<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSL Decryption breaks certain website functionality in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-breaks-certain-website-functionality/m-p/229197#M65900</link>
    <description>&lt;P&gt;You're talking about inbpund SSL decryption, right? It can't be the issue with certificate pinning as certificate is the same (just moved from server to PA). Basically in SSL decryption scenario PA shoul be just listening to decrypted traffic and understand it because it has the apropriate certificate with private key. But in fact it does alter a session a bit as a colleague told me from debugging session with PA support. However for any details and logs about it you will probably have to ask support.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Another could be some external components having issues with decrytpion (if your application is using such).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 03 Sep 2018 06:59:53 GMT</pubDate>
    <dc:creator>santonic</dc:creator>
    <dc:date>2018-09-03T06:59:53Z</dc:date>
    <item>
      <title>SSL Decryption breaks certain website functionality</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-breaks-certain-website-functionality/m-p/228945#M65805</link>
      <description>So I’ve enabled SSL decryption and as expected some sites or applications fail when it’s turned on. No problem I can exclude the domain from decryption.&lt;BR /&gt;&lt;BR /&gt;I have a special case though, in the fact that one of these web applications is a service that my company is developing. When decryption is on it breaks screensharimg from our web application. The developers have asked me to look into this from the FW side of things to assist in them fixing it, as they would like it to work with decryption enabled.&lt;BR /&gt;&lt;BR /&gt;What common reasons are there for ssl decryption to break websites? What can I pull off the firewall to assist them?</description>
      <pubDate>Thu, 30 Aug 2018 18:58:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-breaks-certain-website-functionality/m-p/228945#M65805</guid>
      <dc:creator>welly_59</dc:creator>
      <dc:date>2018-08-30T18:58:40Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption breaks certain website functionality</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-breaks-certain-website-functionality/m-p/228956#M65808</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Are they using certificate pinning? I know that is one reason decryption breaks an app. Here are some resources to look through:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/SSL-decryption-resource-list/ta-p/70397" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/SSL-decryption-resource-list/ta-p/70397&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There are some apps that just dont like it and cant be decrypted, Skype is just one example.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Aug 2018 20:57:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-breaks-certain-website-functionality/m-p/228956#M65808</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-08-30T20:57:17Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption breaks certain website functionality</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-breaks-certain-website-functionality/m-p/229197#M65900</link>
      <description>&lt;P&gt;You're talking about inbpund SSL decryption, right? It can't be the issue with certificate pinning as certificate is the same (just moved from server to PA). Basically in SSL decryption scenario PA shoul be just listening to decrypted traffic and understand it because it has the apropriate certificate with private key. But in fact it does alter a session a bit as a colleague told me from debugging session with PA support. However for any details and logs about it you will probably have to ask support.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Another could be some external components having issues with decrytpion (if your application is using such).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Sep 2018 06:59:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-breaks-certain-website-functionality/m-p/229197#M65900</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2018-09-03T06:59:53Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption breaks certain website functionality</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-breaks-certain-website-functionality/m-p/229213#M65905</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/91200"&gt;@welly_59&lt;/a&gt;&lt;/P&gt;&lt;P&gt;Other than &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/10238"&gt;@santonic&lt;/a&gt;&amp;nbsp;I think you're talking about outbound decryption, right?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is it a java application? In case of that when the developpers do their job and check the certificate chain in a TLS connection, then this might be the reason because java has it's own certificate trust store.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Sep 2018 08:48:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-breaks-certain-website-functionality/m-p/229213#M65905</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-09-03T08:48:42Z</dc:date>
    </item>
  </channel>
</rss>

