<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSL Decrypt issues in 6.7 firepower in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ssl-decrypt-issues-in-6-7-firepower/m-p/4188498#M1076108</link>
    <description>Hi,&lt;BR /&gt;&lt;BR /&gt;Can you compare the certificate when there is an error and without the&lt;BR /&gt;error.? Confirm that resignation is done both times by the same FTD. It&lt;BR /&gt;doesn't seem the case. Also, confirm that the CN of the certificate in both&lt;BR /&gt;cases to see that you are hitting the same destination server.&lt;BR /&gt;&lt;BR /&gt;If the error disappears after refresh, this is a good sign that you are not&lt;BR /&gt;following the same path both times.&lt;BR /&gt;&lt;BR /&gt;***** please remember to rate useful posts&lt;BR /&gt;</description>
    <pubDate>Wed, 25 Nov 2020 05:55:28 GMT</pubDate>
    <dc:creator>Mohammed al Baqari</dc:creator>
    <dc:date>2020-11-25T05:55:28Z</dc:date>
    <item>
      <title>SSL Decrypt issues in 6.7 firepower</title>
      <link>https://community.cisco.com/t5/network-security/ssl-decrypt-issues-in-6-7-firepower/m-p/4188175#M1076097</link>
      <description>&lt;P&gt;Hello, I am wondering if anyone has tested the SSL Decrypt-resign function for DPI on their endpoints in 6.7? We are experiencing an odd behavior across multiple browsers using Win10 1809 that when you first load a web page you get a certificate error:&amp;nbsp;&lt;SPAN&gt;NET::ERR_CERT_AUTHORITY_INVALID. After you refresh the page, however, the certificate message goes away. If I close and reopen Chrome, and try the same webpages that previously failed, I don't get any warning message. If I look at the certificate properties within Chrome, it shows my FTD as the "Issued by" which is the default or normal behavior.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Nov 2020 16:14:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssl-decrypt-issues-in-6-7-firepower/m-p/4188175#M1076097</guid>
      <dc:creator>ryan14</dc:creator>
      <dc:date>2020-11-24T16:14:08Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decrypt issues in 6.7 firepower</title>
      <link>https://community.cisco.com/t5/network-security/ssl-decrypt-issues-in-6-7-firepower/m-p/4188498#M1076108</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;Can you compare the certificate when there is an error and without the&lt;BR /&gt;error.? Confirm that resignation is done both times by the same FTD. It&lt;BR /&gt;doesn't seem the case. Also, confirm that the CN of the certificate in both&lt;BR /&gt;cases to see that you are hitting the same destination server.&lt;BR /&gt;&lt;BR /&gt;If the error disappears after refresh, this is a good sign that you are not&lt;BR /&gt;following the same path both times.&lt;BR /&gt;&lt;BR /&gt;***** please remember to rate useful posts&lt;BR /&gt;</description>
      <pubDate>Wed, 25 Nov 2020 05:55:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssl-decrypt-issues-in-6-7-firepower/m-p/4188498#M1076108</guid>
      <dc:creator>Mohammed al Baqari</dc:creator>
      <dc:date>2020-11-25T05:55:28Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decrypt issues in 6.7 firepower</title>
      <link>https://community.cisco.com/t5/network-security/ssl-decrypt-issues-in-6-7-firepower/m-p/4190828#M1076284</link>
      <description>&lt;P&gt;I looked at the SAN in the certificate properties window and it does match. It's the same behavior every time. If I go to newsite.com, I will get the error message on the very first time I try to load that page. Afterwards, any time I try to go to newsite.com, I never see any certificate errors. Even if I open a new browser and go to newsite.com, I don't get the error message. Its only the very first time I try and go to a new SSL protected website. This behavior did not happen in 6.4, 6.6 for us but started in 6.7. We had to go to 6.7 due to a bug in 6.6.1. If my traffic was taking a different path randomly, you would expect to see the certificate error at those random times it fails. But it is not that behavior. The sites and SSL decrypt policy work after the initial failure.&lt;/P&gt;</description>
      <pubDate>Mon, 30 Nov 2020 15:55:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssl-decrypt-issues-in-6-7-firepower/m-p/4190828#M1076284</guid>
      <dc:creator>ryan14</dc:creator>
      <dc:date>2020-11-30T15:55:29Z</dc:date>
    </item>
  </channel>
</rss>

