SSL Decryption breaks certain website functionality

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

SSL Decryption breaks certain website functionality

L3 Networker
So I’ve enabled SSL decryption and as expected some sites or applications fail when it’s turned on. No problem I can exclude the domain from decryption.

I have a special case though, in the fact that one of these web applications is a service that my company is developing. When decryption is on it breaks screensharimg from our web application. The developers have asked me to look into this from the FW side of things to assist in them fixing it, as they would like it to work with decryption enabled.

What common reasons are there for ssl decryption to break websites? What can I pull off the firewall to assist them?
3 REPLIES 3

Cyber Elite
Cyber Elite

Hello,

Are they using certificate pinning? I know that is one reason decryption breaks an app. Here are some resources to look through:

 

https://live.paloaltonetworks.com/t5/Management-Articles/SSL-decryption-resource-list/ta-p/70397

 

There are some apps that just dont like it and cant be decrypted, Skype is just one example.

 

Hope that helps.

L6 Presenter

You're talking about inbpund SSL decryption, right? It can't be the issue with certificate pinning as certificate is the same (just moved from server to PA). Basically in SSL decryption scenario PA shoul be just listening to decrypted traffic and understand it because it has the apropriate certificate with private key. But in fact it does alter a session a bit as a colleague told me from debugging session with PA support. However for any details and logs about it you will probably have to ask support.

 

Another could be some external components having issues with decrytpion (if your application is using such).

 

L7 Applicator

@welly_59

Other than @santonic I think you're talking about outbound decryption, right?

 

Is it a java application? In case of that when the developpers do their job and check the certificate chain in a TLS connection, then this might be the reason because java has it's own certificate trust store. 

  • 3123 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!