Remediate Cryptography Risk Using Cipher Translation
Focus
Focus
Network Security

Remediate Cryptography Risk Using Cipher Translation

Table of Contents

Remediate Cryptography Risk Using Cipher Translation

Apply Quantum-Safe Cipher Translation to legacy assets through the Quantum-Safe Security app to push decryption profile settings to your NGFWs without modifying internal applications.
Where Can I Use This?What Do I Need?
  • NGFW (Managed by Strata Cloud Manager)
  • Quantum-Safe Security license
  • PAN-OS 12.1 or later on target NGFWs
When your cryptographic inventory identifies assets communicating with deprecated classical encryption, the Quantum-Safe Security app displays a Cipher Translation recommendation. The guided remediation wizard configures your NGFW as a translation proxy between quantum-safe and classical encryption. See Quantum-Safe Cipher Translation for how the two modes work and which PQC algorithms are supported.
The wizard pushes decryption profile settings to NGFWs running PAN-OS 12.1 or later. NGFWs on earlier versions must be upgraded before they can receive the configuration. Verify that you have sufficient RBAC permissions to save and push configurations before starting.
  1. Launch the Quantum-Safe Security app.
    1. Select InsightsQuantum-Safe Security and then select the Inventory tab.
  2. In the Recommendations panel, select the Quantum Safe category.
  3. Locate the recommendation card tagged Private Applications or User Devices with the Cipher Translation tag, then click Remediate.
  4. In Step 1 (Review Decryption Settings), review the settings that will be applied to your decryption profiles, then click Next: Select Decryption Profiles.
    • Max Version: TLS 1.3
    • Key Exchange: PQC Standard
    • Session Settings: Server-side Session Preferred (User Devices) or Client-side Session Preferred (Private Applications)
  5. In Step 2 (Select Decryption Profiles), select the decryption profiles associated with the assets using deprecated cryptography, then click Next: Preview Changes.
  6. In Step 3 (Preview Changes), review the configuration summary.
    • Firewalls running PAN-OS 12.1 or later are listed as targets that will receive the configuration push.
    • Firewalls that don't meet the minimum version requirement are listed separately with an Upgrade Software action required before remediation can proceed.
  7. Click Next: Apply Configuration.
  8. In Step 4 (Apply Configuration), save and push the configuration.
    1. Click Save to save the changes to the configuration.
    2. Click Push to push the configuration to your firewall devices.
      Strata Cloud Manager redirects you to ConfigurationOperationsPush Config to complete the operation. The push takes 5–10 minutes.
    3. Select the appropriate firewall and click Push Config.
    4. On the Push dialog box, enter a description and click Push.
      The operation takes 5-10 minutes. Note that you must be logged in as administrator to complete this task. The Push button is disabled for users with read-only permissions.