|
TLS 1.3 Decryption Limited to RFC-Compliant Key Exchange
Groups
|
Starting in PAN-OS 12.1, the firewall enforces RFC 8446 for SSL
Forward Proxy decryption. Only the following key exchange groups are
supported for TLS 1.3 decryption: X25519, X448, secp256r1,
secp384r1, secp521r1.
Sessions that exclusively negotiate any other elliptic-curve group —
including P-192 (secp192k1), secp160k1, secp256k1, sect163k1, and
related Koblitz and binary curves — don't complete through SSL
Forward Proxy. This affects firewalls upgraded from PAN-OS 11.2 or
earlier.
Workaround: Set TLSv1.2 as the maximum supported TLS version
in the decryption profile and apply it to the decryption policy
rules that handle traffic to servers that exclusively negotiate
non-compliant groups. Alternatively, work with the server operator
to enable RFC 8446-compliant groups.
|