Block session with expired certificate is not working with No Decryption in TLS-1.3

Block session with expired certificate is not working with No Decryption in TLS-1.3

5203
Created On 12/20/21 19:57 PM - Last Modified 05/09/23 03:46 AM


Symptom


When TLS version 1.3 Protocol is used, the Firewall will not block the expired certificate session with no decryption enabled.

Environment




Cause


  • Under TLS version 1.3, Everything after ServerHello is encrypted
  • Server certificate encryption was adopted by default,
  • Firewall cannot see the certificates since those are encrypted by TLS 1.3 protocol.
  • So Block session with expired certificate will not work with "No Decryption" setting.

User-added image

 

 



Resolution


 Enable SSL decryption. Refer Decryption
  •  Note: The firewall supports TLSv1.3 decryption from PAN-OS 10.0


Additional Information




Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000oMsjCAE&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail