TLSv1.3 Decryption with P-192 Curve
|
Until PAN-OS 11.2, the firewall successfully decrypted SSL
Forward Proxy sessions where a client and server negotiated a
TLSv1.3 connection using only the P-192 curve.
Starting in PAN-OS 12.1.2, these sessions will
fail,because the firewall will no longer be able to decrypt
this specific use of P-192 with TLSv1.3. This will result in a
session failure for clients that exclusively use this weak
configuration.
Workaround: Set TLSv1.2 as the maximum supported TLS version in the
decryption profile. Apply the profile to the decryption policy rules
that handle traffic from clients to servers that only negotiate the
P-192 curve.
|