<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Decryption issue in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/decryption-issue/m-p/433229#M95839</link>
    <description>&lt;P&gt;Hello there.&lt;/P&gt;&lt;P&gt;Suggestions I have (not that I am fixing issue, but trying to understand what can/cannot be done)&lt;/P&gt;&lt;P&gt;Go into your Decryption Profile and set the TLS to 1.2 to 1.2 (and not MAX)&lt;/P&gt;&lt;P&gt;While in the profile (for tshooting only), uncheck the 3 checkmarks/boxes under Server Certificate Verification.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You should also look at the Traffic Logs for that specific session and provide the End Session Reason (was it tcp-reset-server or client, threat, decryption error, etc).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We need more information.&amp;nbsp; It is possible that the site just cannot be decrypted and needs to have an exception generated for it.&amp;nbsp; There are some limitations to how the server certificates are generated (think certificate key pinning or hair pinning) that could generate similar results.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Good luck and let us know.&lt;/P&gt;</description>
    <pubDate>Fri, 10 Sep 2021 21:33:17 GMT</pubDate>
    <dc:creator>S.Cantwell</dc:creator>
    <dc:date>2021-09-10T21:33:17Z</dc:date>
    <item>
      <title>Decryption issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/decryption-issue/m-p/433192#M95834</link>
      <description>&lt;P&gt;We have outbound decryption working but there are few sites that popup that donot work from time to time and have to add the to exceptions.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am trying to investigate a recently highlighted website and to learn how to troubleshoot this better.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I run this openssl command connection on the client is successful and wireshark output looks like this and client sees server hello.&lt;/P&gt;&lt;P&gt;-----------------------------------------------&lt;/P&gt;&lt;P&gt;.\openssl s_client -connect windowstechpro.com:443 -brief&lt;BR /&gt;depth=3 DC = ca, DC = abcdef, DC = abc, CN = ABC DEF - Root CA&lt;BR /&gt;verify error:num=19:self signed certificate in certificate chain&lt;BR /&gt;CONNECTION ESTABLISHED&lt;BR /&gt;Protocol version: TLSv1.2&lt;BR /&gt;Ciphersuite: ECDHE-RSA-AES128-SHA256&lt;BR /&gt;Peer certificate: CN = *.windowstechpro.com&lt;BR /&gt;Hash used: SHA256&lt;BR /&gt;Signature type: RSA&lt;BR /&gt;Verification error: self signed certificate in certificate chain&lt;BR /&gt;Server Temp Key: ECDH, P-384, 384 bits&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;-----------------------------------------------&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/36324iE38D67C3DBC037E1/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;but on PA capture looks like this.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/36329i1D1952FC18196575/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;When trying to open the website in browser in firefox it shows&amp;nbsp;PR_END_OF_FILE_ERROR &amp;amp; in chrome "&lt;STRONG&gt;windowstechpro.com&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;unexpectedly closed the connection.&lt;/SPAN&gt;"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On client wireshark shows like this and client never receives a server hello.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/36330i6A16AFBC0BF985E2/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Firewall still looks the same&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/36331i39EFC2017D488035/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Profile settings&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 750px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/36332iDDAA06B5CA828C9A/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 654px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/36333i46DD1BC2132931E6/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Sep 2021 18:51:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/decryption-issue/m-p/433192#M95834</guid>
      <dc:creator>raji_toor</dc:creator>
      <dc:date>2021-09-10T18:51:09Z</dc:date>
    </item>
    <item>
      <title>Re: Decryption issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/decryption-issue/m-p/433229#M95839</link>
      <description>&lt;P&gt;Hello there.&lt;/P&gt;&lt;P&gt;Suggestions I have (not that I am fixing issue, but trying to understand what can/cannot be done)&lt;/P&gt;&lt;P&gt;Go into your Decryption Profile and set the TLS to 1.2 to 1.2 (and not MAX)&lt;/P&gt;&lt;P&gt;While in the profile (for tshooting only), uncheck the 3 checkmarks/boxes under Server Certificate Verification.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You should also look at the Traffic Logs for that specific session and provide the End Session Reason (was it tcp-reset-server or client, threat, decryption error, etc).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We need more information.&amp;nbsp; It is possible that the site just cannot be decrypted and needs to have an exception generated for it.&amp;nbsp; There are some limitations to how the server certificates are generated (think certificate key pinning or hair pinning) that could generate similar results.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Good luck and let us know.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Sep 2021 21:33:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/decryption-issue/m-p/433229#M95839</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2021-09-10T21:33:17Z</dc:date>
    </item>
    <item>
      <title>Re: Decryption issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/decryption-issue/m-p/433573#M95883</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/113304"&gt;@S.Cantwell&lt;/a&gt;&amp;nbsp;I had not done basic troubleshooting and straightaway went for packet captures. Couple of websites I know that were recently highlighted both worked after I broadened the scope of TLS and set minimum to 1.1 with less preferable algorithms.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I still want to ask what was the rational behind behind suggesting to set max version to 1.2 instead of max, doesn't both mean the same as 1.3 is not supported.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 659px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/36363iB78014C88F56439D/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Sep 2021 17:32:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/decryption-issue/m-p/433573#M95883</guid>
      <dc:creator>raji_toor</dc:creator>
      <dc:date>2021-09-13T17:32:34Z</dc:date>
    </item>
    <item>
      <title>Re: Decryption issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/decryption-issue/m-p/433642#M95901</link>
      <description>&lt;P&gt;So, what I understand, based on your settings, is that you have Users or Servers on the internet, that are not following the recommended patch releases to deprecate TLS 1.1 and lower.&amp;nbsp;&amp;nbsp; In Feb/March 2020, the 3 big browser companies (Microsoft, Mozilla, Google) agreed to DEPRECATE support for TLS 1.0 and 1.1.&amp;nbsp;&amp;nbsp;&amp;nbsp; Today's modern browsers support TLS 1.2 and 1.3.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You have run into a situation where the WEBSITE on the Internet is NOT TLS 1.2.&amp;nbsp; It seems to not have been patched to deprecate support for TLS 1.0 and 1.1.&amp;nbsp; So you needed to modify your security configuration to allow 1.1.&amp;nbsp;&lt;/P&gt;&lt;P&gt;You should create 2 decryption profiles.&amp;nbsp; One that support TLS 1.2 to 1.2, and then other one, for this specific destination server, to use this (not recommended) profile of TLS 1.1.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As for my suggestion about TLS 1.3&amp;nbsp; As I just explained.. the FW CAN support TLS 1.3... but if the Website does NOT.. then you will have problems with decryption, because of TLS mismatch.&amp;nbsp;&amp;nbsp; TLS 1.3 can be backward compatible to TLS 1.2.&amp;nbsp; So... on the off chance a TLS 1.3 server talks to to a TLS 1.2 end point, your FW can allow the traffic.&amp;nbsp; It is just a recommendation from PANW.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Sep 2021 21:57:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/decryption-issue/m-p/433642#M95901</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2021-09-13T21:57:43Z</dc:date>
    </item>
  </channel>
</rss>

