Why is decrypt failing for this site

Reply
Highlighted
L4 Transporter

Why is decrypt failing for this site

Hi

 

myeverythingdisc.com

 

my PA's use the unsecure CA..

tring to work out why.

 

Last I checked there was no log so ...

Tags (1)
L7 Applicator

Re: Why is decrypt failing for this site

From what I can see (without troubleshooting this deeply on a PA), it could be because of something called "Extended Master Secret". As the webserver behind your mentionned website is a windows server this might be the reason as I have seen this reason for failed decryptions only on windows servers so far. Other things that might be a reason I cannot see in the webservers TLS configuration.

But to be sure you probably need to dig deeper (or open a support case and let PaloAlto do this work ;)

L4 Transporter

Re: Why is decrypt failing for this site

I have been down this route before - capturing packets etc ... they haven't been helpful.

 

The point I was trying to make was there is not enough logging around this.

 

Thanks

L7 Applicator

Re: Why is decrypt failing for this site

In the traffic logs or default packet captures, yes there is not enough information. But on the CLI you will be able to see what you want to.

 

debug dataplane packet-diag set log feature proxy all
debug dataplane packet-diag set log feature ssl all

 

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!