<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Re-Generate SSL Certificate in Expedition Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/expedition-discussions/re-generate-ssl-certificate/m-p/245315#M976</link>
    <description>&lt;P&gt;Thanks for the feedback.&amp;nbsp; Yes I restarted both the service and the VM, it didn't seem to have any impact.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 09 Jan 2019 12:16:09 GMT</pubDate>
    <dc:creator>LCMember2274</dc:creator>
    <dc:date>2019-01-09T12:16:09Z</dc:date>
    <item>
      <title>Re-Generate SSL Certificate</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/re-generate-ssl-certificate/m-p/245103#M963</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I'm in the process of hardening Expedetion (v 1.1.2) using the Expedition-Hardening-Guide.&amp;nbsp; Everything is going well, expect when I attempt to update the SSL certificate the changes do not seem to take effect.&amp;nbsp; I've even gone so far as to remove the old *snakeoil* files and replace them with new ones.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does anyone have advice on how to update to either a new self-signed certificate or trusted certificate?&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Thanks,&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Jan 2019 13:57:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/re-generate-ssl-certificate/m-p/245103#M963</guid>
      <dc:creator>LCMember2274</dc:creator>
      <dc:date>2019-01-07T13:57:48Z</dc:date>
    </item>
    <item>
      <title>Re: Re-Generate SSL Certificate</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/re-generate-ssl-certificate/m-p/245314#M975</link>
      <description>&lt;P&gt;Probably you did but Have you restarted the apache daemon after the changes?&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jan 2019 12:04:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/re-generate-ssl-certificate/m-p/245314#M975</guid>
      <dc:creator>alestevez</dc:creator>
      <dc:date>2019-01-09T12:04:12Z</dc:date>
    </item>
    <item>
      <title>Re: Re-Generate SSL Certificate</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/re-generate-ssl-certificate/m-p/245315#M976</link>
      <description>&lt;P&gt;Thanks for the feedback.&amp;nbsp; Yes I restarted both the service and the VM, it didn't seem to have any impact.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jan 2019 12:16:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/re-generate-ssl-certificate/m-p/245315#M976</guid>
      <dc:creator>LCMember2274</dc:creator>
      <dc:date>2019-01-09T12:16:09Z</dc:date>
    </item>
    <item>
      <title>Re: Re-Generate SSL Certificate</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/re-generate-ssl-certificate/m-p/245320#M978</link>
      <description>&lt;P&gt;I just tried to run the 2 commands from the hardening guide and worked for me, Have you tried to use another browser to see if it gets the new certificate?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can check in the config file if your apache is pointing to those certificates?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;go to /etc/apache/sites-enabled&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;and edit the file "default-ssl.conf and check for&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;SSLCertificateFile&lt;/SPAN&gt;&lt;SPAN class="s2"&gt;&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;/etc/ssl/certs/ssl-cert-snakeoil.pem&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;SSLCertificateKeyFile&lt;/SPAN&gt;&lt;SPAN class="s2"&gt; /etc/ssl/private/ssl-cert-snakeoil.key&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s2"&gt;Regards&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jan 2019 12:44:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/re-generate-ssl-certificate/m-p/245320#M978</guid>
      <dc:creator>alestevez</dc:creator>
      <dc:date>2019-01-09T12:44:37Z</dc:date>
    </item>
    <item>
      <title>Re: Re-Generate SSL Certificate</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/re-generate-ssl-certificate/m-p/245324#M979</link>
      <description>&lt;P&gt;Thanks, a different browser picked up the new cert.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Appreciate it!&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jan 2019 13:10:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/re-generate-ssl-certificate/m-p/245324#M979</guid>
      <dc:creator>LCMember2274</dc:creator>
      <dc:date>2019-01-09T13:10:31Z</dc:date>
    </item>
    <item>
      <title>Re: Re-Generate SSL Certificate</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/re-generate-ssl-certificate/m-p/395463#M3275</link>
      <description>&lt;P&gt;Let's create a new certificate for Expedition!&lt;/P&gt;
&lt;P&gt;First we need to create a CSR to get signed by an external CA. Copy the stanza below and edit for your &lt;BR /&gt;Expeditions' settings. Save it as req.conf.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;expedition@Expedition:~$ mkdir ssl &amp;amp;&amp;amp; cd ssl&lt;BR /&gt;expedition@Expedition:~/ssl$ vi req.conf&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;[req]&lt;BR /&gt;distinguished_name = req_distinguished_name&lt;BR /&gt;req_extensions = v3_req&lt;BR /&gt;prompt = no&lt;BR /&gt;[req_distinguished_name]&lt;BR /&gt;C = US&lt;BR /&gt;ST = OR&lt;BR /&gt;L = Portland&lt;BR /&gt;O = RiceCasa&lt;BR /&gt;OU = Tooling&lt;BR /&gt;CN = expedtion.example.com&lt;BR /&gt;[v3_req]&lt;BR /&gt;keyUsage = keyEncipherment, dataEncipherment&lt;BR /&gt;extendedKeyUsage = serverAuth&lt;BR /&gt;subjectAltName = @alt_names&lt;BR /&gt;[alt_names]&lt;BR /&gt;DNS.1 = expedition.example.com&lt;BR /&gt;DNS.2 = expedition&lt;BR /&gt;IP.1 = 10.1.0.34&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;With the req.conf configured, create the CSR:&lt;/P&gt;
&lt;P&gt;expedition@Expedition:~/ssl$ openssl req -new -out expedition.csr -newkey rsa:2048 -nodes -sha256 -keyout expedition.key -config req.conf&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Generating a 2048 bit RSA private key&lt;BR /&gt;..................................................+++&lt;BR /&gt;........+++&lt;BR /&gt;writing new private key to 'expedition.key'&lt;BR /&gt;-----&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;expedition@Expedition:~/ssl$ ls -l&lt;BR /&gt;total 20&lt;BR /&gt;drwxrwxr-x 2 expedition expedition 4096 Apr 1 11:49 ./&lt;BR /&gt;drwxr-xr-x 6 expedition expedition 4096 Apr 1 11:49 ../&lt;BR /&gt;-rw-rw-r-- 1 expedition expedition 1167 Apr 1 11:49 expedition.csr&lt;BR /&gt;-rw-rw-r-- 1 expedition expedition 1704 Apr 1 11:49 expedition.key&lt;BR /&gt;-rw-rw-r-- 1 expedition expedition 386 Apr 1 11:48 req.conf&lt;BR /&gt;expedition@Expedition:~/ssl$&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Copy the content of the expedition.csr and submit it to your CA:&lt;BR /&gt;expedition@Expedition:~/ssl$ more expedition.csr &lt;BR /&gt;-----BEGIN CERTIFICATE REQUEST-----&lt;BR /&gt;..... removed .....&lt;BR /&gt;-----END CERTIFICATE REQUEST-----&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Get that signed, and save the signed cert as expedition.crt&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Change the permissions of the private key:&lt;BR /&gt;expedition@Expedition:~/ssl$ chmod 400 expedtion.key&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Move the certs to the proper locations:&lt;BR /&gt;expedition@Expedition:~/ssl$ sudo mv expedition.key /etc/ssl/private/&lt;BR /&gt;expedition@Expedition:~/ssl$ sudo mv expedition.crt /etc/ssl/certs/&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Edit Apache's config:&lt;BR /&gt;expedition@Expedition:~/ssl$ sudo vi /etc/apache2/sites-enabled/default-ssl.conf&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Find these lines:&lt;BR /&gt;SSLCertificateFile /etc/ssl/certs/ssl-cert-snakeoil.pem&lt;BR /&gt;SSLCertificateKeyFile /etc/ssl/private/ssl-cert-snakeoil.key&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Edit them to:&lt;BR /&gt;SSLCertificateFile /etc/ssl/certs/expedition.crt&lt;BR /&gt;SSLCertificateKeyFile /etc/ssl/private/expedition.key&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Restart apache.&lt;BR /&gt;expedition@Expedition:~/ssl$ sudo service apache2 restart&lt;/P&gt;</description>
      <pubDate>Thu, 01 Apr 2021 17:34:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/re-generate-ssl-certificate/m-p/395463#M3275</guid>
      <dc:creator>trice</dc:creator>
      <dc:date>2021-04-01T17:34:51Z</dc:date>
    </item>
  </channel>
</rss>

