<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: troubleshooting SSL decryption in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/troubleshooting-ssl-decryption/m-p/254382#M72196</link>
    <description>&lt;P&gt;Hello Guys,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What is the best way to troubleshoot SSL interception?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here I have an exception with:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Issuer:&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;RapidSSL RSA CA 2018&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Status:&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;untrusted&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ok great but I don't understand why the certificate is untrusted. I am trying to find some information in logs but I don't fing anything relevant. The relevant CA is trusted.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there some commands to troubleshoot that? Maybe the only way in the packet capture.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;</description>
    <pubDate>Wed, 20 Mar 2019 14:44:33 GMT</pubDate>
    <dc:creator>kasito</dc:creator>
    <dc:date>2019-03-20T14:44:33Z</dc:date>
    <item>
      <title>troubleshooting SSL decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/troubleshooting-ssl-decryption/m-p/35566#M26118</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We've been using SSL decryption for a while now.&lt;/P&gt;&lt;P&gt;Where for the most websites, this is not an issue, once in a while a user complains that certain https website doesn't load at all. Browser just keeps loading indefinitely.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We can't find a reason in the logs, traffic is allowed, not blocked, decrypted flag is checked in the log detail.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For now our workaround is to add those websites to an encryption exception list (address group). But that list is starting to grow to 30+ addresses.&lt;/P&gt;&lt;P&gt;Two problems with this approach:&lt;/P&gt;&lt;P&gt;- the list is hard to maintain&lt;/P&gt;&lt;P&gt;- no SSL decryption, so no full App-ID visiblity for those&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How can I troubleshoot this, how can I determine the real reason the sites don't load ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Feb 2014 10:13:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/troubleshooting-ssl-decryption/m-p/35566#M26118</guid>
      <dc:creator>dieter_b</dc:creator>
      <dc:date>2014-02-14T10:13:35Z</dc:date>
    </item>
    <item>
      <title>Re: troubleshooting SSL decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/troubleshooting-ssl-decryption/m-p/35567#M26119</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Reason for decryption fail shold be:&lt;/P&gt;&lt;P&gt; - Client cert used&lt;/P&gt;&lt;P&gt; - Non RFC app&lt;/P&gt;&lt;P&gt; - unsupported crypto setting&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From cli you can use command like:&lt;/P&gt;&lt;P&gt;show system setting ssl-decrypt ecclude-cache&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Carefull not trying to decrypt too many thing according law&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope help&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;v.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Feb 2014 13:56:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/troubleshooting-ssl-decryption/m-p/35567#M26119</guid>
      <dc:creator>VinceM</dc:creator>
      <dc:date>2014-02-14T13:56:12Z</dc:date>
    </item>
    <item>
      <title>Re: troubleshooting SSL decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/troubleshooting-ssl-decryption/m-p/35568#M26120</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am not sure what software version you are on but there was a fix that went in 4.1.9&lt;/P&gt;&lt;P&gt;Bug 43507:Due to a buffering issue, firewalls configured with SSL forward proxy decryption caused performance issues for clients when downloading a large number of files (16k +) from web servers over HTTPS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you are on 4.1.8 i would recommend upgrading. &lt;/P&gt;&lt;P&gt;Thanks &lt;/P&gt;&lt;P&gt;Numan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Feb 2014 17:24:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/troubleshooting-ssl-decryption/m-p/35568#M26120</guid>
      <dc:creator>mbutt</dc:creator>
      <dc:date>2014-02-14T17:24:57Z</dc:date>
    </item>
    <item>
      <title>Re: troubleshooting SSL decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/troubleshooting-ssl-decryption/m-p/35569#M26121</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We're on 5.0.8, so that's probably another issue. Thanks anyway.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 17 Feb 2014 07:16:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/troubleshooting-ssl-decryption/m-p/35569#M26121</guid>
      <dc:creator>dieter_b</dc:creator>
      <dc:date>2014-02-17T07:16:18Z</dc:date>
    </item>
    <item>
      <title>Re: troubleshooting SSL decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/troubleshooting-ssl-decryption/m-p/35570#M26122</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks, didn't know that command.&lt;/P&gt;&lt;P&gt;At least we now can confirm if there's a problem with certain website.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Currently I see all timing out for reason CERT_UNSUPPORTED. Any setting where I can say if that's te reason, don't decrypt and continue ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 17 Feb 2014 07:21:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/troubleshooting-ssl-decryption/m-p/35570#M26122</guid>
      <dc:creator>dieter_b</dc:creator>
      <dc:date>2014-02-17T07:21:29Z</dc:date>
    </item>
    <item>
      <title>Re: troubleshooting SSL decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/troubleshooting-ssl-decryption/m-p/35571#M26123</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Sir,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;Yes,&amp;nbsp; you can change the settings under the decryption profile assigned to the decryption policy and I disabled &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;( &lt;/SPAN&gt;uncheck) the option "Block sessions with unsupported cipher suites".&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;IMG alt="SSL-Decryption.JPG.jpg" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/11641_SSL-Decryption.JPG.jpg" /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;Thanks&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 17 Feb 2014 07:56:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/troubleshooting-ssl-decryption/m-p/35571#M26123</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-02-17T07:56:41Z</dc:date>
    </item>
    <item>
      <title>Re: troubleshooting SSL decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/troubleshooting-ssl-decryption/m-p/35572#M26124</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Great info, I'll try that&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 17 Feb 2014 08:02:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/troubleshooting-ssl-decryption/m-p/35572#M26124</guid>
      <dc:creator>dieter_b</dc:creator>
      <dc:date>2014-02-17T08:02:49Z</dc:date>
    </item>
    <item>
      <title>Re: troubleshooting SSL decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/troubleshooting-ssl-decryption/m-p/254382#M72196</link>
      <description>&lt;P&gt;Hello Guys,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What is the best way to troubleshoot SSL interception?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here I have an exception with:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Issuer:&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;RapidSSL RSA CA 2018&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Status:&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;untrusted&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ok great but I don't understand why the certificate is untrusted. I am trying to find some information in logs but I don't fing anything relevant. The relevant CA is trusted.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there some commands to troubleshoot that? Maybe the only way in the packet capture.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;</description>
      <pubDate>Wed, 20 Mar 2019 14:44:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/troubleshooting-ssl-decryption/m-p/254382#M72196</guid>
      <dc:creator>kasito</dc:creator>
      <dc:date>2019-03-20T14:44:33Z</dc:date>
    </item>
  </channel>
</rss>

