decrypt-cert-validation while performing windows update

Reply
Highlighted
L1 Bithead

decrypt-cert-validation while performing windows update

Hey Guys ... I am doing a normal Windows Update and i am getting error.

While analysing the application type is ms-update and reason for session end is decrypt-cert-validation.

 

Appreciate if you guys can support.

Highlighted
L3 Networker

Re: decrypt-cert-validation while performing windows update

Highlighted
Cyber Elite

Re: decrypt-cert-validation while performing windows update

Hello,

Dont decrypt Microsoft updates. We have a no decrypt policy just for it.

 

Regards,

Highlighted
L4 Transporter

Re: decrypt-cert-validation while performing windows update

@OtakarKlier 

 

What does that no decrypt policy look like?   You can't do no decrypt by application right? Thinking you have a destination list, or list of URL's you are triggering the no decrypt on?

Highlighted
Cyber Elite

Re: decrypt-cert-validation while performing windows update

Hello,

Sorry for not clarifying earlier. A no decrypt policy is just a decryption policy with the action set to 'no-decrypt'. We use this for URL's and URL categories.

image.png

image.png

 

Regards,

Highlighted
L4 Transporter

Re: decrypt-cert-validation while performing windows update

Did you add those directly to your No decrypt policy, or where is that list getting populated from?  - Just asking in reference to where the actual second screenshot resides on your firewall.  Thank you for the quick reply!

Highlighted
Cyber Elite

Re: decrypt-cert-validation while performing windows update

Hello, 

Its a list we came up with when googling. Here is one just for wsus:

https://docs.microsoft.com/en-us/windows-server/administration/windows-server-update-services/deploy...

 

https://kc.mcafee.com/corporate/index?page=content&id=KB88947&actp=null&viewlocale=en_US&showDraft=f...

 

 

 

The main issue we face at times is taht the update will fail since the firewall is blocking something. This is mainly due to the backend IP's and DNS changing at a faster rate than the PAN does. Not a knock against PAN, its just the backend MS Updates change and are not all documented.

 

Regards,

 

Highlighted
L1 Bithead

Re: decrypt-cert-validation while performing windows update

Greetings ... 

Thanks a lot for your inputs and suggestions.

I followed your screenshot and added all URL's but i am still not able to update windows.

I am also sharing my Decryption Profile screenshot.

Decryp.jpg

Highlighted
L1 Bithead

Re: decrypt-cert-validation while performing windows update

@khanshahidnazir   We are also experiencing this.  We have found that MS Store will intermittently update and download, but the full blown WIN10 updates don't work.  

We are using a custom URL Category pushed from the panorama to populate a decryption bypass list of addresses that will not get decrypted.  We are seeing this manifest in the logs with a session end reason of: decrypt-cert-validation.  Is that what you were seeing? 

Highlighted
L1 Bithead

Re: decrypt-cert-validation while performing windows update

Greetings ...

 

Yes we are also seeing this.

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!