Support for Renegotiations for Global Protect Apps

Support for Renegotiations for Global Protect Apps

14358
Created On 01/25/23 13:49 PM - Last Modified 06/02/23 23:56 PM


Symptom


  • Failure to connect Global Protect with clients which use Renegotiations (secure or insecure) as per RFC5746
  • You may see a connection failure as follows :
Connected to [....]:443
SSL negotiation with portal.test.com
SSL connection failure
9069B3F2667F0000:error:0A000152:SSL routines:final_renegotiate:unsafe legacy renegotiation disabled:ssl/statem/extensions.c:879:
Failed to open HTTPS connection to portal.test.com
Failed to complete authentication
--------------------------------------------------------------------------------


Environment


Any Global Protect Setup 

Cause




Resolution


  • Non supportablity of Renegotiations (secure or insecure) is currently an expected behaviour as per TLS Cipher Suites Supported by GlobalProtect Apps


Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000kGWLCA2&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language