<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: External dynamic list failing at refresh in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/external-dynamic-list-failing-at-refresh/m-p/217094#M62820</link>
    <description>&lt;P&gt;There is a bug that EDLs cannot be downloaded from https servers which only support TLS. Fixed in PAN-OS 8.0.7 or higher. Or change the webserver to allow SSLv3.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PAN-85047: Fixed an issue where the firewall failed to retrieve a domain list from an external dynamic list (EDL) server over a TLSv1.0 connection.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However your issue seems to be different. Sounds more like missing certificate in trusted store.&lt;/P&gt;</description>
    <pubDate>Thu, 07 Jun 2018 20:44:21 GMT</pubDate>
    <dc:creator>Anon1</dc:creator>
    <dc:date>2018-06-07T20:44:21Z</dc:date>
    <item>
      <title>External dynamic list failing at refresh</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/external-dynamic-list-failing-at-refresh/m-p/217042#M62807</link>
      <description>&lt;P&gt;This should be simple, but i have been at it for much too long and support hasnt been able to figure it out. Hoping someone here has had this issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a simple EDL to allow (type IP) the source is https and it's a txt file on a bitbucket repo.&lt;/P&gt;&lt;P&gt;I have added the certs (root and intermediate) directly from the CA that signed them (well known CA, not internal). the root had the box checked "trusted root ca cert"&lt;/P&gt;&lt;P&gt;I have created a cert profile with the certs&lt;/P&gt;&lt;P&gt;When I go to refresh I see the refresh job fail with the follwing:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;EDLRefresh job failed. Cert validation failed&lt;BR /&gt;&lt;BR /&gt;EDL server certificate authentication failed. The associated external dynamic list has been removed, which might impact your policy. EDL Name: TEST-EDL-IP, EDL Source URL: &lt;A href="https://blah.blah.blah.txt" target="_blank"&gt;https://blah.blah.blah.txt&lt;/A&gt;, CN: *.blah.com, Reason: self signed certificate in certificate chain&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have tried it on 3 different firewalls and all fail in the same way. All are on panos 8. I have tried it with an http source (without a cert profile) and it works as it's supposed to, so at least I know the EDL object and rules, etc work. I think&amp;nbsp;it might&amp;nbsp;be a stupid simple thing that I am missing, but I can't figure it out. I have no hair. Thank you for your assistance&lt;/P&gt;</description>
      <pubDate>Thu, 07 Jun 2018 18:14:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/external-dynamic-list-failing-at-refresh/m-p/217042#M62807</guid>
      <dc:creator>rperez-mz</dc:creator>
      <dc:date>2018-06-07T18:14:34Z</dc:date>
    </item>
    <item>
      <title>Re: External dynamic list failing at refresh</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/external-dynamic-list-failing-at-refresh/m-p/217051#M62808</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/88480"&gt;@rperez-mz&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Do you have any intermediate certs that maybe need to be added?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Jun 2018 18:14:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/external-dynamic-list-failing-at-refresh/m-p/217051#M62808</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-06-07T18:14:55Z</dc:date>
    </item>
    <item>
      <title>Re: External dynamic list failing at refresh</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/external-dynamic-list-failing-at-refresh/m-p/217052#M62809</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&lt;/P&gt;&lt;P&gt;both root and intermediate have been added. the cert itself for bitbucket was also added, but it can't be included in the cert profile for some reason... not sure it supposed to be anyway.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Jun 2018 18:18:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/external-dynamic-list-failing-at-refresh/m-p/217052#M62809</guid>
      <dc:creator>rperez-mz</dc:creator>
      <dc:date>2018-06-07T18:18:00Z</dc:date>
    </item>
    <item>
      <title>Re: External dynamic list failing at refresh</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/external-dynamic-list-failing-at-refresh/m-p/217094#M62820</link>
      <description>&lt;P&gt;There is a bug that EDLs cannot be downloaded from https servers which only support TLS. Fixed in PAN-OS 8.0.7 or higher. Or change the webserver to allow SSLv3.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PAN-85047: Fixed an issue where the firewall failed to retrieve a domain list from an external dynamic list (EDL) server over a TLSv1.0 connection.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However your issue seems to be different. Sounds more like missing certificate in trusted store.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Jun 2018 20:44:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/external-dynamic-list-failing-at-refresh/m-p/217094#M62820</guid>
      <dc:creator>Anon1</dc:creator>
      <dc:date>2018-06-07T20:44:21Z</dc:date>
    </item>
    <item>
      <title>Re: External dynamic list failing at refresh</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/external-dynamic-list-failing-at-refresh/m-p/217103#M62826</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/88480"&gt;@rperez-mz&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;As&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/715"&gt;@Anon1&lt;/a&gt;&amp;nbsp;mentioned all of the errors kind of point to you missing something within the certificate chain that is causing the issue; I would verify that it's all present and contact TAC so they can look over the configuration in its entirety&amp;nbsp;if you continue to have issues.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Jun 2018 20:59:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/external-dynamic-list-failing-at-refresh/m-p/217103#M62826</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-06-07T20:59:58Z</dc:date>
    </item>
    <item>
      <title>Re: External dynamic list failing at refresh</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/external-dynamic-list-failing-at-refresh/m-p/217643#M62949</link>
      <description>&lt;P&gt;Thank you&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/715"&gt;@Anon1&lt;/a&gt;&amp;nbsp;and&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;you were right. I thought I had the whole chain. I just got in touch with the issuer and asked for the root/issuing, etc certs and indeed they were completelty different. That resolved it.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jun 2018 00:24:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/external-dynamic-list-failing-at-refresh/m-p/217643#M62949</guid>
      <dc:creator>rperez-mz</dc:creator>
      <dc:date>2018-06-13T00:24:22Z</dc:date>
    </item>
  </channel>
</rss>

