- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
05-27-2021 11:46 PM
Hi,
We are receiving decrypt error in our ssl inspection traffic
++++As Per the below logs Server is using an unsupported EC curve x25519. Correct the server configuration to use a curve that the firewall supports.++++
2021-03-17 06:59:01.789 +0100 Error: pan_tls_ec_curve_id_2nid(pan_ec_common.c:66): unsupported ec curve_id 29<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<
2021-03-17 06:59:01.789 +0100 Error: pan_ecdh_parse_server_key_exchange_msg(pan_ecdh.c:436): unsupported curve_na
me 29.<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<
2021-03-17 06:59:01.789 +0100 Error: pan_ssl_keyxchg_parse_server_key_exchange_msg(pan_ssl_keyxchg.c:166): parse_
server_key_exchange_msg(ecdhe) failed<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<
PAN-OS 8.1 Decryption Cipher Suites
>>https://docs.paloaltonetworks.com/compatibility-matrix/supported-cipher-suites/cipher-suites-support...
-------
I still don't understand why the PA generates a "decryption error" instead of letting the connection go through. During testing there were some cases where the client supported TLS 1.3. As the servers also support it and the AP does not, the connection just worked. In this case, the "conflicting" information does not arrive in the "Server hello" message but just after the "key exchange" message, but since the Server hello message is not transmitted to the client, you should undo the session proxy and forward the original message from the server to the client. Anyway, I guess it can't be done for some reason.
any wway to solve it?
05-31-2021 12:41 PM - edited 05-31-2021 12:42 PM
If your firewall is 8.1 as you have given an article for it then you will not be able to decrypt TLS1.3. Read this:
Also in version 10 there is a new log for SSL decryption issues:
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!