<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSL Decryption: SHA1-Intermediate certificate gets decrypted, even if not allowed to in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-sha1-intermediate-certificate-gets-decrypted-even/m-p/305340#M79341</link>
    <description>&lt;P&gt;This is odd that it would be happening with PAN-OS 9.0.5. As anything like that should have been cleared up.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There was a prior discussion talking about similar things:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/General-Topics/PA-3020-SSL-Decryption-Query/m-p/280993#M75902" target="_blank"&gt;https://live.paloaltonetworks.com/t5/General-Topics/PA-3020-SSL-Decryption-Query/m-p/280993#M75902&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But there is no real answer as to why..&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What browsers? does it matter if you use Edge, Firefox or Chrome?&lt;/P&gt;</description>
    <pubDate>Tue, 31 Dec 2019 23:11:43 GMT</pubDate>
    <dc:creator>jdelio</dc:creator>
    <dc:date>2019-12-31T23:11:43Z</dc:date>
    <item>
      <title>SSL Decryption: SHA1-Intermediate certificate gets decrypted, even if not allowed to</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-sha1-intermediate-certificate-gets-decrypted-even/m-p/305172#M79295</link>
      <description>&lt;P&gt;Hi paloalto community,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tested my new ssl decryption rules against the badssl dashboard (&amp;nbsp;&lt;A href="https://badssl.com/dashboard/" target="_blank"&gt;https://badssl.com/dashboard/&lt;/A&gt;&amp;nbsp;).&lt;/P&gt;&lt;P&gt;So far it looks good. Unfortunately the check for sha1-intermediate doesn’t pass. Our PA-850 (Firmware 9.0.5) does create a secure connection to this site for the client ( &lt;A href="https://sha1-intermediate.badssl.com/" target="_blank"&gt;https://sha1-intermediate.badssl.com/&lt;/A&gt;&amp;nbsp;), even I configured to not support SHA1.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is my configuration:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2019-12-30 14_17_20-pa-1.png" style="width: 805px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/23259i0BBF98EF532491A2/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="2019-12-30 14_17_20-pa-1.png" alt="2019-12-30 14_17_20-pa-1.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2019-12-30 14_17_08-pa-1.png" style="width: 805px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/23261i8D8D051CC135A36C/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="2019-12-30 14_17_08-pa-1.png" alt="2019-12-30 14_17_08-pa-1.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2019-12-30 14_16_37-pa-1.png" style="width: 803px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/23260iC11977B7C7B80B2F/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="2019-12-30 14_16_37-pa-1.png" alt="2019-12-30 14_16_37-pa-1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Is there something I forgot to configure?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks and best regards,&lt;/P&gt;&lt;P&gt;Markus&lt;/P&gt;</description>
      <pubDate>Mon, 30 Dec 2019 13:22:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-sha1-intermediate-certificate-gets-decrypted-even/m-p/305172#M79295</guid>
      <dc:creator>mrkskhn</dc:creator>
      <dc:date>2019-12-30T13:22:14Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption: SHA1-Intermediate certificate gets decrypted, even if not allowed to</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-sha1-intermediate-certificate-gets-decrypted-even/m-p/305340#M79341</link>
      <description>&lt;P&gt;This is odd that it would be happening with PAN-OS 9.0.5. As anything like that should have been cleared up.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There was a prior discussion talking about similar things:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/General-Topics/PA-3020-SSL-Decryption-Query/m-p/280993#M75902" target="_blank"&gt;https://live.paloaltonetworks.com/t5/General-Topics/PA-3020-SSL-Decryption-Query/m-p/280993#M75902&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But there is no real answer as to why..&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What browsers? does it matter if you use Edge, Firefox or Chrome?&lt;/P&gt;</description>
      <pubDate>Tue, 31 Dec 2019 23:11:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-sha1-intermediate-certificate-gets-decrypted-even/m-p/305340#M79341</guid>
      <dc:creator>jdelio</dc:creator>
      <dc:date>2019-12-31T23:11:43Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption: SHA1-Intermediate certificate gets decrypted, even if not allowed to</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-sha1-intermediate-certificate-gets-decrypted-even/m-p/305728#M79462</link>
      <description>&lt;P&gt;Same with different browsers&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jan 2020 08:36:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-sha1-intermediate-certificate-gets-decrypted-even/m-p/305728#M79462</guid>
      <dc:creator>mrkskhn</dc:creator>
      <dc:date>2020-01-06T08:36:47Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption: SHA1-Intermediate certificate gets decrypted, even if not allowed to</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-sha1-intermediate-certificate-gets-decrypted-even/m-p/306817#M79692</link>
      <description>&lt;P&gt;Some more trouble with decryption:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.lobster.de/" target="_blank"&gt;https://www.lobster.de/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This page gets an untrusted paloalto cert, even it's a valid certificate? Can someone confirm this on his paloalto decryption setup?&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jan 2020 16:14:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-sha1-intermediate-certificate-gets-decrypted-even/m-p/306817#M79692</guid>
      <dc:creator>mrkskhn</dc:creator>
      <dc:date>2020-01-15T16:14:12Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption: SHA1-Intermediate certificate gets decrypted, even if not allowed to</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-sha1-intermediate-certificate-gets-decrypted-even/m-p/306825#M79696</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/91759"&gt;@mrkskhn&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;At least this website is configured not correctly. The webserver does not send the intemediate certificate in the TLS handshake. Without this intermediate certificate the firewall cannot verify if this certificate is trusted / it is not able to check the certificate path.&lt;/P&gt;&lt;P&gt;You have not 3 possibilities with your current configuration:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Import the intermediate cert of this website manually onto your firewall and mark it as trusted root&lt;/LI&gt;&lt;LI&gt;Create a decryption rule with another decryption profile where you allow untrusted issuers and add a custom URL category to that rule where you add websites like this one&lt;/LI&gt;&lt;LI&gt;Try to contact the operator of the website to have them fix the issue&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;And yes, because paloalto firewalls don't have the intermediate certs locally the "problem" you see will be on all palo fws.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jan 2020 17:08:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-sha1-intermediate-certificate-gets-decrypted-even/m-p/306825#M79696</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2020-01-15T17:08:40Z</dc:date>
    </item>
  </channel>
</rss>

