<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SSL Inbound decryption -Decryption error in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-inbound-decryption-decryption-error/m-p/315965#M81322</link>
    <description>&lt;P&gt;One of my application is not&amp;nbsp; decrypted i have applied SSL inbound decryption policy&amp;nbsp; and got decryption-error.&lt;/P&gt;&lt;P&gt;On other hand another application with same intermediate certificate&amp;nbsp; having decrypted. As same intermediate only&amp;nbsp; child certificate is change.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Untitled.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/24369i60B0F8A290FCB619/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Untitled.png" alt="Untitled.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 12 Mar 2020 07:18:23 GMT</pubDate>
    <dc:creator>Joshan_Lakhani</dc:creator>
    <dc:date>2020-03-12T07:18:23Z</dc:date>
    <item>
      <title>SSL Inbound decryption -Decryption error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-inbound-decryption-decryption-error/m-p/315965#M81322</link>
      <description>&lt;P&gt;One of my application is not&amp;nbsp; decrypted i have applied SSL inbound decryption policy&amp;nbsp; and got decryption-error.&lt;/P&gt;&lt;P&gt;On other hand another application with same intermediate certificate&amp;nbsp; having decrypted. As same intermediate only&amp;nbsp; child certificate is change.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Untitled.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/24369i60B0F8A290FCB619/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Untitled.png" alt="Untitled.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Mar 2020 07:18:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-inbound-decryption-decryption-error/m-p/315965#M81322</guid>
      <dc:creator>Joshan_Lakhani</dc:creator>
      <dc:date>2020-03-12T07:18:23Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Inbound decryption -Decryption error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-inbound-decryption-decryption-error/m-p/316094#M81343</link>
      <description>&lt;P&gt;It is near impossible to answer any speculative issues without logs showing details..&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Looking at past cases, this issue is normally caused by&lt;SPAN&gt;&amp;nbsp;an incomplete certificate chain.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Normally, the workaround for this particular issue to import the entire chain as one bundle. Please follow the document:- &lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/How-to-Install-a-Chained-Certificate-Signed-by-a-Public-CA/ta-p/55523" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/How-to-Install-a-Chained-Certificate-Signed-by-a-Public-CA/ta-p/55523&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I hope this helps.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Mar 2020 19:05:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-inbound-decryption-decryption-error/m-p/316094#M81343</guid>
      <dc:creator>jdelio</dc:creator>
      <dc:date>2020-03-12T19:05:38Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Inbound decryption -Decryption error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-inbound-decryption-decryption-error/m-p/316100#M81344</link>
      <description>&lt;P&gt;Certificate chain is also complete intermediate and parent certificate all are complete i have received this already when i apply decryption.&lt;/P&gt;&lt;P&gt;traffic is generating an error message - ERR_SSL_VERSION_OR_CIPHER_MISMATCH (Cipher suite mismatch&amp;nbsp;Firewall and server).&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture.PNG" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/24375i5873E5C717498E99/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Capture.PNG" alt="Capture.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Mar 2020 19:19:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-inbound-decryption-decryption-error/m-p/316100#M81344</guid>
      <dc:creator>Joshan_Lakhani</dc:creator>
      <dc:date>2020-03-12T19:19:43Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Inbound decryption -Decryption error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-inbound-decryption-decryption-error/m-p/534692#M110009</link>
      <description>&lt;P&gt;Sorry for the bump, but it might help others.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I stumbled upon the exact same problem, the problem in this case was that the certificate/key were automatically renewed on the server. This is quite common when using Let's Encrypt with ACME (http-01 or dns-01) challenge.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When getting this error make sure to check if this is the case.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In these cases it makes sense to automate the renewal of the certificates on the firewall with the API, as an example.&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;curl -k -X POST -F "file=@server.key" "https://1.2.3.4/api/?key=xxx&amp;amp;type=import&amp;amp;category=private-key&amp;amp;certificate-name=server.com&amp;amp;format=pem&amp;amp;passphrase=xxx"
&lt;/LI-CODE&gt;&lt;LI-CODE lang="markup"&gt;curl -k -X POST -F "file=@server.crt" "https://1.2.3.4/api/?key=xxx&amp;amp;type=import&amp;amp;category=certificate&amp;amp;certificate-name=server.com&amp;amp;format=pem"&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Mar 2023 10:50:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-inbound-decryption-decryption-error/m-p/534692#M110009</guid>
      <dc:creator>robmaas</dc:creator>
      <dc:date>2023-03-16T10:50:42Z</dc:date>
    </item>
  </channel>
</rss>

