TLS 1.3 support

Reply
L1 Bithead

TLS 1.3 support

Hi everybody,

any news regarding change of decryption from passive to proxy mode to support TLS 1.3 decryption?

Thank you,

Jan

L3 Networker

Re: TLS 1.3 support

Hi @Jan_Linhart ,

 

Is below document addresses your query?

https://live.paloaltonetworks.com/t5/Customer-Advisories/Action-required-if-you-have-enabled-SSL-dec...

 

Added to above, As of my knowledge, PA will be doing proxy by default for all connections matching with forward proxy rule,

But inbound inspection is different, it was passive eveasdropping till PanOS 8.0, so if key exchange is DH/ECDH, the decryption fails before 8.0. But after 8.0 they changed the behaviour, so that PA will be active in MITM. if key exchange is RSA, PA wont be proxying the connection, but if key exchange is DH/ECDH, PA will involk the proxy module. 

L1 Bithead

Re: TLS 1.3 support

Hi Abdul,

unfortunately, there is no answer for my question. PAN-OS has support for TLS1.3 now, but not support for decryption.

Please look at this link:

https://blog.gigamon.com/2018/05/10/tls-1-3-is-moving-forward-what-you-need-to-know-today-to-get-rea...

 

Most important part is:

With TLS 1.3, this passive mode decryption (the one PANW is using - transparent for clients) will no longer be possible since the RSA key exchange has been removed. 

 

Jan

L3 Networker

Re: TLS 1.3 support

Hi @Jan_Linhart ,

 

PA is doing proxy for DH/ECDH key exchange now also. so if you have a PanOS version supports TLS 1.3, things should work i feel. 

 

Do you have a trustable source which says 'Pan OS wont support decryption for TLS 1.3' ?.

L4 Transporter

Re: TLS 1.3 support

23.10.2018:

 

Dear valued Palo Alto Networks customer,

 

Please take the action recommended below if you have enabled SSL decryption forward proxy. This is required for users to access Gmail and other websites and applications using web browsers that implement strict TLS 1.3 compliance. We have been informed that Google Chrome is planning to implement strict TLS 1.3 compliance in their upcoming version 72. The stable build of Google Chrome version 72 may be available in January 2019, and if your users use a pre-stable build of Google Chrome, they will experience the issue outlined below earlier.

 

Applies to

All supported PAN-OS releases

 

Action Required

If you run PAN-OS 8.1:

  • Upgrade to PAN-OS 8.1.4 (available now)
L6 Presenter

Re: TLS 1.3 support

@Abdul_Razaq @Chacko42  I think what @Jan_Linhart  is asking is not so much about the ability for PAN-OS to just merely support the protocol, but rather the ability to actually DECRYPT the TLS1.3 session.

 

I think that it something that is being targeted for PAN-OS 9.1, but who knows if it'll actually make it in the release...

 

BTW this is another reason I bet Palo came out with the X2XX hardware.  I doubt the legacy HW would have been able to handle TLS1.3 decryption.

L6 Presenter

Re: TLS 1.3 support


@Abdul_Razaq wrote:

Hi @Jan_Linhart ,

 

 

Do you have a trustable source which says 'Pan OS wont support decryption for TLS 1.3' ?.


 

 

Yeah PAN-OS software itself.

 

Decrypt.png

Highlighted
L7 Applicator

Re: TLS 1.3 support

So it's important to note here the difference between supporting the protocol and actively being able to decrypt TLS 1.3.

  • Palo Alto has now added support for TLS1.3 and has made the required changes so that the firewall will no-longer attempt to decrypt TLS 1.3 traffic, which was causing issues for customers with decryption enabled running PAN-OS versions prior to 8.0.14 in the 8.0 code branch or 8.1.4 in the 8.1 code branch.
  •  Palo Alto can't actually decrypt TLS1.3 traffic just yet and as @Brandon_Wertz mentioned it's something being targeted for a future update. Whether or not it actually makes it into 9.1 or not we'll have to wait and see. 
L1 Bithead

Re: TLS 1.3 support

Hi guys, 

as you wrote before - I'm aware of protocol support, but I was asking about plans for decryption support. It is not going to be easy at all and PANW will have to completely change decryption concept from "passive" to real proxy.

 

Jan

L4 Transporter

Re: TLS 1.3 support

ok, so did this one ever get answered?

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!