<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Renew Global Protect Gateway &amp;amp; Portal Certificates in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/renew-global-protect-gateway-amp-portal-certificates/m-p/455023#M2242</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/204219"&gt;@malayalamitlokam&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It's easy.&amp;nbsp; Simply import the new certificate, and it will replace the existing one.&amp;nbsp; I would export the existing certificate and key just in case.&amp;nbsp; Since your existing configuration works, I would give the new certificate the same name so I don't have to change the configuration.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Depending on the CA, you should be able to get a new cert with the same private key.&amp;nbsp; In which case you would not need to import the private key.&amp;nbsp; This is a good doc for reference -&amp;gt; &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClFoCAK" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClFoCAK&lt;/A&gt;.&amp;nbsp; One thing I don't like about the doc is that it says you should import the server (portal, gateway) cert with the private key.&amp;nbsp; This is not necessary if you generated the CSR and key from the Palo Alto or you are re-using the existing private key.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tom&lt;/P&gt;</description>
    <pubDate>Wed, 22 Dec 2021 17:06:28 GMT</pubDate>
    <dc:creator>TomYoung</dc:creator>
    <dc:date>2021-12-22T17:06:28Z</dc:date>
    <item>
      <title>Renew Global Protect Gateway &amp; Portal Certificates</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/renew-global-protect-gateway-amp-portal-certificates/m-p/454870#M2240</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Greetings,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are using certificate from external CA for Global Protect Portal and Gateway which is currently in production.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It is expiring next week. What will be the best way to renew the certificate.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank &amp;amp; Regards&lt;/P&gt;&lt;P&gt;S Prasad&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Dec 2021 05:07:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/renew-global-protect-gateway-amp-portal-certificates/m-p/454870#M2240</guid>
      <dc:creator>malayalamitlokam</dc:creator>
      <dc:date>2021-12-22T05:07:06Z</dc:date>
    </item>
    <item>
      <title>Re: Renew Global Protect Gateway &amp; Portal Certificates</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/renew-global-protect-gateway-amp-portal-certificates/m-p/455023#M2242</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/204219"&gt;@malayalamitlokam&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It's easy.&amp;nbsp; Simply import the new certificate, and it will replace the existing one.&amp;nbsp; I would export the existing certificate and key just in case.&amp;nbsp; Since your existing configuration works, I would give the new certificate the same name so I don't have to change the configuration.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Depending on the CA, you should be able to get a new cert with the same private key.&amp;nbsp; In which case you would not need to import the private key.&amp;nbsp; This is a good doc for reference -&amp;gt; &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClFoCAK" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClFoCAK&lt;/A&gt;.&amp;nbsp; One thing I don't like about the doc is that it says you should import the server (portal, gateway) cert with the private key.&amp;nbsp; This is not necessary if you generated the CSR and key from the Palo Alto or you are re-using the existing private key.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Wed, 22 Dec 2021 17:06:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/renew-global-protect-gateway-amp-portal-certificates/m-p/455023#M2242</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2021-12-22T17:06:28Z</dc:date>
    </item>
  </channel>
</rss>

