<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Nodes polling error in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/nodes-polling-error/m-p/182829#M99442</link>
    <description>&lt;P&gt;Good point but my Office365 https requests work behind same DNS proxy. I believe customer is using OpenDNS so that makes sense. I'll take a look at the other prototype to see if I get the same error. I appreciate the response.&lt;/P&gt;</description>
    <pubDate>Thu, 19 Oct 2017 19:39:19 GMT</pubDate>
    <dc:creator>clockhart</dc:creator>
    <dc:date>2017-10-19T19:39:19Z</dc:date>
    <item>
      <title>Nodes polling error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nodes-polling-error/m-p/153152#M99436</link>
      <description>&lt;P&gt;Hello somewho have an idea?&lt;/P&gt;
&lt;P&gt;Installed Minemeld on an fresh Ubuntu 14.0.4 like the manual installation guide.&lt;/P&gt;
&lt;P&gt;Import the Office365 configuration&amp;nbsp;&lt;/P&gt;
&lt;P&gt;All Nodes got an SSL Error message see below&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2017-04-19T12:45:54 (22890)basepoller.hup INFO: office365_O365 - hup received, force polling&lt;BR /&gt;2017-04-19T12:45:54 (22890)basepoller._huppable_wait INFO: hup is clear: False&lt;BR /&gt;2017-04-19T12:45:54 (22890)basepoller._actor_loop INFO: office365_O365 - command: 1492598754316 poll&lt;BR /&gt;2017-04-19T12:45:54 (22890)basepoller._polling_loop INFO: Polling office365_O365&lt;BR /&gt;2017-04-19T12:45:54 (22890)connectionpool._new_conn INFO: Starting new HTTPS connection (1): support.content.office.net&lt;BR /&gt;2017-04-19T12:45:54 (22890)basepoller._poll ERROR: Exception in polling loop for office365_O365: [Errno bad handshake] [('SSL routines', 'SSL3_GET_SERVER_CERTIFICATE', 'certificate verify failed')]&lt;BR /&gt;Traceback (most recent call last):&lt;BR /&gt; File "/opt/minemeld/engine/0.9.36.post2/local/lib/python2.7/site-packages/minemeld/ft/basepoller.py", line 701, in _poll&lt;BR /&gt; performed = self._polling_loop()&lt;BR /&gt; File "/opt/minemeld/engine/0.9.36.post2/local/lib/python2.7/site-packages/minemeld/ft/basepoller.py", line 568, in _polling_loop&lt;BR /&gt; iterator = self._build_iterator(now)&lt;BR /&gt; File "/opt/minemeld/engine/0.9.36.post2/local/lib/python2.7/site-packages/minemeld/ft/o365.py", line 165, in _build_iterator&lt;BR /&gt; oiterator = self._o365_iterator(now)&lt;BR /&gt; File "/opt/minemeld/engine/0.9.36.post2/local/lib/python2.7/site-packages/minemeld/ft/o365.py", line 115, in _o365_iterator&lt;BR /&gt; r = _session.send(prepreq, **rkwargs)&lt;BR /&gt; File "/opt/minemeld/engine/0.9.36.post2/local/lib/python2.7/site-packages/requests/sessions.py", line 573, in send&lt;BR /&gt; r = adapter.send(request, **kwargs)&lt;BR /&gt; File "/opt/minemeld/engine/0.9.36.post2/local/lib/python2.7/site-packages/requests/adapters.py", line 431, in send&lt;BR /&gt; raise SSLError(e, request=request)&lt;BR /&gt;SSLError: [Errno bad handshake] [('SSL routines', 'SSL3_GET_SERVER_CERTIFICATE', 'certificate verify failed')]&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any guidance that can be provided would be greatly appreciated!&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks Holger&lt;/P&gt;</description>
      <pubDate>Wed, 19 Apr 2017 10:49:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nodes-polling-error/m-p/153152#M99436</guid>
      <dc:creator>HolgerKiene</dc:creator>
      <dc:date>2017-04-19T10:49:03Z</dc:date>
    </item>
    <item>
      <title>Re: Nodes polling error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nodes-polling-error/m-p/153153#M99437</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/39317"&gt;@HolgerKiene&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;certificate verification is failing. Are you behind a proxy or a device doing SSL decryption ?&lt;/P&gt;
&lt;P&gt;Could you open a shell on the MineMeld instance, issue the following and report back any error you see ?&lt;/P&gt;
&lt;PRE&gt;$ cd /tmp/ &amp;amp;&amp;amp; wget https://support.content.office.net/en-us/static/O365IPAddresses.xml&lt;/PRE&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;luigi&lt;/P&gt;</description>
      <pubDate>Wed, 19 Apr 2017 11:08:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nodes-polling-error/m-p/153153#M99437</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2017-04-19T11:08:09Z</dc:date>
    </item>
    <item>
      <title>Re: Nodes polling error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nodes-polling-error/m-p/153167#M99438</link>
      <description>&lt;P&gt;Thanks for for your fast answer,&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="short_text"&gt;&lt;SPAN class=""&gt;You're right my mistake&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="short_text"&gt;&lt;SPAN class=""&gt;Holger&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Apr 2017 12:24:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nodes-polling-error/m-p/153167#M99438</guid>
      <dc:creator>HolgerKiene</dc:creator>
      <dc:date>2017-04-19T12:24:03Z</dc:date>
    </item>
    <item>
      <title>Re: Nodes polling error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nodes-polling-error/m-p/153772#M99439</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/39317"&gt;@HolgerKiene&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;thanks for taking the time to tell us everything is working&amp;nbsp;!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;luigi&lt;/P&gt;</description>
      <pubDate>Mon, 24 Apr 2017 06:40:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nodes-polling-error/m-p/153772#M99439</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2017-04-24T06:40:56Z</dc:date>
    </item>
    <item>
      <title>Re: Nodes polling error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nodes-polling-error/m-p/182815#M99440</link>
      <description>&lt;P&gt;Another node get error:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;dcadmin@MICMM01:/tmp$ wget &lt;A href="https://check.torproject.org/exit-addresses" target="_blank"&gt;https://check.torproject.org/exit-addresses&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;--2017-10-19 12:54:22--&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;A href="https://check.torproject.org/exit-addresses" target="_blank"&gt;https://check.torproject.org/exit-addresses&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Resolving check.torproject.org (check.torproject.org)... 146.112.61.106, ::ffff:146.112.61.106&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Connecting to check.torproject.org (check.torproject.org)|146.112.61.106|:443... connected.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;ERROR: cannot verify check.torproject.org's certificate, issued by ‘/CN=Cisco Umbrella Secondary SubCA dfw-SG/O=Cisco’:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;Unable to locally verify the issuer's authority.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;To connect to check.torproject.org insecurely, use `--no-check-certificate'.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;dcadmin@MICMM01:/tmp$&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Can I change the prototype to request http rather than https?&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Tor Exit Node:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;&lt;SPAN&gt;&lt;A href="https://check.torproject.org/exit-addresses" target="_blank"&gt;https://check.torproject.org/exit-addresses&lt;/A&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Oct 2017 19:02:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nodes-polling-error/m-p/182815#M99440</guid>
      <dc:creator>clockhart</dc:creator>
      <dc:date>2017-10-19T19:02:43Z</dc:date>
    </item>
    <item>
      <title>Re: Nodes polling error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nodes-polling-error/m-p/182821#M99441</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/30918"&gt;@clockhart&lt;/a&gt;&amp;nbsp;: are you aware of the&amp;nbsp;&lt;FONT face="courier new,courier"&gt;hailataxii.guest_blutmagie_de_torExits&lt;/FONT&gt;&amp;nbsp;prototype in the standard library that also "mines" the tor exit nodes? Any reason not to use it?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've just realized you're receiving a certificate error from Cisco Umbrella. That means that your MineMeld instance is using a secure proxy to reach the feed (SSL man-in-the-middle). In such a case you need to import the related certificates in the MineMeld's trust ring.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Oct 2017 19:36:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nodes-polling-error/m-p/182821#M99441</guid>
      <dc:creator>xhoms</dc:creator>
      <dc:date>2017-10-19T19:36:47Z</dc:date>
    </item>
    <item>
      <title>Re: Nodes polling error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nodes-polling-error/m-p/182829#M99442</link>
      <description>&lt;P&gt;Good point but my Office365 https requests work behind same DNS proxy. I believe customer is using OpenDNS so that makes sense. I'll take a look at the other prototype to see if I get the same error. I appreciate the response.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Oct 2017 19:39:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nodes-polling-error/m-p/182829#M99442</guid>
      <dc:creator>clockhart</dc:creator>
      <dc:date>2017-10-19T19:39:19Z</dc:date>
    </item>
    <item>
      <title>Re: Nodes polling error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nodes-polling-error/m-p/182857#M99443</link>
      <description>&lt;P&gt;Set up my miner, aggregator and output nodes but no luck. hailataxi Miner&amp;nbsp;reports&amp;nbsp;273 indicators, which is considerably lower than the tor-exit.nodes (913). Is there a reason for the discrepancy?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also am I using the wrong aggregator? My list is empty.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Oct 2017 20:47:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nodes-polling-error/m-p/182857#M99443</guid>
      <dc:creator>clockhart</dc:creator>
      <dc:date>2017-10-19T20:47:10Z</dc:date>
    </item>
    <item>
      <title>Re: Nodes polling error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nodes-polling-error/m-p/183177#M99444</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/30918"&gt;@clockhart&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;to track tor nodes please use blutmagie.* prototypes, I have found them more reliable over time.&lt;/P&gt;
&lt;P&gt;One reason you could considerably less nodes from hailataxii is caused by how TAXII DataFeed work. TAXII DataFeeds are designed to publish updates, not full current lists of indicators. This means that the 273 nodes you see are most probably the 273 tor nodes most recently added to the list of active tor nodes, not the full list. Blutmagie.* and tor.* prototypes instead provide the full current list of Tor nodes.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;luigi&lt;/P&gt;</description>
      <pubDate>Mon, 23 Oct 2017 07:07:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nodes-polling-error/m-p/183177#M99444</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2017-10-23T07:07:17Z</dc:date>
    </item>
    <item>
      <title>Re: Nodes polling error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nodes-polling-error/m-p/185381#M99445</link>
      <description>&lt;P&gt;Luigi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for the response. I'm using blutmagie now for my miner and it's looking good. Appreciate the assistance.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;cpl&lt;/P&gt;</description>
      <pubDate>Fri, 03 Nov 2017 15:50:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nodes-polling-error/m-p/185381#M99445</guid>
      <dc:creator>clockhart</dc:creator>
      <dc:date>2017-11-03T15:50:00Z</dc:date>
    </item>
    <item>
      <title>Re: Nodes polling error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nodes-polling-error/m-p/190118#M99446</link>
      <description>&lt;P&gt;Hello, I'm just getting started with MineMeld. We have an internal block IP and URL feeds that&amp;nbsp;are hosted on a web server, a text file hosted via HTTPS page. My issue is that this server does not have a valid certificate, but It's my internal server, so I don't care. Is there a way to ignore certificate errors when pulling HTTPS feeds?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Dec 2017 16:30:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nodes-polling-error/m-p/190118#M99446</guid>
      <dc:creator>jniedenthal</dc:creator>
      <dc:date>2017-12-05T16:30:20Z</dc:date>
    </item>
    <item>
      <title>Re: Nodes polling error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nodes-polling-error/m-p/190121#M99447</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/62243"&gt;@jniedenthal&lt;/a&gt; : That behavior of the HttpFT class is controlled by the &lt;FONT face="andale mono,times"&gt;&lt;SPAN class="pl-s"&gt;verify_cert&lt;/SPAN&gt;&lt;/FONT&gt; boolean configuration attibute (defaults to true). Add the attribute to your prototype with the value set to "False"&lt;/P&gt;</description>
      <pubDate>Tue, 05 Dec 2017 16:35:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nodes-polling-error/m-p/190121#M99447</guid>
      <dc:creator>xhoms</dc:creator>
      <dc:date>2017-12-05T16:35:32Z</dc:date>
    </item>
  </channel>
</rss>

