08-14-2018 08:03 AM
since tls 1.3 is now a ietf standard, is there any use running ssl-decryption in the close future?
as far i understand 1.3 documents, it "looks like" 1.2 for the firewall, so there's no way to just block 1.3 and force both parties to downgrade to 1.2, or i'm wrong?
any news/tech docs from pan about the 1.3 "issue"?
08-14-2018 08:15 AM - edited 08-14-2018 08:27 AM
This will be interesting ...
I am waiting already quite a while for an answer ...
Not sure where I read that, but the only chance seems to be an explicit proxy or the complete visibiluty for encrypted traffic is gone.
TLS1.3 in combination with DoH and also the DNS sinkhole feature is gone...
08-14-2018 01:21 PM
You'll need to block TLS 1.3 on the client itself to force it to attempt to failback; but you're 100% right, the standard really isn't able to be decrypted as far as I'm aware.
The standard will be interesting, as it essentially makes any sort of decrytion from the firewall as we know it impracticle. I wouldn't be suprised to see a move back to full fleged proxy servers or agent based firewalls directly on a end-users computer. I think at this point though we're still waiting on a good solution.
08-14-2018 03:17 PM
I haven't read up on this but I'm assuming Inbound Decryption could eventually work if they implemented TLS 1.3 on PAN-OS?
Since you generally own the cert and servers with Inbound then you could always make them use TLS 1.2 but if your server team wanted to implement 1.3 wouldn't the firewall still be able to decrypt with the cert installed?
08-14-2018 03:29 PM
Yes, inbound decryption will work - as soon as PAN-OS supports TLS1.3.
Until then - as the firewall does not know about TLS 1.3 - it only offers TLS1.2 to the clients as highest version. If the server in this case obly support TLS1.3, the inbound decryption will fail.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!