<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Certificate Chain Requirements from External CA for Global Protect in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/certificate-chain-requirements-from-external-ca-for-global/m-p/1219746#M6443</link>
    <description>&lt;P&gt;As per the image it into firewall along with ROOT-CA cert private key is also imported, but for server/ssl cert only certificate is imported not key, Without private key it wont appear in SSL/TLS profile settings, Reimport the certificate along with private key.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 07 Feb 2025 05:41:54 GMT</pubDate>
    <dc:creator>Naga_Chaturvedi</dc:creator>
    <dc:date>2025-02-07T05:41:54Z</dc:date>
    <item>
      <title>Certificate Chain Requirements from External CA for Global Protect</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/certificate-chain-requirements-from-external-ca-for-global/m-p/1219678#M6441</link>
      <description>&lt;P&gt;Hi Everyone,&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;So I'm having issues configuring my GP as it does not allow me to select the server-cert from the TLS/SSL Service profile Window.&lt;/P&gt;
&lt;P&gt;The server-cert is not even an option to select from within the window itself and when i try to import it from inside the TLS/SSL Service profile window - it imports but errors out saying the cert is invalid.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I noticed that the certificate chain I got from SSL.com that I imported doesn't have a check mark on the key column under the server cert, I only have a checkmark under the key column for the root cert which overwrote the CSR.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="GP7337_1-1738863827766.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/65875iFDC5B98438214A44/image-size/medium?v=v2&amp;amp;px=400" role="button" title="GP7337_1-1738863827766.png" alt="GP7337_1-1738863827766.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So the question I have is - how do I get a key check mark to appear under the Server-Cert inside the cert chain?&amp;nbsp; Do I have the wrong type of SSL cert?&amp;nbsp; What am I missing?&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Thanks in Advance Everyone!&lt;/P&gt;</description>
      <pubDate>Thu, 06 Feb 2025 17:45:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/certificate-chain-requirements-from-external-ca-for-global/m-p/1219678#M6441</guid>
      <dc:creator>GP7337</dc:creator>
      <dc:date>2025-02-06T17:45:01Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate Chain Requirements from External CA for Global Protect</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/certificate-chain-requirements-from-external-ca-for-global/m-p/1219746#M6443</link>
      <description>&lt;P&gt;As per the image it into firewall along with ROOT-CA cert private key is also imported, but for server/ssl cert only certificate is imported not key, Without private key it wont appear in SSL/TLS profile settings, Reimport the certificate along with private key.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Feb 2025 05:41:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/certificate-chain-requirements-from-external-ca-for-global/m-p/1219746#M6443</guid>
      <dc:creator>Naga_Chaturvedi</dc:creator>
      <dc:date>2025-02-07T05:41:54Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate Chain Requirements from External CA for Global Protect</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/certificate-chain-requirements-from-external-ca-for-global/m-p/1219801#M6447</link>
      <description>&lt;P&gt;Hi &lt;A href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/245004" target="_blank"&gt;Naga,&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for your reply! &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;So this is part of the problem I don't have a key for the server cert specifically as the cert I received is part of a certificate bundle.&lt;/P&gt;
&lt;P&gt;When I try to import the CSR key that was used to generate the external CA's certificate chain it errors out saying the key isn't valid.&lt;/P&gt;
&lt;P&gt;So is there a specific attribute or a type of cert I need in order to get this to work?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Gary&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Feb 2025 15:11:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/certificate-chain-requirements-from-external-ca-for-global/m-p/1219801#M6447</guid>
      <dc:creator>GP7337</dc:creator>
      <dc:date>2025-02-07T15:11:43Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate Chain Requirements from External CA for Global Protect</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/certificate-chain-requirements-from-external-ca-for-global/m-p/1221774#M6513</link>
      <description>&lt;P&gt;Just a heads up this was fixed - when you are importing the certs into the firewall do not overwrite the CSR until you are importing the server cert portion of the certificate chain.&amp;nbsp; This way the key will be paired properly with the server cert.&lt;BR /&gt;Hope this helps someone in the future &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Feb 2025 15:01:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/certificate-chain-requirements-from-external-ca-for-global/m-p/1221774#M6513</guid>
      <dc:creator>GP7337</dc:creator>
      <dc:date>2025-02-24T15:01:54Z</dc:date>
    </item>
  </channel>
</rss>

