<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ms-update and MS Internet Explorer root CA in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ms-update-and-ms-internet-explorer-root-ca/m-p/8983#M6564</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Mattieb,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have seen similar issue and I want to share some screenshots in creating a custom app just to make it easy if some one faces the issue.&lt;/P&gt;&lt;P&gt;Steps:&lt;/P&gt;&lt;P&gt;1&amp;gt; Create custom app. 2&amp;gt; Apply in a security rule before the rule which blocks MS-Update APP rule. 3&amp;gt; Clear any existing matching sessions so the new sessions to hit the new app.&lt;/P&gt;&lt;P&gt;&lt;IMG alt="ms-crl-1.PNG.png" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/11637_ms-crl-1.PNG.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="ms-crl-2.PNG.png" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/11638_ms-crl-2.PNG.png" style="width: 620px; height: 405px;" /&gt;&lt;/P&gt;&lt;P&gt;Wireshark info:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="ms-crl-3.PNG.png" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/11639_ms-crl-3.PNG.png" style="width: 620px; height: 170px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 13 Feb 2014 16:13:23 GMT</pubDate>
    <dc:creator>Phoenix</dc:creator>
    <dc:date>2014-02-13T16:13:23Z</dc:date>
    <item>
      <title>ms-update and MS Internet Explorer root CA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ms-update-and-ms-internet-explorer-root-ca/m-p/8980#M6561</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;In my company, we explicitely block the application ms-update to control workstations update policy.&lt;/P&gt;&lt;P&gt;But I realized that MS internet explorer tries to update its "root list sequence number" at each HTTPS connection.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The file that MS IE tries to access is at :&lt;/P&gt;&lt;P&gt;www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In your opinion, what would be the best approach to block ms-update except this Internet Explorer access ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Jul 2013 14:46:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ms-update-and-ms-internet-explorer-root-ca/m-p/8980#M6561</guid>
      <dc:creator>mattieub</dc:creator>
      <dc:date>2013-07-22T14:46:49Z</dc:date>
    </item>
    <item>
      <title>Re: ms-update and MS Internet Explorer root CA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ms-update-and-ms-internet-explorer-root-ca/m-p/8981#M6562</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;You can&amp;nbsp; create a custom application based on the url information.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;and create a security rule that allow this application and place it above the rule which deny the windows update.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/docs/DOC-1966"&gt;https://live.paloaltonetworks.com/docs/DOC-1966&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Jul 2013 15:38:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ms-update-and-ms-internet-explorer-root-ca/m-p/8981#M6562</guid>
      <dc:creator>Gregoux</dc:creator>
      <dc:date>2013-07-22T15:38:41Z</dc:date>
    </item>
    <item>
      <title>Re: ms-update and MS Internet Explorer root CA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ms-update-and-ms-internet-explorer-root-ca/m-p/8982#M6563</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Thanks for the tip. It works as expected.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Jul 2013 14:51:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ms-update-and-ms-internet-explorer-root-ca/m-p/8982#M6563</guid>
      <dc:creator>mattieub</dc:creator>
      <dc:date>2013-07-23T14:51:32Z</dc:date>
    </item>
    <item>
      <title>Re: ms-update and MS Internet Explorer root CA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ms-update-and-ms-internet-explorer-root-ca/m-p/8983#M6564</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Mattieb,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have seen similar issue and I want to share some screenshots in creating a custom app just to make it easy if some one faces the issue.&lt;/P&gt;&lt;P&gt;Steps:&lt;/P&gt;&lt;P&gt;1&amp;gt; Create custom app. 2&amp;gt; Apply in a security rule before the rule which blocks MS-Update APP rule. 3&amp;gt; Clear any existing matching sessions so the new sessions to hit the new app.&lt;/P&gt;&lt;P&gt;&lt;IMG alt="ms-crl-1.PNG.png" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/11637_ms-crl-1.PNG.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="ms-crl-2.PNG.png" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/11638_ms-crl-2.PNG.png" style="width: 620px; height: 405px;" /&gt;&lt;/P&gt;&lt;P&gt;Wireshark info:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="ms-crl-3.PNG.png" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/11639_ms-crl-3.PNG.png" style="width: 620px; height: 170px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Feb 2014 16:13:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ms-update-and-ms-internet-explorer-root-ca/m-p/8983#M6564</guid>
      <dc:creator>Phoenix</dc:creator>
      <dc:date>2014-02-13T16:13:23Z</dc:date>
    </item>
  </channel>
</rss>

