Decryption with Elliptical Curve DSA PAN -OS 8.0.x

cancel
Showing results for 
Search instead for 
Did you mean: 

Decryption with Elliptical Curve DSA PAN -OS 8.0.x

L3 Networker

Hi Team, 

 

New features and improvement in version 8 allows for additional cipher algorithms to be decrypted and the re-encrypted to check for malicious content.

Can generate a self-signed or a cert off MS Certificate Authority.

Many customers have the decryption cert with the RSA Algorithm already configured. Need to set up the additional one as below to take advantage of the new feature. So will have two forward trust and two forward untrust. 

 

The ECDSA one is then preferred and the PAN device will fail back to the RSA one if required.

 

RSA.GIF

ED.GIF

 

 

To generate a self signed one, is simple enough, just select the different algorithm as below. 

 

 

generate.GIF

 

Done some tests with same recently and seems to be working ok, if any trouble with same contact your support provider, 

 

Cheers, 

 

Rob 

 

1 ACCEPTED SOLUTION

Accepted Solutions

Cyber Elite
Cyber Elite

FYI: There is no need to generate a new Root Cert with an EC Key. PAN-OS 8 allows you to decrypt connections to websites with ECDSA certs also with an RSA Decryption certificate.

 

--> For example: https://ecdsa.scotthelme.co.uk/

View solution in original post

1 REPLY 1

Cyber Elite
Cyber Elite

FYI: There is no need to generate a new Root Cert with an EC Key. PAN-OS 8 allows you to decrypt connections to websites with ECDSA certs also with an RSA Decryption certificate.

 

--> For example: https://ecdsa.scotthelme.co.uk/

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!