<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic &amp;quot;Decryption error&amp;quot; in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/quot-decryption-error-quot/m-p/3368048#M924053</link>
    <description>&lt;P&gt;Running FP 8130 appliances, within FP Management we are seeing "Decryption Error" for port 443 traffic. We have a valid root cert for the MtM decryption process. Where can we find more information about WHY this has a "Decryption Error"?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 15:38:44 GMT</pubDate>
    <dc:creator>ashaw216</dc:creator>
    <dc:date>2020-02-21T15:38:44Z</dc:date>
    <item>
      <title>"Decryption error"</title>
      <link>https://community.cisco.com/t5/network-security/quot-decryption-error-quot/m-p/3368048#M924053</link>
      <description>&lt;P&gt;Running FP 8130 appliances, within FP Management we are seeing "Decryption Error" for port 443 traffic. We have a valid root cert for the MtM decryption process. Where can we find more information about WHY this has a "Decryption Error"?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 15:38:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/quot-decryption-error-quot/m-p/3368048#M924053</guid>
      <dc:creator>ashaw216</dc:creator>
      <dc:date>2020-02-21T15:38:44Z</dc:date>
    </item>
    <item>
      <title>Re: "Decryption error"</title>
      <link>https://community.cisco.com/t5/network-security/quot-decryption-error-quot/m-p/3368064#M924054</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What's the version of firmware running and exact error?&lt;/P&gt;
&lt;P&gt;Are you using decrypt resign or decrypt with known key?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Yogesh&lt;/P&gt;</description>
      <pubDate>Wed, 18 Apr 2018 12:22:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/quot-decryption-error-quot/m-p/3368064#M924054</guid>
      <dc:creator>yogdhanu</dc:creator>
      <dc:date>2018-04-18T12:22:34Z</dc:date>
    </item>
    <item>
      <title>Re: "Decryption error"</title>
      <link>https://community.cisco.com/t5/network-security/quot-decryption-error-quot/m-p/3368137#M924055</link>
      <description>&lt;P&gt;6.1.0, under SSL Status it says "Do Not Decrypt (Decryption Error)"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We are using Decrypt - Resign.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Apr 2018 13:33:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/quot-decryption-error-quot/m-p/3368137#M924055</guid>
      <dc:creator>ashaw216</dc:creator>
      <dc:date>2018-04-18T13:33:13Z</dc:date>
    </item>
    <item>
      <title>Re: "Decryption error"</title>
      <link>https://community.cisco.com/t5/network-security/quot-decryption-error-quot/m-p/3368864#M924056</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can try using this command on the sensor CLI&lt;/P&gt;
&lt;PRE style="margin: 0px 10px 10px; padding: 5px; background-color: #e5e5e5; border: 1px dotted #808080; overflow-x: auto; white-space: pre; word-wrap: normal; color: #333333; font-size: 12px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: left; text-indent: 0px; text-transform: none; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration-style: initial; text-decoration-color: initial;"&gt;system support ssl-&lt;SPAN class="lia-search-match-lithium" style="font-weight: bold; background: #ffffcc; color: #666666; padding: 0px 2px; line-height: 1.2;"&gt;client&lt;/SPAN&gt;-&lt;SPAN class="lia-search-match-lithium" style="font-weight: bold; background: #ffffcc; color: #666666; padding: 0px 2px; line-height: 1.2;"&gt;hello&lt;/SPAN&gt;-tuning extensions_remove 16,13172&lt;/PRE&gt;
&lt;P&gt;This would make sure some extensions which are not supported on firepower are removed from client hello.&lt;/P&gt;
&lt;P&gt;The error details need be found using SSL debugs which would require TAC case.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope it helps,&lt;/P&gt;
&lt;P&gt;yogesh&lt;/P&gt;</description>
      <pubDate>Thu, 19 Apr 2018 10:29:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/quot-decryption-error-quot/m-p/3368864#M924056</guid>
      <dc:creator>yogdhanu</dc:creator>
      <dc:date>2018-04-19T10:29:35Z</dc:date>
    </item>
  </channel>
</rss>

