:date>2018-05-11T16:33:06Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with Windows Insider Updates when using SSL Decrypt</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-windows-insider-updates-when-using-ssl-decrypt/m-p/214065#M62236</link>
      <description>&lt;P&gt;Just curious, but do you know if the normal Windows update sites need to have SSL decryption exceptions in order to work with PAN-OS 8.0? &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 11 May 2018 18:52:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-with-windows-insider-updates-when-using-ssl-decrypt/m-p/214065#M62236</guid>
      <dc:creator>Demast</dc:creator>
      <dc:date>2018-05-11T18:52:28Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with Windows Insider Updates when using SSL Decrypt</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-windows-insider-updates-when-using-ssl-decrypt/m-p/214067#M62237</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;All the URL's in that article should not be decrypted.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Fri, 11 May 2018 18:54:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-with-windows-insider-updates-when-using-ssl-decrypt/m-p/214067#M62237</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-05-11T18:54:06Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with Windows Insider Updates when using SSL Decrypt</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-windows-insider-updates-when-using-ssl-decrypt/m-p/214098#M62240</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1075"&gt;@Demast&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;It kind of sounds like you could be running into an instance that a lot of enterprises find themselves in, and I'm going to make some assumptions about your enviroment that may or may not be true.&lt;/P&gt;&lt;P&gt;1) You utilize WSUS/SCCM for the 'normal' endpoints to download their updates.&lt;/P&gt;&lt;P&gt;2) You don't run with SSL-Decryption either on your entire server VLAN or specifically for the WSUS/SCCM server.&lt;/P&gt;&lt;P&gt;3) These are the only users you have that require updates directly from Microsoft, as all others would update from the server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regardless of what the situation is, &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt; is right that you can't decrypt this traffic due to how the computer and Microsoft authenticate when pulling the updates from Microsoft's servers. I have multiple users utilizing the Insider program, myself included, and I didn't need to modify anything to get this to function correctly.&lt;/P&gt;</description>
      <pubDate>Sun, 13 May 2018 02:35:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-with-windows-insider-updates-when-using-ssl-decrypt/m-p/214098#M62240</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-05-13T02:35:45Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with Windows Insider Updates when using SSL Decrypt</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-windows-insider-updates-when-using-ssl-decrypt/m-p/214169#M62251</link>
      <description>&lt;P&gt;I am a little confused.&amp;nbsp; You said you didn't need to modify anything to get it working but you also said you can't decrypt this traffic.&amp;nbsp; Do you mean that you did needed to add to the no-decrypt URLs as per the article for the regular windows updates but after that you did not need to do anything else for windows insider updates?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You are right, we are early in the outgoing on 443 decryption so it is not yet widespread, and also most windows workstations and servers do get central updates.&amp;nbsp; We are on all Windows 10 if it makes a difference, I have read some things saying it might get updates differently or from a different place.&amp;nbsp; I was hoping I would not need to add decrypt exceptions for windows since some exist by default, but if needed I will add exceptions.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 14 May 2018 14:20:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-with-windows-insider-updates-when-using-ssl-decrypt/m-p/214169#M62251</guid>
      <dc:creator>Demast</dc:creator>
      <dc:date>2018-05-14T14:20:09Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with Windows Insider Updates when using SSL Decrypt</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-windows-insider-updates-when-using-ssl-decrypt/m-p/214179#M62254</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1075"&gt;@Demast&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;What I was trying to say is that I didn't need to modify anything for my users running Insider builds outside of the decryption exceptions that I've already put in place for other users to pull normal Windows Updates. As&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&amp;nbsp;mentioned Updates require a few decryption exceptions for them to work properly.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 14 May 2018 15:00:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-with-windows-insider-updates-when-using-ssl-decrypt/m-p/214179#M62254</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-05-14T15:00:25Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with Windows Insider Updates when using SSL Decrypt</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-windows-insider-updates-when-using-ssl-decrypt/m-p/214192#M62255</link>
      <description>&lt;P&gt;Thank you, I will give it a try and see what happens.&lt;/P&gt;</description>
      <pubDate>Mon, 14 May 2018 15:02:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-with-windows-insider-updates-when-using-ssl-decrypt/m-p/214192#M62255</guid>
      <dc:creator>Demast</dc:creator>
      <dc:date>2018-05-14T15:02:12Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with Windows Insider Updates when using SSL Decrypt</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-windows-insider-updates-when-using-ssl-decrypt/m-p/214484#M62331</link>
      <description>&lt;P&gt;I found this in &lt;A href="https://live.paloaltonetworks.com/t5/General-Topics/SSL-Decrypt-amp-Windows-Updates/m-p/168600#M53674" target="_self"&gt;another live community posting&lt;/A&gt; regarding Windows updates.&amp;nbsp; The exceptions were:&lt;/P&gt;&lt;P&gt;*.do.dsp.mp.microsoft.com&lt;/P&gt;&lt;P&gt;*.delivery.mp.microsoft.com&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Once I added this, it started working.&lt;/P&gt;</description>
      <pubDate>Wed, 16 May 2018 19:13:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-with-windows-insider-updates-when-using-ssl-decrypt/m-p/214484#M62331</guid>
      <dc:creator>Demast</dc:creator>
      <dc:date>2018-05-16T19:13:49Z</dc:date>
    </item>
  </channel>
</rss>

