Palo Alto Certificate Management

 1. Device > Certificate Management >  Certificates > Device Certificates, click Generate




















2 . Click "Export Certificate" to download CSR file  













                                                                                          

3. Submit and Download Base 64 encoded certificate


























4. Device > Certificate Management >  Certificates > Device Certificates, import the certificate





















Note this certificate has key but no CA.


5. Device > Certificate Management > SSL/TLS Service Profile, add a new profile




6. Device > Setup > Management > General Settings, specify SSL/TLS Service Profile





















==============

SSL Decryption Certificate



1. Import internal root CA, mark it as trusted Root CA




















































2. Generate CSR for Forward-Trust-Cert, export it, request a cert from internal CA, import the cert.



































































































Mark it as Forward Trust Certificate

























3. Generate a self signed Forward-Untrusted-Cert
    Make sure "Certificate Authority" is checked.






































Mark the cert as "Forward Untrust Certificate"

























-------

All certs:




Comments

Popular posts from this blog

ASA IKEv1 VPN troubleshooting Steps and Tips

Firepower 2100/1100 FTD/ASA initial setup, reimage, upgrade.

Firepower FMC and FTD troubleshooting