<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSL decryption( Some traffic is not decrypted) in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-some-traffic-is-not-decrypted/m-p/310889#M80496</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/124013"&gt;@Jafar_Hussain&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Neither &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;nor me &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp; are working for Paloaltonetworks. We use our free time to try to help here in the community. So if you cannot wait more than 3 hours (as you asked again for an update here 3 hours after your post with the cert warnings) you should contact official paloalto support.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyway, which certificate did you change to SHA512? Was it really the CA cert used for decryption? What key size did you configure for the dynamically created certificates? Could you show a screenshot of the cert?&lt;/P&gt;</description>
    <pubDate>Wed, 12 Feb 2020 20:30:18 GMT</pubDate>
    <dc:creator>Remo</dc:creator>
    <dc:date>2020-02-12T20:30:18Z</dc:date>
    <item>
      <title>SSL decryption( Some traffic is not decrypted)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-some-traffic-is-not-decrypted/m-p/310089#M80325</link>
      <description>&lt;P&gt;Dear All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have applied SSL forward decryption in my Paloalto, then i observed some traffic are decrypted and some traffic not decrypt.&lt;/P&gt;&lt;P&gt;Example:- I have applied the decryption in social-networking (Facebook traffic is decrypted but Snapchat traffic is not decrypted,however, both are falling under the social-networking category.)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Why it's strange behaviour.&lt;/P&gt;</description>
      <pubDate>Fri, 07 Feb 2020 19:46:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-some-traffic-is-not-decrypted/m-p/310089#M80325</guid>
      <dc:creator>Jafar_Hussain</dc:creator>
      <dc:date>2020-02-07T19:46:28Z</dc:date>
    </item>
    <item>
      <title>Re: SSL decryption( Some traffic is not decrypted)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-some-traffic-is-not-decrypted/m-p/310098#M80326</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Unfortunately there is some traffic that cannot be decrypted or it will break the connection. Snapchat is one of these as it uses a pinned certificate.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="OtakarKlier_0-1581107884919.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/23871i189FF95B219E906B/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="OtakarKlier_0-1581107884919.png" alt="OtakarKlier_0-1581107884919.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;To view the automatically bypassed domains, click the Device tab -&amp;gt; Certificate Management -&amp;gt; SSL Decryption Exclusion&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClEzCAK" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClEzCAK&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;</description>
      <pubDate>Fri, 07 Feb 2020 20:39:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-some-traffic-is-not-decrypted/m-p/310098#M80326</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2020-02-07T20:39:38Z</dc:date>
    </item>
    <item>
      <title>Re: SSL decryption( Some traffic is not decrypted)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-some-traffic-is-not-decrypted/m-p/310104#M80327</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ok, thanks for the information. it means all the URL/Application which are already in exclusion, will not decrypt?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Apart from this if any traffic is not decrypted so what is the issue?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Feb 2020 20:53:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-some-traffic-is-not-decrypted/m-p/310104#M80327</guid>
      <dc:creator>Jafar_Hussain</dc:creator>
      <dc:date>2020-02-07T20:53:50Z</dc:date>
    </item>
    <item>
      <title>Re: SSL decryption( Some traffic is not decrypted)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-some-traffic-is-not-decrypted/m-p/310111#M80328</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/124013"&gt;@Jafar_Hussain&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Correct; if the domain is listed in the SSL Decryption Exclusion list, the firewall is going to let that through without going through the decryption process so that it doesn't break anything.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/124013"&gt;@Jafar_Hussain&lt;/a&gt;&amp;nbsp;wrote:&lt;P&gt;Apart from this if any traffic is not decrypted so what is the issue?&amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&amp;nbsp;Can you provide one of the domains that you are running into an issue with that isn't covered by an exclusion? Keep in mind, depending on how you have things configured if the firewall detects that it isn't able to decrypt certain traffic without causing an issue, it will put that into a cache to skip decryption going forward so it doesn't continue to break the site for users.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Feb 2020 21:13:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-some-traffic-is-not-decrypted/m-p/310111#M80328</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-02-07T21:13:02Z</dc:date>
    </item>
    <item>
      <title>Re: SSL decryption( Some traffic is not decrypted)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-some-traffic-is-not-decrypted/m-p/310112#M80329</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp; Thanks for the information.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I will keep is in observation. if i found something I will let you know.&lt;/P&gt;&lt;P&gt;Thanks once again.&lt;/P&gt;</description>
      <pubDate>Fri, 07 Feb 2020 21:27:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-some-traffic-is-not-decrypted/m-p/310112#M80329</guid>
      <dc:creator>Jafar_Hussain</dc:creator>
      <dc:date>2020-02-07T21:27:46Z</dc:date>
    </item>
    <item>
      <title>Re: SSL decryption( Some traffic is not decrypted)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-some-traffic-is-not-decrypted/m-p/310373#M80362</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am facing a problem with the certificate(When I enabled the decryption and tried to open the website in Mozilla and internet explorer it is working as expected means it is taking the same self-sign certificate which I have generated).&lt;/P&gt;&lt;P&gt;However, when I tried to access the website in chrome, the browser is not accepting the certificate which is generated by FW. it is taking its own google certificate.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you help me with this?&lt;/P&gt;</description>
      <pubDate>Mon, 10 Feb 2020 10:54:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-some-traffic-is-not-decrypted/m-p/310373#M80362</guid>
      <dc:creator>Jafar_Hussain</dc:creator>
      <dc:date>2020-02-10T10:54:36Z</dc:date>
    </item>
    <item>
      <title>Re: SSL decryption( Some traffic is not decrypted)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-some-traffic-is-not-decrypted/m-p/310436#M80383</link>
      <description>&lt;P&gt;&amp;nbsp;any one can give me reply........&lt;/P&gt;</description>
      <pubDate>Mon, 10 Feb 2020 19:27:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-some-traffic-is-not-decrypted/m-p/310436#M80383</guid>
      <dc:creator>Jafar_Hussain</dc:creator>
      <dc:date>2020-02-10T19:27:50Z</dc:date>
    </item>
    <item>
      <title>Re: SSL decryption( Some traffic is not decrypted)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-some-traffic-is-not-decrypted/m-p/310439#M80384</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/124013"&gt;@Jafar_Hussain&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Can you post the actual website so we can actually take a look at it.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Feb 2020 19:32:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-some-traffic-is-not-decrypted/m-p/310439#M80384</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-02-10T19:32:14Z</dc:date>
    </item>
    <item>
      <title>Re: SSL decryption( Some traffic is not decrypted)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-some-traffic-is-not-decrypted/m-p/310441#M80385</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Example:-&amp;nbsp; For testing, I have created a custom URL category only for (youtube+facebook+netflix). this is policy i mention in decryption rule with decrypt SSL forward proxy. and I have an import certificate already in my machine. when i try to open this URL in Mozilla and Internet explorer it is working as expected both browsers are taking a certificate which i have import however in chrome i can't see the same certificate this browser is taking its own google certificate why ?????&lt;/P&gt;</description>
      <pubDate>Mon, 10 Feb 2020 19:39:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-some-traffic-is-not-decrypted/m-p/310441#M80385</guid>
      <dc:creator>Jafar_Hussain</dc:creator>
      <dc:date>2020-02-10T19:39:48Z</dc:date>
    </item>
    <item>
      <title>Re: SSL decryption( Some traffic is not decrypted)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-some-traffic-is-not-decrypted/m-p/310442#M80386</link>
      <description>&lt;P&gt;How do these connecrions look in the traffic log? Could it be possible that they use port 443/udp?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Feb 2020 19:43:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-some-traffic-is-not-decrypted/m-p/310442#M80386</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2020-02-10T19:43:08Z</dc:date>
    </item>
    <item>
      <title>Re: SSL decryption( Some traffic is not decrypted)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-some-traffic-is-not-decrypted/m-p/310443#M80387</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/124013"&gt;@Jafar_Hussain&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Right off the bat I would look at if you are allowing QUIC traffic when you are utilizing Chrome.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Feb 2020 19:43:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-some-traffic-is-not-decrypted/m-p/310443#M80387</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-02-10T19:43:52Z</dc:date>
    </item>
    <item>
      <title>Re: SSL decryption( Some traffic is not decrypted)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-some-traffic-is-not-decrypted/m-p/310444#M80388</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp; I am not getting your point.&lt;/P&gt;&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;&amp;nbsp; I can see in the traffic log when I open the chrome browser there is no decryption showing in traffic log however when I open in Mozilla traffic log showing as decrypted.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Feb 2020 19:55:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-some-traffic-is-not-decrypted/m-p/310444#M80388</guid>
      <dc:creator>Jafar_Hussain</dc:creator>
      <dc:date>2020-02-10T19:55:01Z</dc:date>
    </item>
    <item>
      <title>Re: SSL decryption( Some traffic is not decrypted)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-some-traffic-is-not-decrypted/m-p/310446#M80389</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/124013"&gt;@Jafar_Hussain&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Chrome will default to using the QUIC protocol, which to&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;'s point will come across on udp/443. Best practices would have you disallowing QUIC connections so that traffic is forced to fail-back to standard SSL/TLS connections over tcp/443. Then your decryption will actually work.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Feb 2020 20:00:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-some-traffic-is-not-decrypted/m-p/310446#M80389</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-02-10T20:00:15Z</dc:date>
    </item>
    <item>
      <title>Re: SSL decryption( Some traffic is not decrypted)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-some-traffic-is-not-decrypted/m-p/310447#M80390</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;&lt;/P&gt;&lt;P&gt;Thanks for your reply.&lt;/P&gt;&lt;P&gt;I will check tomorrow and let you know.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Feb 2020 20:04:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-some-traffic-is-not-decrypted/m-p/310447#M80390</guid>
      <dc:creator>Jafar_Hussain</dc:creator>
      <dc:date>2020-02-10T20:04:57Z</dc:date>
    </item>
    <item>
      <title>Re: SSL decryption( Some traffic is not decrypted)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-some-traffic-is-not-decrypted/m-p/310537#M80407</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your help and support.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Below is the task i have performed:-&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have disabled the QUIC protocol in the chrome browser then it is working as expected.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;Problem:-&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;But i have large network in my environment, so i am not going through to disable the QUIC protocol in every system.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;Solution:-&lt;/STRONG&gt;&lt;/U&gt; I have gone through the below documents and deny the traffic of the QUIC application. now it is working as expected.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClarCAC" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClarCAC&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2020 06:52:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-some-traffic-is-not-decrypted/m-p/310537#M80407</guid>
      <dc:creator>Jafar_Hussain</dc:creator>
      <dc:date>2020-02-11T06:52:03Z</dc:date>
    </item>
    <item>
      <title>Re: SSL decryption( Some traffic is not decrypted)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-some-traffic-is-not-decrypted/m-p/310825#M80487</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;hello,&lt;/P&gt;&lt;P&gt;Now the problem is chrome is accepting the certificate, but I am not able some websites in the chrome browser.&lt;/P&gt;&lt;P&gt;Ex:- I have applied decryption only for youtube and NetFlix. but when I open Netflix it is working fine below is the screenshot for Netflix:-&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Jafar_Hussain_0-1581521919783.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/23922iCDB8090A13854D03/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Jafar_Hussain_0-1581521919783.png" alt="Jafar_Hussain_0-1581521919783.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;But When I open youtube in chrome, getting the error. below is the screenshot.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Jafar_Hussain_1-1581522020611.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/23923i2905E6AE8A09B547/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Jafar_Hussain_1-1581522020611.png" alt="Jafar_Hussain_1-1581522020611.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have changed certificates already with SHA 512 value but still issue persists.&lt;/P&gt;&lt;P&gt;Could you please help me with this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Feb 2020 15:41:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-some-traffic-is-not-decrypted/m-p/310825#M80487</guid>
      <dc:creator>Jafar_Hussain</dc:creator>
      <dc:date>2020-02-12T15:41:38Z</dc:date>
    </item>
    <item>
      <title>Re: SSL decryption( Some traffic is not decrypted)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-some-traffic-is-not-decrypted/m-p/310878#M80494</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could you please update on this,&lt;/P&gt;</description>
      <pubDate>Wed, 12 Feb 2020 18:48:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-some-traffic-is-not-decrypted/m-p/310878#M80494</guid>
      <dc:creator>Jafar_Hussain</dc:creator>
      <dc:date>2020-02-12T18:48:07Z</dc:date>
    </item>
    <item>
      <title>Re: SSL decryption( Some traffic is not decrypted)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-some-traffic-is-not-decrypted/m-p/310889#M80496</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/124013"&gt;@Jafar_Hussain&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Neither &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;nor me &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp; are working for Paloaltonetworks. We use our free time to try to help here in the community. So if you cannot wait more than 3 hours (as you asked again for an update here 3 hours after your post with the cert warnings) you should contact official paloalto support.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyway, which certificate did you change to SHA512? Was it really the CA cert used for decryption? What key size did you configure for the dynamically created certificates? Could you show a screenshot of the cert?&lt;/P&gt;</description>
      <pubDate>Wed, 12 Feb 2020 20:30:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-some-traffic-is-not-decrypted/m-p/310889#M80496</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2020-02-12T20:30:18Z</dc:date>
    </item>
    <item>
      <title>Re: SSL decryption( Some traffic is not decrypted)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-some-traffic-is-not-decrypted/m-p/310949#M80509</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sorry for this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have configured a new CA certificate with keysize- 2048 and sha 512.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Feb 2020 05:20:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-some-traffic-is-not-decrypted/m-p/310949#M80509</guid>
      <dc:creator>Jafar_Hussain</dc:creator>
      <dc:date>2020-02-13T05:20:14Z</dc:date>
    </item>
    <item>
      <title>Re: SSL decryption( Some traffic is not decrypted)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-some-traffic-is-not-decrypted/m-p/311050#M80523</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/124013"&gt;@Jafar_Hussain&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and you did configure this new ca cert as "Forward Trust Certificate"?&lt;/P&gt;</description>
      <pubDate>Thu, 13 Feb 2020 12:47:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-some-traffic-is-not-decrypted/m-p/311050#M80523</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2020-02-13T12:47:05Z</dc:date>
    </item>
  </channel>
</rss>

