<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: WSA S190 SSL Configuration  - can't open some web-resourses in Web Security</title>
    <link>https://community.cisco.com/t5/web-security/wsa-s190-ssl-configuration-can-t-open-some-web-resourses/m-p/4112452#M9105</link>
    <description>&lt;P&gt;On all sites I see the same java-scrypt&lt;/P&gt;</description>
    <pubDate>Thu, 02 Jul 2020 13:55:20 GMT</pubDate>
    <dc:creator>Anton84</dc:creator>
    <dc:date>2020-07-02T13:55:20Z</dc:date>
    <item>
      <title>WSA S190 SSL Configuration  - can't open some web-resourses</title>
      <link>https://community.cisco.com/t5/web-security/wsa-s190-ssl-configuration-can-t-open-some-web-resourses/m-p/4107325#M9084</link>
      <description>&lt;P&gt;Hello all, we are using proxy S190, some sites can't open (example 220-volt.ru, onlinetrade.ru etc.)I think,&amp;nbsp; SSL Configuration is not correctly. Can anybody help me with that problem?&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jun 2020 13:20:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-s190-ssl-configuration-can-t-open-some-web-resourses/m-p/4107325#M9084</guid>
      <dc:creator>Anton84</dc:creator>
      <dc:date>2020-06-22T13:20:57Z</dc:date>
    </item>
    <item>
      <title>Re: WSA S190 SSL Configuration  - can't open some web-resourses</title>
      <link>https://community.cisco.com/t5/web-security/wsa-s190-ssl-configuration-can-t-open-some-web-resourses/m-p/4107413#M9085</link>
      <description>&lt;P&gt;Hi Anton,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'd start troubleshooting that by checking:&lt;/P&gt;
&lt;P&gt;1. Access Logs for transactions towards the failing servers.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2. Proxy error logs/HTTPS logs for any error messages related to the destination. Enable debug log level temporary to see more details for the transactions.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If nothing has been found, I'd collect packet captures on WSA (both legs - client to WSA and WSA to the server at the same time). I'd be looking at TLS handshakes in captures:&lt;/P&gt;
&lt;P&gt;1. if any alerts/errors reported&lt;/P&gt;
&lt;P&gt;2. what are protocol versions and cipher suits and if they match from both sides&lt;/P&gt;
&lt;P&gt;3. any certificate related issues&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also to better understand the problem I'd like to know:&lt;/P&gt;
&lt;P&gt;1. WSA version&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2. Is HTTPS proxy enabled? Is HTTPS decryption enabled for those specific destinations?&lt;/P&gt;
&lt;P&gt;3. How does the issue look from the user perspective? Any error messages displayed in the browser?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jun 2020 14:42:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-s190-ssl-configuration-can-t-open-some-web-resourses/m-p/4107413#M9085</guid>
      <dc:creator>opryluts</dc:creator>
      <dc:date>2020-06-22T14:42:50Z</dc:date>
    </item>
    <item>
      <title>Re: WSA S190 SSL Configuration  - can't open some web-resourses</title>
      <link>https://community.cisco.com/t5/web-security/wsa-s190-ssl-configuration-can-t-open-some-web-resourses/m-p/4107766#M9086</link>
      <description>&lt;P&gt;I see in https -log that, when trying to open onlinetrade.ru:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tue Jun 23 10:06:20 2020 Debug: HTTPS : - : Subject Key Identifier: 56:B5:6A:93:3B:B9:0D:10:21:07:43:8E:FA:00:41:EE:EC:75:CD:C3 for Cert: /OU=Domain Control Validated/OU=PositiveSSL Wildcard/CN=*.onlinetrade.ru&lt;BR /&gt;Tue Jun 23 10:06:20 2020 Debug: HTTPS : - : Subject Key Identifier: 53:79:BF:5A:AA:2B:4A:CF:54:80:E1:D8:9B:C0:9D:F2:B2:03:66:CB for Cert: /C=US/ST=New Jersey/L=Jersey City/O=The USERTRUST Network/CN=USERTrust RSA Certification Authority&lt;BR /&gt;Tue Jun 23 10:06:20 2020 Debug: HTTPS : - : Subject Key Identifier: 8D:8C:5E:C4:54:AD:8A:E1:77:E9:9B:F9:9B:05:E1:B8:01:8D:61:E1 for Cert: /C=GB/ST=Greater Manchester/L=Salford/O=Sectigo Limited/CN=Sectigo RSA Domain Validation Secure Server CA&lt;BR /&gt;Tue Jun 23 10:06:20 2020 Debug: HTTPS : - : Subject Key Identifier: AD:BD:98:7A:34:B4:26:F7:FA:C4:26:54:EF:03:BD:E0:24:CB:54:1A for Cert: /C=SE/O=AddTrust AB/OU=AddTrust External TTP Network/CN=AddTrust External CA Root&lt;BR /&gt;Tue Jun 23 10:06:20 2020 Debug: HTTPS : - : Error Bitmap is - 00000000 00000000 0&lt;BR /&gt;Tue Jun 23 10:06:20 2020 Debug: HTTPS : - : Generating long serial-number for expired certificate.&lt;BR /&gt;Tue Jun 23 10:06:20 2020 Debug: HTTPS : - : Certificate sha256 fingerprint is - 0x96E31336990C7E64FF723774A78FF5BC2722977836583CC4A4A84BDC67990650&lt;BR /&gt;Tue Jun 23 10:06:20 2020 Debug: HTTPS : - : New serial computed is 0x96E31336990C7E64FF723774A78FF5BC2722977836583CC4A4A84BDC6799065058304C12&lt;BR /&gt;Tue Jun 23 10:06:20 2020 Debug: HTTPS : - : SSLVersionCallback: Invalid SSL version 0&lt;BR /&gt;Tue Jun 23 10:06:20 2020 Debug: HTTPS : - : New Session negotiated with SSL client&lt;BR /&gt;Tue Jun 23 10:06:20 2020 Debug: HTTPS : - : Verify Cert Callback error - code = 3 : unable to get certificate CRL&lt;BR /&gt;Tue Jun 23 10:06:20 2020 Debug: HTTPS : - : Verify Cert Callback error - code = 3 : unable to get certificate CRL&lt;BR /&gt;Tue Jun 23 10:06:20 2020 Debug: HTTPS : - : Verify Cert Callback error - code = 3 : unable to get certificate CRL&lt;BR /&gt;Tue Jun 23 10:06:20 2020 Debug: HTTPS : - : Verify Cert Callback error - code = 3 : unable to get certificate CRL&lt;BR /&gt;Tue Jun 23 10:06:20 2020 Debug: HTTPS : - : Verify Cert Callback error - code = 3 : unable to get certificate CRL&lt;BR /&gt;Tue Jun 23 10:06:20 2020 Debug: HTTPS : - : Verify Cert Callback error - code = 3 : unable to get certificate CRL&lt;BR /&gt;Tue Jun 23 10:06:20 2020 Debug: HTTPS : - : Verify Cert Callback error - code = 3 : unable to get certificate CRL&lt;BR /&gt;Tue Jun 23 10:06:20 2020 Debug: HTTPS : - : Verify Cert Callback error - code = 3 : unable to get certificate CRL&lt;BR /&gt;Tue Jun 23 10:06:20 2020 Debug: HTTPS : - : Verify Cert Callback error - code = 3 : unable to get certificate CRL&lt;BR /&gt;Tue Jun 23 10:06:20 2020 Debug: HTTPS : - : Verify Cert Callback error - code = 3 : unable to get certificate CRL&lt;BR /&gt;Tue Jun 23 10:06:20 2020 Debug: HTTPS : - : Verify Cert Callback error - code = 3 : unable to get certificate CRL&lt;BR /&gt;Tue Jun 23 10:06:20 2020 Debug: HTTPS : - : Verify Cert Callback error - code = 3 : unable to get certificate CRL&lt;BR /&gt;Tue Jun 23 10:06:20 2020 Debug: HTTPS : - : Verify Cert Callback error - code = 3 : unable to get certificate CRL&lt;BR /&gt;Tue Jun 23 10:06:20 2020 Debug: HTTPS : - : Verify Cert Callback error - code = 3 : unable to get certificate CRL&lt;BR /&gt;Tue Jun 23 10:06:20 2020 Debug: HTTPS : - : Verify Cert Callback error - code = 3 : unable to get certificate CRL&lt;BR /&gt;Tue Jun 23 10:06:20 2020 Debug: HTTPS : - : Verify Cert Callback error - code = 3 : unable to get certificate CRL&lt;BR /&gt;Tue Jun 23 10:06:20 2020 Debug: HTTPS : - : Verify Cert Callback error - code = 3 : unable to get certificate CRL&lt;BR /&gt;Tue Jun 23 10:06:20 2020 Debug: HTTPS : - : Verify Cert Callback error - code = 3 : unable to get certificate CRL&lt;BR /&gt;Tue Jun 23 10:06:20 2020 Debug: HTTPS : - : Verify Cert Callback error - code = 3 : unable to get certificate CRL&lt;BR /&gt;Tue Jun 23 10:06:20 2020 Debug: HTTPS : - : Verify Cert Callback error - code = 3 : unable to get certificate CRL&lt;BR /&gt;Tue Jun 23 10:06:20 2020 Debug: HTTPS : - : Verify Cert Callback error - code = 3 : unable to get certificate CRL&lt;BR /&gt;Tue Jun 23 10:06:20 2020 Debug: HTTPS : - : Verify Cert Callback error - code = 3 : unable to get certificate CRL&lt;BR /&gt;Tue Jun 23 10:06:20 2020 Debug: HTTPS : - : Verify Cert Callback error - code = 3 : unable to get certificate CRL&lt;BR /&gt;Tue Jun 23 10:06:20 2020 Debug: HTTPS : - : Verify Cert Callback error - code = 3 : unable to get certificate CRL&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jun 2020 06:32:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-s190-ssl-configuration-can-t-open-some-web-resourses/m-p/4107766#M9086</guid>
      <dc:creator>Anton84</dc:creator>
      <dc:date>2020-06-23T06:32:52Z</dc:date>
    </item>
    <item>
      <title>Re: WSA S190 SSL Configuration  - can't open some web-resourses</title>
      <link>https://community.cisco.com/t5/web-security/wsa-s190-ssl-configuration-can-t-open-some-web-resourses/m-p/4107805#M9087</link>
      <description>&lt;P&gt;Hi Anton,&lt;/P&gt;
&lt;P&gt;Thanks for the logs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Seems the issue is caused by cross-signed certs in the chain and recently expired Add-Trust certificate. More details are here&amp;nbsp;&lt;A href="https://support.sectigo.com/articles/Knowledge/Sectigo-AddTrust-External-CA-Root-Expiring-May-30-2020" target="_blank"&gt;https://support.sectigo.com/articles/Knowledge/Sectigo-AddTrust-External-CA-Root-Expiring-May-30-2020&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please check the version of the trusted cert bundle on the WSA (GUI -&amp;gt; Network -&amp;gt; Certificate Management) - version 1.7 should have the fix for the issue. If it is lower than 1.7 please try updating it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jun 2020 07:44:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-s190-ssl-configuration-can-t-open-some-web-resourses/m-p/4107805#M9087</guid>
      <dc:creator>opryluts</dc:creator>
      <dc:date>2020-06-23T07:44:54Z</dc:date>
    </item>
    <item>
      <title>Re: WSA S190 SSL Configuration  - can't open some web-resourses</title>
      <link>https://community.cisco.com/t5/web-security/wsa-s190-ssl-configuration-can-t-open-some-web-resourses/m-p/4107917#M9088</link>
      <description>&lt;P&gt;Thanks for your answer, I see 1.7 version, but stange that status is "updates in progress"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jun 2020 11:56:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-s190-ssl-configuration-can-t-open-some-web-resourses/m-p/4107917#M9088</guid>
      <dc:creator>Anton84</dc:creator>
      <dc:date>2020-06-23T11:56:22Z</dc:date>
    </item>
    <item>
      <title>Re: WSA S190 SSL Configuration  - can't open some web-resourses</title>
      <link>https://community.cisco.com/t5/web-security/wsa-s190-ssl-configuration-can-t-open-some-web-resourses/m-p/4107925#M9089</link>
      <description>&lt;P&gt;Hi Anton,&lt;/P&gt;
&lt;P&gt;Please grep updater logs for the "trusted_root" keyword and check if any error messages displayed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also you can try restarting updater service by CLI -&amp;gt; diagnostic -&amp;gt; services -&amp;gt; updater -&amp;gt; restart command.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jun 2020 12:09:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-s190-ssl-configuration-can-t-open-some-web-resourses/m-p/4107925#M9089</guid>
      <dc:creator>opryluts</dc:creator>
      <dc:date>2020-06-23T12:09:34Z</dc:date>
    </item>
    <item>
      <title>Re: WSA S190 SSL Configuration  - can't open some web-resourses</title>
      <link>https://community.cisco.com/t5/web-security/wsa-s190-ssl-configuration-can-t-open-some-web-resourses/m-p/4107953#M9090</link>
      <description>&lt;P&gt;when i click to update, i see in logs:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tue Jun 23 16:12:50 2020 Info: Starting scheduled update&lt;BR /&gt;Tue Jun 23 16:12:51 2020 Info: Scheduled next update to occur at Tue Jun 23 16:17:51 2020&lt;BR /&gt;Tue Jun 23 16:15:45 2020 Info: Scheduled next wbrs update to occur at Tue Jun 23 16:20:45 2020&lt;BR /&gt;Tue Jun 23 16:17:51 2020 Info: Starting scheduled update&lt;BR /&gt;Tue Jun 23 16:17:56 2020 Info: Scheduled next update to occur at Tue Jun 23 16:22:56 2020&lt;BR /&gt;Tue Jun 23 16:20:45 2020 Info: Scheduled next wbrs update to occur at Tue Jun 23 16:25:45 2020&lt;BR /&gt;Tue Jun 23 16:22:56 2020 Info: Starting scheduled update&lt;BR /&gt;Tue Jun 23 16:22:58 2020 Info: Scheduled next update to occur at Tue Jun 23 16:27:58 2020&lt;BR /&gt;Tue Jun 23 16:23:14 2020 Info: Received remote command to signal a manual update&lt;BR /&gt;Tue Jun 23 16:23:14 2020 Info: Starting manual update&lt;BR /&gt;Tue Jun 23 16:23:15 2020 Info: Scheduled next update to occur at Tue Jun 23 16:28:15 2020&lt;BR /&gt;Tue Jun 23 16:25:45 2020 Info: Scheduled next wbrs update to occur at Tue Jun 23 16:30:45 2020&lt;BR /&gt;Tue Jun 23 16:28:15 2020 Info: Starting scheduled update&lt;BR /&gt;Tue Jun 23 16:28:16 2020 Info: Scheduled next update to occur at Tue Jun 23 16:33:16 2020&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If i grep "trusted_root" in log, i see old logs:&lt;/P&gt;&lt;P&gt;Mon Jun 1 23:02:27 2020 Info: trusted_root applying file "trusted_root/1.0.0/trustedca.pem/default/1583495981"&lt;BR /&gt;Mon Jun 1 23:02:44 2020 Info: trusted_root verifying applied files&lt;BR /&gt;Mon Jun 1 23:02:44 2020 Info: trusted_root updating the client manifest&lt;BR /&gt;Mon Jun 1 23:02:44 2020 Info: trusted_root update completed&lt;BR /&gt;Mon Jun 1 23:02:44 2020 Info: trusted_root waiting for new updates&lt;BR /&gt;Thu Jun 4 02:46:41 2020 Info: trusted_root updater shutdown complete&lt;BR /&gt;Thu Jun 4 02:46:41 2020 Info: trusted_root waiting for new updates&lt;BR /&gt;Fri Jun 5 12:32:52 2020 Info: trusted_root updater shutdown complete&lt;BR /&gt;Fri Jun 5 12:32:52 2020 Info: trusted_root waiting for new updates&lt;BR /&gt;Fri Jun 5 16:53:10 2020 Info: trusted_root updater shutdown complete&lt;BR /&gt;Fri Jun 5 16:53:10 2020 Info: trusted_root waiting for new updates&lt;BR /&gt;Wed Jun 10 17:38:19 2020 Info: trusted_root updater shutdown complete&lt;BR /&gt;Wed Jun 10 17:38:19 2020 Info: trusted_root waiting for new updates&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;by CLI - &amp;gt; diagnostic I dont have any services:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;diagnostic&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Choose the operation you want to perform:&lt;BR /&gt;- NET - Network Diagnostic Utility.&lt;BR /&gt;- PROXY - Proxy Debugging Utility.&lt;BR /&gt;- REPORTING - Reporting Utilities.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jun 2020 12:59:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-s190-ssl-configuration-can-t-open-some-web-resourses/m-p/4107953#M9090</guid>
      <dc:creator>Anton84</dc:creator>
      <dc:date>2020-06-23T12:59:21Z</dc:date>
    </item>
    <item>
      <title>Re: WSA S190 SSL Configuration  - can't open some web-resourses</title>
      <link>https://community.cisco.com/t5/web-security/wsa-s190-ssl-configuration-can-t-open-some-web-resourses/m-p/4107973#M9091</link>
      <description>&lt;P&gt;Thanks Anton,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Those lines indicate that the trust cert bundle has been downloaded:&lt;/P&gt;
&lt;PRE&gt;Mon Jun 1 23:02:27 2020 Info: trusted_root applying file "trusted_root/1.0.0/trustedca.pem/default/1583495981"
Mon Jun 1 23:02:44 2020 Info: trusted_root verifying applied files
Mon Jun 1 23:02:44 2020 Info: trusted_root updating the client manifest
Mon Jun 1 23:02:44 2020 Info: trusted_root update completed
Mon Jun 1 23:02:44 2020 Info: trusted_root waiting for new updates&lt;/PRE&gt;
&lt;P&gt;Might be it was not properly applied to the proxy services since still GUI reports that update is in progress. You can try rebooting the box out of production hours and see if that helps.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jun 2020 13:26:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-s190-ssl-configuration-can-t-open-some-web-resourses/m-p/4107973#M9091</guid>
      <dc:creator>opryluts</dc:creator>
      <dc:date>2020-06-23T13:26:22Z</dc:date>
    </item>
    <item>
      <title>Re: WSA S190 SSL Configuration  - can't open some web-resourses</title>
      <link>https://community.cisco.com/t5/web-security/wsa-s190-ssl-configuration-can-t-open-some-web-resourses/m-p/4110629#M9095</link>
      <description>&lt;P&gt;Unfortunately after reboot i look the same picture.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jun 2020 05:17:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-s190-ssl-configuration-can-t-open-some-web-resourses/m-p/4110629#M9095</guid>
      <dc:creator>Anton84</dc:creator>
      <dc:date>2020-06-29T05:17:58Z</dc:date>
    </item>
    <item>
      <title>Re: WSA S190 SSL Configuration  - can't open some web-resourses</title>
      <link>https://community.cisco.com/t5/web-security/wsa-s190-ssl-configuration-can-t-open-some-web-resourses/m-p/4110641#M9096</link>
      <description>&lt;P&gt;maybe blocked certs can prevent to open sites&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jun 2020 08:30:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-s190-ssl-configuration-can-t-open-some-web-resourses/m-p/4110641#M9096</guid>
      <dc:creator>Anton84</dc:creator>
      <dc:date>2020-06-29T08:30:18Z</dc:date>
    </item>
    <item>
      <title>Re: WSA S190 SSL Configuration  - can't open some web-resourses</title>
      <link>https://community.cisco.com/t5/web-security/wsa-s190-ssl-configuration-can-t-open-some-web-resourses/m-p/4110716#M9097</link>
      <description>&lt;P&gt;Hi Anton,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for the update.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I don't see any cert from the chain in the block list. Let's start from the beginning - what AsyncOS version is your WSA running?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jun 2020 09:03:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-s190-ssl-configuration-can-t-open-some-web-resourses/m-p/4110716#M9097</guid>
      <dc:creator>opryluts</dc:creator>
      <dc:date>2020-06-29T09:03:37Z</dc:date>
    </item>
    <item>
      <title>Re: WSA S190 SSL Configuration  - can't open some web-resourses</title>
      <link>https://community.cisco.com/t5/web-security/wsa-s190-ssl-configuration-can-t-open-some-web-resourses/m-p/4111192#M9103</link>
      <description>&lt;P&gt;Version: 11.5.1-124&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jun 2020 08:10:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-s190-ssl-configuration-can-t-open-some-web-resourses/m-p/4111192#M9103</guid>
      <dc:creator>Anton84</dc:creator>
      <dc:date>2020-06-30T08:10:32Z</dc:date>
    </item>
    <item>
      <title>Re: WSA S190 SSL Configuration  - can't open some web-resourses</title>
      <link>https://community.cisco.com/t5/web-security/wsa-s190-ssl-configuration-can-t-open-some-web-resourses/m-p/4111364#M9104</link>
      <description>&lt;P&gt;Thank you, that version supports cross-signed certificates.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Could you please describe how does the issue look from users perspective? What do they see in the browser window when accessing those sites? Any error messages or a blank screen?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also what do you see in access logs for those failing transactions?&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jun 2020 13:28:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-s190-ssl-configuration-can-t-open-some-web-resourses/m-p/4111364#M9104</guid>
      <dc:creator>opryluts</dc:creator>
      <dc:date>2020-06-30T13:28:21Z</dc:date>
    </item>
    <item>
      <title>Re: WSA S190 SSL Configuration  - can't open some web-resourses</title>
      <link>https://community.cisco.com/t5/web-security/wsa-s190-ssl-configuration-can-t-open-some-web-resourses/m-p/4112452#M9105</link>
      <description>&lt;P&gt;On all sites I see the same java-scrypt&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jul 2020 13:55:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-s190-ssl-configuration-can-t-open-some-web-resourses/m-p/4112452#M9105</guid>
      <dc:creator>Anton84</dc:creator>
      <dc:date>2020-07-02T13:55:20Z</dc:date>
    </item>
    <item>
      <title>Re: WSA S190 SSL Configuration  - can't open some web-resourses</title>
      <link>https://community.cisco.com/t5/web-security/wsa-s190-ssl-configuration-can-t-open-some-web-resourses/m-p/4115821#M9110</link>
      <description>&lt;P&gt;Hi Anton,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for the inputs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Seems I see the same behaviour in my lab. I'll dig into the issue...&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jul 2020 08:11:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-s190-ssl-configuration-can-t-open-some-web-resourses/m-p/4115821#M9110</guid>
      <dc:creator>opryluts</dc:creator>
      <dc:date>2020-07-09T08:11:05Z</dc:date>
    </item>
    <item>
      <title>Re: WSA S190 SSL Configuration  - can't open some web-resourses</title>
      <link>https://community.cisco.com/t5/web-security/wsa-s190-ssl-configuration-can-t-open-some-web-resourses/m-p/4115844#M9112</link>
      <description>&lt;P&gt;Hi Anton,&lt;/P&gt;
&lt;P&gt;I think I see the problem...&lt;/P&gt;
&lt;P&gt;All those websites use a protection service&amp;nbsp;&lt;A href="https://variti.com/ru-ru/" target="_blank"&gt;https://variti.com/ru-ru/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;And for some reason, it blocks or tries to verify those transactions. Not sure why but to me it looks like a misbehaving from their side. I tested those 2 sites from different locations, directly and via WSA and most of times I'm getting responses with "Server: Variti/0.9.3a" HTTP header and JS in the payload.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Sometimes I was able to load the page. In those cases, Server header was set to Nginx and payload was in HTML.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'd advise contacting Variti/Website owners to see why their protection service blocks those transactions.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jul 2020 09:05:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-s190-ssl-configuration-can-t-open-some-web-resourses/m-p/4115844#M9112</guid>
      <dc:creator>opryluts</dc:creator>
      <dc:date>2020-07-09T09:05:27Z</dc:date>
    </item>
  </channel>
</rss>

