<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PA-3020 SSL Decryption Query in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pa-3020-ssl-decryption-query/m-p/281228#M75936</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;version 8.0.9&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I have blocked ‘quic’ on the firewall for my test user.&amp;nbsp; This still allowed traffic to work using Google Chrome.&amp;nbsp; However, when I enabled SSL decryption I received the same error in Chrome -&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;NET::ERR_CERT_WEAK_SIGNATURE_ALGORITHM.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 06 Aug 2019 05:10:48 GMT</pubDate>
    <dc:creator>Jatin.Singh</dc:creator>
    <dc:date>2019-08-06T05:10:48Z</dc:date>
    <item>
      <title>PA-3020 SSL Decryption Query</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-3020-ssl-decryption-query/m-p/280993#M75902</link>
      <description>&lt;P&gt;Hi, I have enabled SSL decryption (forward proxy) on our PA-3020 firewall. The certificate is generated from our CSR and is installed on our PA-3020. I have set up a separate forward trust and forward untrust certificate. The forward trust certificate has been distributed via windows group policy and resides in the 'intermediate' and 'trusted' cert authorities within windows. I can confirm that the SSL decryption appears to have been set up correctly as demonstrated in the screenshots provided. when accessing 'bbc.com' through the Microsoft EDGE browser I am getting a trusted cert from the PA-3020. When accessing 'badssl.com' in Microsoft EDGE i am getting the correct untrusted certificate from the PA-3020. However, when using Google chrome I am getting an error about weak encryption on the firewall. It states that I am using a weak encryption algorithm. When creating the cert on the PA-3020 I used an RSA algorithm (2048 bits) and a SHA256 digest. Can you advise why the PA-3020 certificate is not working on google chrome?&lt;/P&gt;</description>
      <pubDate>Mon, 05 Aug 2019 02:24:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-3020-ssl-decryption-query/m-p/280993#M75902</guid>
      <dc:creator>Jatin.Singh</dc:creator>
      <dc:date>2019-08-05T02:24:13Z</dc:date>
    </item>
    <item>
      <title>Re: PA-3020 SSL Decryption Query</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-3020-ssl-decryption-query/m-p/281002#M75905</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/114565"&gt;@Jatin.Singh&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;What version of PAN-OS are you running.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Aug 2019 02:35:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-3020-ssl-decryption-query/m-p/281002#M75905</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-08-05T02:35:07Z</dc:date>
    </item>
    <item>
      <title>Re: PA-3020 SSL Decryption Query</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-3020-ssl-decryption-query/m-p/281228#M75936</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;version 8.0.9&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I have blocked ‘quic’ on the firewall for my test user.&amp;nbsp; This still allowed traffic to work using Google Chrome.&amp;nbsp; However, when I enabled SSL decryption I received the same error in Chrome -&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;NET::ERR_CERT_WEAK_SIGNATURE_ALGORITHM.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Aug 2019 05:10:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-3020-ssl-decryption-query/m-p/281228#M75936</guid>
      <dc:creator>Jatin.Singh</dc:creator>
      <dc:date>2019-08-06T05:10:48Z</dc:date>
    </item>
    <item>
      <title>Re: PA-3020 SSL Decryption Query</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-3020-ssl-decryption-query/m-p/281362#M75962</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/114565"&gt;@Jatin.Singh&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;This could actually be due to Chrome supporting TLS 1.3 and the PAN-OS version you are running not knowing to get out of the way and not attempt to decrypt the traffic. This was either added for PAN-OS 8.0 in 8.0.14 or 8.0.16, I can't recall exactly which one. I would upgrade your firewall to 8.0.19 and see if the issue persists.&amp;nbsp;&lt;/P&gt;&lt;P&gt;FYI, PAN-OS 8 goes EOL on Oct 31st, I would start planning your upgrade to 8.1.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Aug 2019 17:04:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-3020-ssl-decryption-query/m-p/281362#M75962</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-08-06T17:04:38Z</dc:date>
    </item>
    <item>
      <title>Re: PA-3020 SSL Decryption Query</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-3020-ssl-decryption-query/m-p/282241#M76053</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have upgrade the Palo to&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;8.1.9 and issue is still there, is there any other solution for this issue?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Aug 2019 05:25:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-3020-ssl-decryption-query/m-p/282241#M76053</guid>
      <dc:creator>Jatin.Singh</dc:creator>
      <dc:date>2019-08-12T05:25:59Z</dc:date>
    </item>
  </channel>
</rss>

