<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Minemeld SSL Certificates in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/minemeld-ssl-certificates/m-p/246058#M97243</link>
    <description>&lt;P&gt;Thank you so much, I can make the PA vm send https log to minemeld now.&lt;/P&gt;
&lt;P&gt;Best Regards,&lt;/P&gt;
&lt;P&gt;An&lt;/P&gt;</description>
    <pubDate>Tue, 15 Jan 2019 10:05:40 GMT</pubDate>
    <dc:creator>Nupagazy</dc:creator>
    <dc:date>2019-01-15T10:05:40Z</dc:date>
    <item>
      <title>Minemeld SSL Certificates</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/minemeld-ssl-certificates/m-p/112938#M97232</link>
      <description>&lt;P&gt;Hi - 2 questions:-&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;gt; How do we change the default SSL certificate on Minemeld?&amp;nbsp; Standard Apache cert replacement?&lt;/P&gt;
&lt;P&gt;&amp;gt; If we have a custom source running SSL with a self-signed cert, can we force a HTTPS miner to ignore the cert error?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 13 Sep 2016 16:43:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/minemeld-ssl-certificates/m-p/112938#M97232</guid>
      <dc:creator>apackard</dc:creator>
      <dc:date>2016-09-13T16:43:52Z</dc:date>
    </item>
    <item>
      <title>Re: Minemeld SSL Certificates</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/minemeld-ssl-certificates/m-p/112940#M97233</link>
      <description>&lt;P&gt;Hi apackard,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;How to change certs&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Certificate is served by nginx and stored in /etc/nginx/minemeld.cer (certificate) /etc/nginx/minemeld.pem (private key). You can stop nginx ("sudo service nginx stop"), replace the files with a valid certificate and private key and restart nginx ("sudo service nginx start").&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Ignore cert errors&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Sure, this is usually done with the prototype. Which Miner are you using ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Sep 2016 16:54:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/minemeld-ssl-certificates/m-p/112940#M97233</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2016-09-13T16:54:47Z</dc:date>
    </item>
    <item>
      <title>Re: Minemeld SSL Certificates</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/minemeld-ssl-certificates/m-p/113186#M97234</link>
      <description>&lt;P&gt;Thanks very much - half asleep on the Apache\ngix mixup..!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I created a new miner and used the following prototype as a template: - minemeld.ft.http.HttpFT&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;TABLE class="table table-condensed"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;attributes&lt;/TD&gt;
&lt;TD&gt;
&lt;UL&gt;
&lt;LI&gt;application: http&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI&gt;confidence: 100&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI&gt;direction: inbound&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI&gt;share_level: green&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI&gt;type: IPv4&lt;/LI&gt;
&lt;/UL&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;source_name&lt;/TD&gt;
&lt;TD&gt;&lt;SPAN&gt;mm.ciuthreatintel&lt;/SPAN&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;url&lt;/TD&gt;
&lt;TD&gt;&lt;SPAN&gt;https://&amp;lt;internal_FQDN&amp;gt;:8787/pa-dbl.txt&lt;/SPAN&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I can see polling errors being reported under the Statistics UI page but can't find where they are actually logged - looking again with fresh eyes I see I have set the application attribute to http.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On that subject is there any documentation on these attributes, they mostly seem obvious but I'm not sure on some of them?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Many Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 14 Sep 2016 10:06:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/minemeld-ssl-certificates/m-p/113186#M97234</guid>
      <dc:creator>apackard</dc:creator>
      <dc:date>2016-09-14T10:06:16Z</dc:date>
    </item>
    <item>
      <title>Re: Minemeld SSL Certificates</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/minemeld-ssl-certificates/m-p/113516#M97235</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/6173"&gt;@apackard﻿&lt;/a&gt;&amp;nbsp;Look for the file /opt/minemeld/log/minemeld-engine.log and search inside it for the name of your node. Attributes looks correct, could you paste the full YAML config of the prototype (removing the confidential part of it) ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks !&lt;/P&gt;
&lt;P&gt;luigi&lt;/P&gt;</description>
      <pubDate>Thu, 15 Sep 2016 06:49:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/minemeld-ssl-certificates/m-p/113516#M97235</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2016-09-15T06:49:55Z</dc:date>
    </item>
    <item>
      <title>Re: Minemeld SSL Certificates</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/minemeld-ssl-certificates/m-p/113556#M97236</link>
      <description>&lt;P&gt;Thanks Luigi.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Pertinent error log entry:-&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Exception in polling loop for CIU_Threatintel_Droplist: [Errno bad handshake] [('SSL routines', 'SSL3_GET_SERVER_CERTIFICATE', 'certificate verify failed')]&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;And the YAML:-&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;#####@#####:/opt/minemeld/prototypes/0.9.20$ cat minemeldlocal.yml&lt;BR /&gt;author: minemeld-web&lt;BR /&gt;description: Local prototype library managed via MineMeld WebUI&lt;BR /&gt;prototypes:&lt;BR /&gt; CIU Threatintel Droplist:&lt;BR /&gt; class: minemeld.ft.http.HttpFT&lt;BR /&gt; config:&lt;BR /&gt; attributes:&lt;BR /&gt; application: http&lt;BR /&gt; confidence: 100&lt;BR /&gt; direction: inbound&lt;BR /&gt; share_level: green&lt;BR /&gt; type: IPv4&lt;BR /&gt; source_name: mm.ciuthreatintel&lt;BR /&gt; url: https://##########:8787/pa-dbl.txt&lt;BR /&gt; description: #####\ThreatStream moderated IP blocklist&lt;BR /&gt; development_status: STABLE&lt;BR /&gt; node_type: miner&lt;/P&gt;</description>
      <pubDate>Thu, 15 Sep 2016 10:43:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/minemeld-ssl-certificates/m-p/113556#M97236</guid>
      <dc:creator>apackard</dc:creator>
      <dc:date>2016-09-15T10:43:52Z</dc:date>
    </item>
    <item>
      <title>Re: Minemeld SSL Certificates</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/minemeld-ssl-certificates/m-p/113561#M97237</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/6173"&gt;@apackard﻿&lt;/a&gt;&amp;nbsp;MineMeld can't verify the cert of the server hosting the blocklist.&lt;/P&gt;
&lt;P&gt;You can:&lt;/P&gt;
&lt;P&gt;- copying&amp;nbsp;the CA of the server certificate on the MineMeld instance and then setting REQUESTS_CA_BUNDLE env in /etc/default/minemeld to point to that location (preferred if the server is not using a self-signed cert)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- adding the setting verify_cert: false inside the prototype in the config section to&amp;nbsp;disable certificate verification&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;NOTE: there is a bug in MineMeld 0.9.20 affecting local prototypes, to avoid losing your custom proto please move&amp;nbsp;the minemeldlocal.yml to the right place:&lt;/P&gt;
&lt;PRE&gt;sudo -u minemeld mv /opt/minemeld/prototypes/current/minemeldlocal.yml /opt/minemeld/local/prototypes/&lt;/PRE&gt;</description>
      <pubDate>Thu, 15 Sep 2016 11:20:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/minemeld-ssl-certificates/m-p/113561#M97237</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2016-09-15T11:20:26Z</dc:date>
    </item>
    <item>
      <title>Re: Minemeld SSL Certificates</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/minemeld-ssl-certificates/m-p/113565#M97238</link>
      <description>&lt;P&gt;Perfect, many thanks.&lt;/P&gt;</description>
      <pubDate>Thu, 15 Sep 2016 11:39:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/minemeld-ssl-certificates/m-p/113565#M97238</guid>
      <dc:creator>apackard</dc:creator>
      <dc:date>2016-09-15T11:39:21Z</dc:date>
    </item>
    <item>
      <title>Re: Minemeld SSL Certificates</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/minemeld-ssl-certificates/m-p/245794#M97239</link>
      <description>&lt;P&gt;Hi Luigi,&lt;/P&gt;
&lt;P&gt;When I add cert signed by PAN deivce to /etc/nginx ( minemeld.cer and minemeld.pem) , when I restart nginx ( sudo service nginx restart ) it ask the PAM pass phrase. ALthough I put the correct password or remove the password from pem, it always ask.&lt;/P&gt;
&lt;P&gt;So I can not change minemeld to use certificate signed by our PAN vm.&amp;nbsp; Do I missed anything ?&lt;/P&gt;
&lt;P&gt;Best Regards,&lt;/P&gt;
&lt;P&gt;An&lt;/P&gt;</description>
      <pubDate>Sun, 13 Jan 2019 14:27:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/minemeld-ssl-certificates/m-p/245794#M97239</guid>
      <dc:creator>Nupagazy</dc:creator>
      <dc:date>2019-01-13T14:27:45Z</dc:date>
    </item>
    <item>
      <title>Re: Minemeld SSL Certificates</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/minemeld-ssl-certificates/m-p/245798#M97240</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/94970"&gt;@Nupagazy&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;if the restart ask for password, typically means that your private key is password protected. I know you already removed that, but could you double check?&lt;/P&gt;</description>
      <pubDate>Sun, 13 Jan 2019 18:18:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/minemeld-ssl-certificates/m-p/245798#M97240</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2019-01-13T18:18:05Z</dc:date>
    </item>
    <item>
      <title>Re: Minemeld SSL Certificates</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/minemeld-ssl-certificates/m-p/245908#M97241</link>
      <description>&lt;P&gt;I found following config of minemeld-web:&lt;/P&gt;
&lt;P&gt;ssl_certificate /etc/nginx/minemeld.cer&lt;/P&gt;
&lt;P&gt;ssl_certificate_key /etc/nginx/minemeld.pem&lt;/P&gt;
&lt;P&gt;Which certificates generated by PAN vm should I replace the above two ?&lt;/P&gt;
&lt;P&gt;Best Regards,&lt;/P&gt;
&lt;P&gt;An&lt;/P&gt;</description>
      <pubDate>Mon, 14 Jan 2019 14:18:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/minemeld-ssl-certificates/m-p/245908#M97241</guid>
      <dc:creator>Nupagazy</dc:creator>
      <dc:date>2019-01-14T14:18:49Z</dc:date>
    </item>
    <item>
      <title>Re: Minemeld SSL Certificates</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/minemeld-ssl-certificates/m-p/245930#M97242</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/94970"&gt;@Nupagazy&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;basically you should place in&amp;nbsp;&lt;SPAN&gt;/etc/nginx/minemeld.cer your certificate in PEM format, and in&amp;nbsp;/etc/nginx/minemeld.pem your private in PEM (with no password!)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Luigi&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Jan 2019 16:51:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/minemeld-ssl-certificates/m-p/245930#M97242</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2019-01-14T16:51:22Z</dc:date>
    </item>
    <item>
      <title>Re: Minemeld SSL Certificates</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/minemeld-ssl-certificates/m-p/246058#M97243</link>
      <description>&lt;P&gt;Thank you so much, I can make the PA vm send https log to minemeld now.&lt;/P&gt;
&lt;P&gt;Best Regards,&lt;/P&gt;
&lt;P&gt;An&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jan 2019 10:05:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/minemeld-ssl-certificates/m-p/246058#M97243</guid>
      <dc:creator>Nupagazy</dc:creator>
      <dc:date>2019-01-15T10:05:40Z</dc:date>
    </item>
  </channel>
</rss>

