<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: decrypt-cert-validation while performing windows update in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/decrypt-cert-validation-while-performing-windows-update/m-p/296955#M78012</link>
    <description>&lt;P&gt;Greetings ...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes we are also seeing this.&lt;/P&gt;</description>
    <pubDate>Thu, 07 Nov 2019 07:46:03 GMT</pubDate>
    <dc:creator>khanshahidnazir</dc:creator>
    <dc:date>2019-11-07T07:46:03Z</dc:date>
    <item>
      <title>decrypt-cert-validation while performing windows update</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/decrypt-cert-validation-while-performing-windows-update/m-p/287839#M76755</link>
      <description>&lt;P&gt;Hey Guys ... I am doing a normal Windows Update and i am getting error.&lt;/P&gt;&lt;P&gt;While analysing the application type is ms-update and reason for session end is decrypt-cert-validation.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Appreciate if you guys can support.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Sep 2019 12:42:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/decrypt-cert-validation-while-performing-windows-update/m-p/287839#M76755</guid>
      <dc:creator>khanshahidnazir</dc:creator>
      <dc:date>2019-09-11T12:42:18Z</dc:date>
    </item>
    <item>
      <title>Re: decrypt-cert-validation while performing windows update</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/decrypt-cert-validation-while-performing-windows-update/m-p/287860#M76761</link>
      <description>&lt;P&gt;FYI:&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000boONCAY" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000boONCAY&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Sep 2019 14:03:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/decrypt-cert-validation-while-performing-windows-update/m-p/287860#M76761</guid>
      <dc:creator>myky</dc:creator>
      <dc:date>2019-09-11T14:03:56Z</dc:date>
    </item>
    <item>
      <title>Re: decrypt-cert-validation while performing windows update</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/decrypt-cert-validation-while-performing-windows-update/m-p/287885#M76763</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Dont decrypt Microsoft updates. We have a no decrypt policy just for it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Wed, 11 Sep 2019 16:15:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/decrypt-cert-validation-while-performing-windows-update/m-p/287885#M76763</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2019-09-11T16:15:12Z</dc:date>
    </item>
    <item>
      <title>Re: decrypt-cert-validation while performing windows update</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/decrypt-cert-validation-while-performing-windows-update/m-p/287893#M76769</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What does that no decrypt policy look like?&amp;nbsp; &amp;nbsp;You can't do no decrypt by application right? Thinking you have a destination list, or list of URL's you are triggering the no decrypt on?&lt;/P&gt;</description>
      <pubDate>Wed, 11 Sep 2019 16:36:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/decrypt-cert-validation-while-performing-windows-update/m-p/287893#M76769</guid>
      <dc:creator>Sec101</dc:creator>
      <dc:date>2019-09-11T16:36:13Z</dc:date>
    </item>
    <item>
      <title>Re: decrypt-cert-validation while performing windows update</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/decrypt-cert-validation-while-performing-windows-update/m-p/287904#M76772</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Sorry for not clarifying earlier. A no decrypt policy is just a decryption policy with the action set to 'no-decrypt'. We use this for URL's and URL categories.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 684px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21337i4BB8DEE77C724E8B/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 295px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21336iC58DB726E8E733BA/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Wed, 11 Sep 2019 16:43:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/decrypt-cert-validation-while-performing-windows-update/m-p/287904#M76772</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2019-09-11T16:43:05Z</dc:date>
    </item>
    <item>
      <title>Re: decrypt-cert-validation while performing windows update</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/decrypt-cert-validation-while-performing-windows-update/m-p/288167#M76803</link>
      <description>&lt;P&gt;Did you add those directly to your No decrypt policy, or where is that list getting populated from?&amp;nbsp; - Just asking in reference to where the actual second screenshot resides on your firewall.&amp;nbsp; Thank you for the quick reply!&lt;/P&gt;</description>
      <pubDate>Thu, 12 Sep 2019 20:57:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/decrypt-cert-validation-while-performing-windows-update/m-p/288167#M76803</guid>
      <dc:creator>Sec101</dc:creator>
      <dc:date>2019-09-12T20:57:20Z</dc:date>
    </item>
    <item>
      <title>Re: decrypt-cert-validation while performing windows update</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/decrypt-cert-validation-while-performing-windows-update/m-p/288169#M76804</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Its a list we came up with when googling. Here is one just for wsus:&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.microsoft.com/en-us/windows-server/administration/windows-server-update-services/deploy/2-configure-wsus" target="_blank"&gt;https://docs.microsoft.com/en-us/windows-server/administration/windows-server-update-services/deploy/2-configure-wsus&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://kc.mcafee.com/corporate/index?page=content&amp;amp;id=KB88947&amp;amp;actp=null&amp;amp;viewlocale=en_US&amp;amp;showDraft=false&amp;amp;platinum_status=false&amp;amp;locale=en_US" target="_blank"&gt;https://kc.mcafee.com/corporate/index?page=content&amp;amp;id=KB88947&amp;amp;actp=null&amp;amp;viewlocale=en_US&amp;amp;showDraft=false&amp;amp;platinum_status=false&amp;amp;locale=en_US&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The main issue we face at times is taht the update will fail since the firewall is blocking something. This is mainly due to the backend IP's and DNS changing at a faster rate than the PAN does. Not a knock against PAN, its just the backend MS Updates change and are not all documented.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Sep 2019 21:07:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/decrypt-cert-validation-while-performing-windows-update/m-p/288169#M76804</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2019-09-12T21:07:42Z</dc:date>
    </item>
    <item>
      <title>Re: decrypt-cert-validation while performing windows update</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/decrypt-cert-validation-while-performing-windows-update/m-p/288525#M76854</link>
      <description>&lt;P&gt;Greetings ...&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks a lot for your inputs and suggestions.&lt;/P&gt;&lt;P&gt;I followed your screenshot and added all URL's but i am still not able to update windows.&lt;/P&gt;&lt;P&gt;I am also sharing my Decryption Profile screenshot.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Decryp.jpg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21451i263A409AF5DA78F1/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Decryp.jpg" alt="Decryp.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Sep 2019 08:17:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/decrypt-cert-validation-while-performing-windows-update/m-p/288525#M76854</guid>
      <dc:creator>khanshahidnazir</dc:creator>
      <dc:date>2019-09-16T08:17:10Z</dc:date>
    </item>
    <item>
      <title>Re: decrypt-cert-validation while performing windows update</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/decrypt-cert-validation-while-performing-windows-update/m-p/296792#M78000</link>
      <description>&lt;P&gt;&lt;SPAN&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/121188"&gt;@khanshahidnazir&lt;/a&gt;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt; We are also experiencing this.&amp;nbsp; We have found that MS Store will intermittently update and download, but the full blown WIN10 updates don't work.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are using a custom URL Category pushed from the panorama to populate a decryption bypass list of addresses that will not get decrypted.&amp;nbsp; We are seeing this manifest in the logs with a session end reason of: decrypt-cert-validation.&amp;nbsp; Is that what you were seeing?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Nov 2019 18:14:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/decrypt-cert-validation-while-performing-windows-update/m-p/296792#M78000</guid>
      <dc:creator>charlesk</dc:creator>
      <dc:date>2019-11-06T18:14:11Z</dc:date>
    </item>
    <item>
      <title>Re: decrypt-cert-validation while performing windows update</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/decrypt-cert-validation-while-performing-windows-update/m-p/296955#M78012</link>
      <description>&lt;P&gt;Greetings ...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes we are also seeing this.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Nov 2019 07:46:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/decrypt-cert-validation-while-performing-windows-update/m-p/296955#M78012</guid>
      <dc:creator>khanshahidnazir</dc:creator>
      <dc:date>2019-11-07T07:46:03Z</dc:date>
    </item>
    <item>
      <title>Re: decrypt-cert-validation while performing windows update</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/decrypt-cert-validation-while-performing-windows-update/m-p/297087#M78024</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;If these are windows 10 1903 systems and use the distributed model for updates. You'll need to add the following to your whitelist to allow and not decrypt these domains:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;•*.do.dsp.mp.microsoft.com&lt;BR /&gt;*.delivery.mp.microsoft.com&lt;BR /&gt;*.prod.do.dsp.mp.microsoft.com&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.microsoft.com/en-us/windows/privacy/manage-windows-1903-endpoints" target="_blank"&gt;https://docs.microsoft.com/en-us/windows/privacy/manage-windows-1903-endpoints&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Thu, 07 Nov 2019 17:11:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/decrypt-cert-validation-while-performing-windows-update/m-p/297087#M78024</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2019-11-07T17:11:45Z</dc:date>
    </item>
    <item>
      <title>Re: decrypt-cert-validation while performing windows update</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/decrypt-cert-validation-while-performing-windows-update/m-p/297093#M78027</link>
      <description>&lt;P&gt;We already have the *.mp.microsoft.com whitelisted and have for some time.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Nov 2019 17:46:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/decrypt-cert-validation-while-performing-windows-update/m-p/297093#M78027</guid>
      <dc:creator>charlesk</dc:creator>
      <dc:date>2019-11-07T17:46:16Z</dc:date>
    </item>
    <item>
      <title>Re: decrypt-cert-validation while performing windows update</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/decrypt-cert-validation-while-performing-windows-update/m-p/297101#M78028</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;So did we and it was getting blocked. That is why we had to add the additional domains I listed previously :(.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Thu, 07 Nov 2019 18:11:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/decrypt-cert-validation-while-performing-windows-update/m-p/297101#M78028</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2019-11-07T18:11:34Z</dc:date>
    </item>
  </channel>
</rss>

