<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Palo decrypt error unsupported in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/palo-decrypt-error-unsupported/m-p/410004#M92529</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/85066"&gt;@BigPalo&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What PAN-OS version do you use? Could you tell us the website where you see this decryption error?&lt;/P&gt;</description>
    <pubDate>Sat, 29 May 2021 13:43:55 GMT</pubDate>
    <dc:creator>Remo</dc:creator>
    <dc:date>2021-05-29T13:43:55Z</dc:date>
    <item>
      <title>Palo decrypt error unsupported</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-decrypt-error-unsupported/m-p/409778#M92495</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are receiving decrypt error in our ssl inspection traffic&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;++++As Per the below logs Server is using an unsupported EC curve x25519. Correct the server configuration to use a curve that the firewall supports.++++&lt;BR /&gt;&lt;BR /&gt;2021-03-17 06:59:01.789 +0100 Error: pan_tls_ec_curve_id_2nid(pan_ec_common.c:66): unsupported ec curve_id 29&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&lt;BR /&gt;2021-03-17 06:59:01.789 +0100 Error: pan_ecdh_parse_server_key_exchange_msg(pan_ecdh.c:436): unsupported curve_na&lt;BR /&gt;me 29.&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&lt;BR /&gt;2021-03-17 06:59:01.789 +0100 Error: pan_ssl_keyxchg_parse_server_key_exchange_msg(pan_ssl_keyxchg.c:166): parse_&lt;BR /&gt;server_key_exchange_msg(ecdhe) failed&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&lt;BR /&gt;&lt;BR /&gt;PAN-OS 8.1 Decryption Cipher Suites&lt;BR /&gt;&amp;gt;&amp;gt;&lt;A href="https://eur01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fdocs.paloaltonetworks.com%2Fcompatibility-matrix%2Fsupported-cipher-suites%2Fcipher-suites-supported-in-pan-os-8-1%2Fcipher-suites-supported-in-pan-os-8-1-decryption.html%23id181GE0UF0HR_id17C8FH070PP&amp;amp;data=04%7C01%7CJesus.CANO%40axians.es%7C66b8d5877674422c43d308d9210de7bf%7Ccae7d06108f340dd80c33c0b8889224a%7C0%7C0%7C637577165879230851%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&amp;amp;sdata=Ke%2FP%2FJ5depB%2BXfaIR2j0dwxd6DOe4Z1mFgHKENSVlJU%3D&amp;amp;reserved=0" target="_blank"&gt;https://docs.paloaltonetworks.com/compatibility-matrix/supported-cipher-suites/cipher-suites-supported-in-pan-os-8-1/cipher-suites-supported-in-pan-os-8-1-decryption.html#id181GE0UF0HR_id17C8FH070PP&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;-------&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;I still don't understand why the PA generates a "decryption error" instead of letting the connection go through. During testing there were some cases where the client supported TLS 1.3. As the servers also support it and the AP does not, the connection just worked. In this case, the "conflicting" information does not arrive in the "Server hello" message but just after the "key exchange" message, but since the Server hello message is not transmitted to the client, you should undo the session proxy and forward the original message from the server to the client. Anyway, I guess it can't be done for some reason.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;any wway to solve it?&lt;/P&gt;</description>
      <pubDate>Fri, 28 May 2021 06:46:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-decrypt-error-unsupported/m-p/409778#M92495</guid>
      <dc:creator>BigPalo</dc:creator>
      <dc:date>2021-05-28T06:46:20Z</dc:date>
    </item>
    <item>
      <title>Re: Palo decrypt error unsupported</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-decrypt-error-unsupported/m-p/410004#M92529</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/85066"&gt;@BigPalo&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What PAN-OS version do you use? Could you tell us the website where you see this decryption error?&lt;/P&gt;</description>
      <pubDate>Sat, 29 May 2021 13:43:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-decrypt-error-unsupported/m-p/410004#M92529</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2021-05-29T13:43:55Z</dc:date>
    </item>
    <item>
      <title>Re: Palo decrypt error unsupported</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-decrypt-error-unsupported/m-p/410213#M92568</link>
      <description>&lt;P&gt;If your firewall is 8.1 as you have given an article for it then you will not be able to decrypt TLS1.3. Read this:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-new-features/decryption-features/ssl-decryption-support-for-tlsv13.html" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-new-features/decryption-features/ssl-decryption-support-for-tlsv13.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also in version 10 there is a new log for SSL decryption issues:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-admin/decryption/troubleshoot-and-monitor-decryption.html" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-admin/decryption/troubleshoot-and-monitor-decryption.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 31 May 2021 19:42:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-decrypt-error-unsupported/m-p/410213#M92568</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2021-05-31T19:42:12Z</dc:date>
    </item>
  </channel>
</rss>

