Inbound Decryption Advice to overcome Decrypt error

Showing results for 
Show  only  | Search instead for 
Did you mean: 

Inbound Decryption Advice to overcome Decrypt error

L1 Bithead

I am asking for help to get SSL Inbound decryption working. I have read all the posts and tried everything I can think of but I keep getting the decrypt error status so I may have a basic misunderstanding. If someone has an insight into what I am doing wrong after reading the information below I would be grateful to receive it.

The web server is restricted by group policy to a few encryption algorithms that the Palo Alto firewall supports being:



• TLS_RSA_WITH_AES_128_GCM_SHA256 (0x009c)

• TLS_RSA_WITH_AES_256_GCM_SHA384 (0x009d)


I have tried a certificate issued by “GoDaddy” and also a certificate issued by my internal CA but I get the same result from each. The clients trust both certificate authorities. When the client connects, one packet appears to be decrypted but the rest produce a Decrypt error. A capture shows no errors.

The “Client Hello” appears normal listing its supported encryption algorithms followed by a “Server hello, Change Cipher Spec” which looks like it sets the Encryption algorithm to “TLS_RSA_with_AES_128_CBC_SHA256”. This is followed by a “Change Cipher Spec, Encrypted Handshake Message” which I am unsure what this does. These all appear below.

Client Hello

 Client helloClient helloServer HelloServer HelloChange CipherChange Cipher



L1 Bithead

I kept researching and found a post by Anil Kumar that indicated the issue may be the TLS Extension "Extended Master Secret". If I disable this on the server ad the client, decryption works. Disabling this only on the server seems to be insufficient for decryption to work. The problem now is what to do. Do I downgrade from TLS to SSL or do I forgo decryption. I would be interested in your comment on these options.


Does anyone know if/when Palo Alto will support this Extension for decryption?

To complete the story: Soon after my post in August I was informed that a flaw in implementing Extended Master Secret would be fixed soon. An update issued soon thereafter fixed the issue.

  • 2 replies
  • 101 Subscriptions
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!