SSL decryption issue for Windows Store

Reply
Highlighted
L4 Transporter

SSL decryption issue for Windows Store

Hello,

 

After enabling SSL Decryption, we cannot download from Windows store. Getting error below.

Tried excluding hostname with Microsoft but no luck. How to fix this issue?

 

Error-windows-store.jpgexclude-store-list-decrypt.JPG

 

 

Thanks in advance.


Accepted Solutions
Highlighted
Cyber Elite

I am not sure if these are still all required exceptions but it is worth a try:

Screenshot_20180504-175517.jpg

View solution in original post


All Replies
Highlighted
Cyber Elite

I am not sure if these are still all required exceptions but it is worth a try:

Screenshot_20180504-175517.jpg

View solution in original post

Highlighted
L1 Bithead

fe3cr.delivery.mp.microsoft.com  is another.

Highlighted
Cyber Elite

what is the reason we need to allow all the hosts?

if we allow *.microsoft.com why does it not work then?

Curious to know the reason behind this?

MP
Highlighted
L1 Bithead

We (PA support) tested *.microsoft.com in url category and a policy.  That did not work.

We then added *.microsoft.com to the ssl decryption exception list.  Still no joy.

We then added the specific fe3cr.delivery.mp.microsoft.com url.  And Success.

Highlighted
Cyber Elite

@MP18 this is actually a goos question. From my side I can only say, that I did not test with *.microsoft.com as the requirement was to configure exceptions as accurate as possible.

 

Unfortunetely with these exact URLs there is the downside that - as we found out - they change with (not all) new microsoft versions of windows 10.

Highlighted
Cyber Elite

I have seen this behaviour with other websites where fix for us was to exempt  the source IP for decryption.

Seems *.url does not work in ssl exclusion  list.

 

This was not with single urls many urls and end devices were servers in data centre.

MP
Highlighted
L0 Member

Hello there,

Would you mind to tell me the fix for the same if there is any changed recently to the same url. As I am being reported continuously for the store problem as you mentioned.

I will be waiting for your reply.

thanks

Highlighted
Cyber Elite

Hi @TahirA 

 

We created the Decryption policy based on Source IP as exclusion list was not working on our PAN OS 8.1.9.

I do not know if PA has fixed this in newer PAN OS version.

 

Regards

MP
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!