<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSL Decryption every day more exclusions in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-every-day-more-exclusions/m-p/332820#M84117</link>
    <description>&lt;P&gt;There are an increasing number of sites that use techniques that block SSL decryption. As an example, SSL pinning is used to block MITM attacks so it will keep you from accessing a site that uses it when SSL decrypt is enabled.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The PA has a large default list of excluded sites, located in Device-Certificate Management-SSL Decryption Exclusion. We've had to add a fair number of sites to this list, including a few of the Microsoft online offerings.&lt;/P&gt;&lt;P&gt;I would agree that you shouldn't disable decryption globally, you'll just have to keep on top of creating exclusions when needed. I think you should also review your current policies. As you say, they are pretty soft.&lt;/P&gt;</description>
    <pubDate>Wed, 10 Jun 2020 16:50:02 GMT</pubDate>
    <dc:creator>rmfalconer</dc:creator>
    <dc:date>2020-06-10T16:50:02Z</dc:date>
    <item>
      <title>SSL Decryption every day more exclusions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-every-day-more-exclusions/m-p/332217#M84013</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are using a PaloAlto 3260 with PanOS 9.0.7. We have configured SSL decryption wich uses a certificate signed by our own Windows CA server. Each client in our environment has the Windows Root CA.&lt;/P&gt;&lt;P&gt;In the beginning (2 years ago) everything worked well. We could decrypt everything except everything in the category financial.&lt;/P&gt;&lt;P&gt;But now latest months it seems I need to add a lot of websites for no decryption because otherwise the employees can't visit the website. It is getting frustrated and I'm think about disabling SSL decryption, but maybe you guys know an answer or solution.&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jun 2020 06:37:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-every-day-more-exclusions/m-p/332217#M84013</guid>
      <dc:creator>ZEBIT</dc:creator>
      <dc:date>2020-06-08T06:37:14Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption every day more exclusions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-every-day-more-exclusions/m-p/332275#M84024</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1006"&gt;@ZEBIT&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would advise against disabling SSL decryption entirely.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Instead of just adding them to the no decrypt policy try figuring out why users are experiencing issues with those sites.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Are you blocking access on some of the verifications (unsupported ciphers, versions, certificate issues, ... ) ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;-Kiwi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV id="ConnectiveDocSignExtentionInstalled" data-extension-version="1.0.4"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Mon, 08 Jun 2020 09:47:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-every-day-more-exclusions/m-p/332275#M84024</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2020-06-08T09:47:36Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption every day more exclusions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-every-day-more-exclusions/m-p/332288#M84025</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11943"&gt;@kiwi&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think I'm quit soft (too soft) in my policy. Here you can see screenshots of the whole policy + certficats like our partner implemented.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture3.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/26136iB0CF77B537A713CD/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Capture3.PNG" alt="Capture3.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture4.PNG" style="width: 801px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/26134i0230E568D453E80A/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Capture4.PNG" alt="Capture4.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture5.PNG" style="width: 801px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/26135i687E7D70B908BD90/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Capture5.PNG" alt="Capture5.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture6.PNG" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/26133i93BCCDB70D9D7858/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Capture6.PNG" alt="Capture6.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture7.PNG" style="width: 956px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/26137i0BDEAC345BCD59F8/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Capture7.PNG" alt="Capture7.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture.PNG" style="width: 804px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/26138i6A998B18959A2266/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Capture.PNG" alt="Capture.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture1.PNG" style="width: 798px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/26139iFAF7AF8711633DE5/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Capture1.PNG" alt="Capture1.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jun 2020 10:13:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-every-day-more-exclusions/m-p/332288#M84025</guid>
      <dc:creator>ZEBIT</dc:creator>
      <dc:date>2020-06-08T10:13:16Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption every day more exclusions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-every-day-more-exclusions/m-p/332820#M84117</link>
      <description>&lt;P&gt;There are an increasing number of sites that use techniques that block SSL decryption. As an example, SSL pinning is used to block MITM attacks so it will keep you from accessing a site that uses it when SSL decrypt is enabled.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The PA has a large default list of excluded sites, located in Device-Certificate Management-SSL Decryption Exclusion. We've had to add a fair number of sites to this list, including a few of the Microsoft online offerings.&lt;/P&gt;&lt;P&gt;I would agree that you shouldn't disable decryption globally, you'll just have to keep on top of creating exclusions when needed. I think you should also review your current policies. As you say, they are pretty soft.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jun 2020 16:50:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-every-day-more-exclusions/m-p/332820#M84117</guid>
      <dc:creator>rmfalconer</dc:creator>
      <dc:date>2020-06-10T16:50:02Z</dc:date>
    </item>
  </channel>
</rss>

