<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: OSX update and Decryption in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/osx-update-and-decryption/m-p/316980#M81475</link>
    <description>&lt;P&gt;Hi,&lt;SPAN class="UserName lia-user-name lia-user-rank-L7-Applicator lia-component-message-view-widget-author-username"&gt;&lt;A href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480" target="_self"&gt;&lt;SPAN class=""&gt;BPry&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;gt;Whitelist the following:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;gt;....&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV class="lia-message-author-with-avatar"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="lia-message-author-with-avatar"&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-L7-Applicator lia-component-message-view-widget-author-username"&gt;&lt;SPAN class=""&gt;Is this list actual?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="lia-message-author-with-avatar"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="lia-message-author-with-avatar"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="lia-message-author-with-avatar"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="lia-message-author-with-avatar"&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-L7-Applicator lia-component-message-view-widget-author-username"&gt;&lt;SPAN class=""&gt;&amp;nbsp;You mean path "Device -&amp;gt; Cert mgmt -&amp;gt; SSL Decription Exclusion" and add&amp;nbsp; all listed domains one by one?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="lia-message-author-with-avatar"&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-L7-Applicator lia-component-message-view-widget-author-username"&gt;&lt;SPAN class=""&gt;Or "Policies -&amp;gt; Decryption -&amp;gt; New rule" and add rule with custom URL category.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Andrew&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 18 Mar 2020 08:18:13 GMT</pubDate>
    <dc:creator>aaobuhov</dc:creator>
    <dc:date>2020-03-18T08:18:13Z</dc:date>
    <item>
      <title>OSX update and Decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/osx-update-and-decryption/m-p/287464#M76717</link>
      <description>&lt;P&gt;I've installed our Root CA cert in the "System" keychain, and have it marked as trusted.&amp;nbsp; I can successfully decrypt web traffic from a MAC running Mojave.&amp;nbsp; No problems there.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The problem comes in when I try updating the OSX or even check for updates from the CLI.&amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I run "softwareupdate -l"&amp;nbsp; in terminal, In the logs on the firewall it appears to be coming through as web browsing app, and getting decrypted.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I ran a packet capture, and it shows the client is resetting the connection after succesffuly going out to&amp;nbsp;swscan.apple.com, which is not whitelisted for decryption exclusions.&amp;nbsp; Has anyone run into issues when trying to decrypt on OSX with a trusted root cert, while trying to update the operating system itself?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Guessing adding these domains to decryption exclusion is going to fix this?&lt;/P&gt;</description>
      <pubDate>Mon, 09 Sep 2019 20:27:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/osx-update-and-decryption/m-p/287464#M76717</guid>
      <dc:creator>Sec101</dc:creator>
      <dc:date>2019-09-09T20:27:35Z</dc:date>
    </item>
    <item>
      <title>Re: OSX update and Decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/osx-update-and-decryption/m-p/287498#M76718</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/59122"&gt;@Sec101&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Whitelist the following:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;gg.apple.com&lt;/LI&gt;&lt;LI&gt;gnf-mdn.apple.com&lt;/LI&gt;&lt;LI&gt;gnf-mr.apple.com&lt;/LI&gt;&lt;LI&gt;gs.apple.com&lt;/LI&gt;&lt;LI&gt;ig.apple.com&lt;/LI&gt;&lt;LI&gt;mesu.apple.com&lt;/LI&gt;&lt;LI&gt;skl.apple.com&lt;/LI&gt;&lt;LI&gt;swcdn.apple.com&lt;/LI&gt;&lt;LI&gt;swdist.apple.com&lt;/LI&gt;&lt;LI&gt;swdownload.apple.com&lt;/LI&gt;&lt;LI&gt;swpost.apple.com&lt;/LI&gt;&lt;LI&gt;swscan.apple.com&lt;/LI&gt;&lt;LI&gt;updates-http.cdn-apple.com&lt;/LI&gt;&lt;LI&gt;updates.cdn-apple.com&lt;/LI&gt;&lt;LI&gt;xp.apple.com&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;That should take care of the software updates and allow your clients to actually update successfully.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Sep 2019 01:48:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/osx-update-and-decryption/m-p/287498#M76718</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-09-10T01:48:07Z</dc:date>
    </item>
    <item>
      <title>Re: OSX update and Decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/osx-update-and-decryption/m-p/287644#M76727</link>
      <description>&lt;P&gt;Perfect!&amp;nbsp; As always, an excellent reply!&amp;nbsp; Thank you.&amp;nbsp; When you say whitelist- you mean exclude decryption right?&lt;/P&gt;</description>
      <pubDate>Tue, 10 Sep 2019 14:01:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/osx-update-and-decryption/m-p/287644#M76727</guid>
      <dc:creator>Sec101</dc:creator>
      <dc:date>2019-09-10T14:01:08Z</dc:date>
    </item>
    <item>
      <title>Re: OSX update and Decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/osx-update-and-decryption/m-p/287645#M76728</link>
      <description>&lt;P&gt;Correct. Exclude those domains from decryption and your clients should be able to check for and download updates again.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Sep 2019 14:04:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/osx-update-and-decryption/m-p/287645#M76728</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-09-10T14:04:37Z</dc:date>
    </item>
    <item>
      <title>Re: OSX update and Decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/osx-update-and-decryption/m-p/316980#M81475</link>
      <description>&lt;P&gt;Hi,&lt;SPAN class="UserName lia-user-name lia-user-rank-L7-Applicator lia-component-message-view-widget-author-username"&gt;&lt;A href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480" target="_self"&gt;&lt;SPAN class=""&gt;BPry&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;gt;Whitelist the following:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;gt;....&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV class="lia-message-author-with-avatar"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="lia-message-author-with-avatar"&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-L7-Applicator lia-component-message-view-widget-author-username"&gt;&lt;SPAN class=""&gt;Is this list actual?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="lia-message-author-with-avatar"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="lia-message-author-with-avatar"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="lia-message-author-with-avatar"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="lia-message-author-with-avatar"&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-L7-Applicator lia-component-message-view-widget-author-username"&gt;&lt;SPAN class=""&gt;&amp;nbsp;You mean path "Device -&amp;gt; Cert mgmt -&amp;gt; SSL Decription Exclusion" and add&amp;nbsp; all listed domains one by one?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="lia-message-author-with-avatar"&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-L7-Applicator lia-component-message-view-widget-author-username"&gt;&lt;SPAN class=""&gt;Or "Policies -&amp;gt; Decryption -&amp;gt; New rule" and add rule with custom URL category.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Andrew&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Mar 2020 08:18:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/osx-update-and-decryption/m-p/316980#M81475</guid>
      <dc:creator>aaobuhov</dc:creator>
      <dc:date>2020-03-18T08:18:13Z</dc:date>
    </item>
    <item>
      <title>Re: OSX update and Decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/osx-update-and-decryption/m-p/317037#M81487</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/97840"&gt;@aaobuhov&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;That is the actual list yes. You can exclude these domains in either method, personally I like doing it in the decryption rulebase via a custom No-Decrypt URL category.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Mar 2020 13:08:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/osx-update-and-decryption/m-p/317037#M81487</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-03-18T13:08:13Z</dc:date>
    </item>
    <item>
      <title>Re: OSX update and Decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/osx-update-and-decryption/m-p/317040#M81488</link>
      <description>&lt;P&gt;Thank you for reply&amp;nbsp;&lt;/P&gt;&lt;P&gt;I prefer "&lt;SPAN&gt;No-Decrypt URL category" too.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Can i summarize your list to:&lt;/P&gt;&lt;P&gt;*.apple.com&lt;/P&gt;&lt;P&gt;*.cdn-apple.com&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It will be a less strict list.&lt;BR /&gt;Is such version possible?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Andrew&lt;/P&gt;</description>
      <pubDate>Wed, 18 Mar 2020 13:17:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/osx-update-and-decryption/m-p/317040#M81488</guid>
      <dc:creator>aaobuhov</dc:creator>
      <dc:date>2020-03-18T13:17:06Z</dc:date>
    </item>
    <item>
      <title>Re: OSX update and Decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/osx-update-and-decryption/m-p/317041#M81489</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/97840"&gt;@aaobuhov&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;You could. As you said, it would be less restrictive and potentially allow additional traffic that you otherwise could have decrypted and gained insight into.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Mar 2020 13:20:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/osx-update-and-decryption/m-p/317041#M81489</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-03-18T13:20:18Z</dc:date>
    </item>
    <item>
      <title>Re: OSX update and Decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/osx-update-and-decryption/m-p/317043#M81490</link>
      <description>&lt;P&gt;Thank you, I understand.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best wishes,&lt;BR /&gt;Andrew&lt;/P&gt;</description>
      <pubDate>Wed, 18 Mar 2020 13:30:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/osx-update-and-decryption/m-p/317043#M81490</guid>
      <dc:creator>aaobuhov</dc:creator>
      <dc:date>2020-03-18T13:30:03Z</dc:date>
    </item>
  </channel>
</rss>

