Enhanced Security Measures in Place:   To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.

[RFC5746] issue with ssl decryption: openssl3.0 unsafe legacy renegotiation disabled

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

[RFC5746] issue with ssl decryption: openssl3.0 unsafe legacy renegotiation disabled

L0 Member

Since I upgraded to the lastest fedora, all of my python/ansible script failed when they are decrypted by our palo alto ssl outbound policy.

 

After some diging, fedora 35 was using openssl 1.1.1 and fedora 36 switched to openssl 3.0: https://fedoraproject.org/wiki/Changes/OpenSSL3.0

 

On the openssl 3.0 changelog, we can find this:

OPENSSL changelog between 1.1.1 and 3.0.0 [7 sep 2021] contains:

* Support for RFC 5746 secure renegotiation is now required by default for SSL or TLS connections to succeed.

 

I found a post on a stackoverflow that explain how to reenable unsecure renegociation to have a quick fix. This won't be a good solution when all our devs will be using linux and dockers with openssl 3.0 installed.

 

Is there a way to configure ssl decryption on the palo alto to enable secure renegociation ?

 

2 REPLIES 2

L0 Member

This will be supported natively in the following versions:

 

11.0.2 - ETA July 2023
10.2.5 - ETA  August 2023
10.1.11 - ETA - September 2023
9.1.17 - ETA October 2023

L0 Member

Looks like it's there now:

10.2.5 and 10.1.10

https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-release-notes/pan-os-10-2-5-known-and-addressed...

PAN-184630
Fixed an issue where TLS clients, such as those using OpenSSL 3.0, enforced the TLS renegotiation extension (RFC 5746).
  • 10742 Views
  • 2 replies
  • 2 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!