<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Strict TLS 1.3 in chrome 72 or 73? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/strict-tls-1-3-in-chrome-72-or-73/m-p/248097#M70577</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/3296"&gt;@emr_1&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;72 enables downgrade protection, and to an extent, the damage was already done with the release of 70. 72 is simply taking things a small step further. To prepare yourself for this, simply upgrade to one of the following and you should be good to go.&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;&lt;UL&gt;&lt;LI&gt;PAN-OS 8.1 must be&amp;nbsp;&lt;SPAN&gt;≥&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;8.1.4&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;PAN-OS 8.0 must be ≥&amp;nbsp;8.0.14&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;PAN-OS 7.1 must be ≥&amp;nbsp;7.1.21&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/DIV&gt;</description>
    <pubDate>Wed, 30 Jan 2019 04:20:32 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2019-01-30T04:20:32Z</dc:date>
    <item>
      <title>Strict TLS 1.3 in chrome 72 or 73?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/strict-tls-1-3-in-chrome-72-or-73/m-p/247888#M70528</link>
      <description>&lt;P&gt;Hello Guys,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Which information is true?&lt;/P&gt;&lt;P&gt;Chrome 72(in topic) or Chrome 73(in article)?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="chrome72.png" style="width: 500px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/18483iDE9D582B5DC262E5/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="chrome72.png" alt="chrome72.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="chrome73.png" style="width: 500px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/18484i22777BF91EE84355/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="chrome73.png" alt="chrome73.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Jan 2019 01:40:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/strict-tls-1-3-in-chrome-72-or-73/m-p/247888#M70528</guid>
      <dc:creator>emr_1</dc:creator>
      <dc:date>2019-01-29T01:40:15Z</dc:date>
    </item>
    <item>
      <title>Re: Strict TLS 1.3 in chrome 72 or 73?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/strict-tls-1-3-in-chrome-72-or-73/m-p/248097#M70577</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/3296"&gt;@emr_1&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;72 enables downgrade protection, and to an extent, the damage was already done with the release of 70. 72 is simply taking things a small step further. To prepare yourself for this, simply upgrade to one of the following and you should be good to go.&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;&lt;UL&gt;&lt;LI&gt;PAN-OS 8.1 must be&amp;nbsp;&lt;SPAN&gt;≥&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;8.1.4&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;PAN-OS 8.0 must be ≥&amp;nbsp;8.0.14&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;PAN-OS 7.1 must be ≥&amp;nbsp;7.1.21&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 30 Jan 2019 04:20:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/strict-tls-1-3-in-chrome-72-or-73/m-p/248097#M70577</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-01-30T04:20:32Z</dc:date>
    </item>
    <item>
      <title>Re: Strict TLS 1.3 in chrome 72 or 73?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/strict-tls-1-3-in-chrome-72-or-73/m-p/248125#M70583</link>
      <description>&lt;P&gt;Hi BPry,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your reply.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tested with my testbed : PA-5020 v8.0.13 with Chrome 72.&lt;/P&gt;&lt;P&gt;Here is test results.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;chrome://flags/#tls13-variant ## default&lt;BR /&gt;chrome://flags/#enforce-tls13-downgrade ## default&lt;BR /&gt;-&amp;gt; I could access to the gmail&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;chrome://flags/#tls13-variant ## default&lt;BR /&gt;chrome://flags/#enforce-tls13-downgrade ## enabled&lt;BR /&gt;-&amp;gt; confirmed "ERR_TLS13_DOWNGRADE_DETECTED"&lt;/P&gt;&lt;P&gt;-&amp;gt; also confirmed I could access to the gmail after I upgrade into 8.0.14.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;chrome://flags/#tls13-variant ## default&lt;BR /&gt;chrome://flags/#enforce-tls13-downgrade ## disabled&lt;BR /&gt;-&amp;gt; I could access to the gmail&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thus, I believe downgrade protection is not enabled in 72.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jan 2019 07:21:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/strict-tls-1-3-in-chrome-72-or-73/m-p/248125#M70583</guid>
      <dc:creator>emr_1</dc:creator>
      <dc:date>2019-01-30T07:21:19Z</dc:date>
    </item>
    <item>
      <title>Re: Strict TLS 1.3 in chrome 72 or 73?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/strict-tls-1-3-in-chrome-72-or-73/m-p/248181#M70604</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/3296"&gt;@emr_1&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;They may have gotten enough pushback from Enterprise users that they chose not to enable it by Default; I know the original plan was to do so in 72. Looking through the Chromium commits I'm not seeing anything about it being switched in 73 either, they actually disabled the KeyUpdate function due to bugs.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I wouldn't be suprised to see this goalpost keep getting pushed back to be honest.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jan 2019 14:54:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/strict-tls-1-3-in-chrome-72-or-73/m-p/248181#M70604</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-01-30T14:54:31Z</dc:date>
    </item>
    <item>
      <title>Re: Strict TLS 1.3 in chrome 72 or 73?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/strict-tls-1-3-in-chrome-72-or-73/m-p/248215#M70612</link>
      <description>&lt;P&gt;Google pushed the full enforcement to Chrome version 73 (unless they push it again). They have enabled it in version 72 but only if you don't trust the CA.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The advisory has now been updated to reflect this new info:&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Customer-Advisories/Action-required-if-you-have-enabled-SSL-decryption-forward-proxy/ta-p/236596" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Customer-Advisories/Action-required-if-you-have-enabled-SSL-decryption-forward-proxy/ta-p/236596&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jan 2019 22:37:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/strict-tls-1-3-in-chrome-72-or-73/m-p/248215#M70612</guid>
      <dc:creator>gwesson</dc:creator>
      <dc:date>2019-01-30T22:37:07Z</dc:date>
    </item>
    <item>
      <title>Re: Strict TLS 1.3 in chrome 72 or 73?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/strict-tls-1-3-in-chrome-72-or-73/m-p/248231#M70614</link>
      <description>&lt;P&gt;Hi BPry, gwesson&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for replies. I understood the situation.&lt;/P&gt;</description>
      <pubDate>Thu, 31 Jan 2019 03:03:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/strict-tls-1-3-in-chrome-72-or-73/m-p/248231#M70614</guid>
      <dc:creator>emr_1</dc:creator>
      <dc:date>2019-01-31T03:03:15Z</dc:date>
    </item>
  </channel>
</rss>

