<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSL decryption troubleshooting in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-troubleshooting/m-p/308444#M80015</link>
    <description>&lt;P&gt;No&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anything on Digicert or Comodo is an issue. [at least]&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have to unset "Untrusted Issuer" &amp;amp; "Unknown Status" , and that's in addition to the "Check Timeout" which fails for everything.&lt;/P&gt;</description>
    <pubDate>Wed, 29 Jan 2020 08:34:54 GMT</pubDate>
    <dc:creator>RobinClayton</dc:creator>
    <dc:date>2020-01-29T08:34:54Z</dc:date>
    <item>
      <title>SSL decryption troubleshooting</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-troubleshooting/m-p/308026#M79949</link>
      <description>&lt;P&gt;I am trying to get SSL Forward Proxy working properly, generally it seems to be OK but I have a site I have tested&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;is for the bank hsbc&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;that gives an error..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Certificate Error&lt;/P&gt;&lt;P&gt;There is an issue with the SSL certificate of the server you are trying to contact.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Certificate Name:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;IP:&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;91.214.6.22&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Category:&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;not-resolved&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Issuer:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Status:&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;unknown&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Reason:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have read this&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cm66CAC" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cm66CAC&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Coincidentally, the site in the help link actualy uses the exact same certificate as HSBC.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have imported both certificates in the chain&amp;nbsp;&lt;/P&gt;&lt;P&gt;"DigiCert High Assurance EV Root"&lt;BR /&gt;"DigiCert SHA2 Extended Validation Server CA"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tried setting root and SHA2 as CA...&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But the error persists for both the site I need and the site from the help document.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My forward Proxy is presently configured&amp;nbsp; like.... ( I had to disable "Check Timeout" as that failed also )&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[/] Block sessions with expired certificates&lt;/P&gt;&lt;P&gt;[/] Block sessions with untrusted issuers&lt;/P&gt;&lt;P&gt;[/] Block sessions with unknown certificate status&lt;/P&gt;&lt;P&gt;[ ] Block sessions on certificate status check timeout&lt;/P&gt;&lt;P&gt;[ ]Restrict certificate extensions&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;BR /&gt;Cheers&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Rob&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jan 2020 10:05:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-troubleshooting/m-p/308026#M79949</guid>
      <dc:creator>RobinClayton</dc:creator>
      <dc:date>2020-01-27T10:05:23Z</dc:date>
    </item>
    <item>
      <title>Re: SSL decryption troubleshooting</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-troubleshooting/m-p/308407#M80009</link>
      <description>&lt;P&gt;Hey there Rob&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/71756"&gt;@RobinClayton&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;I am sorry that you are having issues trying to decrypt that one site.. but I will state that in the normal setup for SSL Decryption, we normally exclude Banking and Medical sites to reserve privacy.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I assume that other sites work without issue?&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2020 00:11:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-troubleshooting/m-p/308407#M80009</guid>
      <dc:creator>jdelio</dc:creator>
      <dc:date>2020-01-29T00:11:06Z</dc:date>
    </item>
    <item>
      <title>Re: SSL decryption troubleshooting</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-troubleshooting/m-p/308444#M80015</link>
      <description>&lt;P&gt;No&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anything on Digicert or Comodo is an issue. [at least]&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have to unset "Untrusted Issuer" &amp;amp; "Unknown Status" , and that's in addition to the "Check Timeout" which fails for everything.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2020 08:34:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-troubleshooting/m-p/308444#M80015</guid>
      <dc:creator>RobinClayton</dc:creator>
      <dc:date>2020-01-29T08:34:54Z</dc:date>
    </item>
    <item>
      <title>Re: SSL decryption troubleshooting</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-troubleshooting/m-p/308534#M80037</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Are you having the PAN perform certificate checks? And is the PAN allowing that checked traffic?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also I agree with Jdelio, its best to exclude the following to avoid issues with compliance and privacy:&lt;/P&gt;&lt;P&gt;banking&lt;/P&gt;&lt;P&gt;medical&lt;/P&gt;&lt;P&gt;military&lt;/P&gt;&lt;P&gt;government&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2020 16:26:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-troubleshooting/m-p/308534#M80037</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2020-01-29T16:26:30Z</dc:date>
    </item>
    <item>
      <title>Re: SSL decryption troubleshooting</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-troubleshooting/m-p/308538#M80041</link>
      <description>&lt;P&gt;The unit is configured to send both CRL and OSCP but I can't find where I would see this traffic. Service router does not include an option for OSCP only CRL...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is on an 8.0 FW, but the certs are there and look to have the same time stamp.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rob&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2020 16:38:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-troubleshooting/m-p/308538#M80041</guid>
      <dc:creator>RobinClayton</dc:creator>
      <dc:date>2020-01-29T16:38:30Z</dc:date>
    </item>
    <item>
      <title>Re: SSL decryption troubleshooting</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-troubleshooting/m-p/308539#M80042</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;If the service routes are set to default, they would source from the management interface. So filter traffic from it and appropriate applications to see. Also dont decrypt this traffic :).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2020 16:40:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-troubleshooting/m-p/308539#M80042</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2020-01-29T16:40:19Z</dc:date>
    </item>
    <item>
      <title>Re: SSL decryption troubleshooting</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-troubleshooting/m-p/308546#M80043</link>
      <description>&lt;P&gt;It was set on the MGMT interface, but I did not see any CRL/OSCP app-id traffic.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I now have it configured for CRL Service on the external interface, but that made no difference.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2020 16:48:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-troubleshooting/m-p/308546#M80043</guid>
      <dc:creator>RobinClayton</dc:creator>
      <dc:date>2020-01-29T16:48:52Z</dc:date>
    </item>
    <item>
      <title>Re: SSL decryption troubleshooting</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-troubleshooting/m-p/308595#M80046</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/71756"&gt;@RobinClayton&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Keep in mind that depending on your actual firewall configuration, you may not be recording the logs for this traffic. You'll want to ensure that you have your security rulebase and routing setup so that the firewall sees and logs this traffic. Alternatively, since you are now sourcing the traffic to from your untrust interface you can start a PCAP and look for the traffic.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2020 22:29:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-troubleshooting/m-p/308595#M80046</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-01-29T22:29:54Z</dc:date>
    </item>
  </channel>
</rss>

