<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Portal/Gateway certificate renewals - automation? in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/portal-gateway-certificate-renewals-automation/m-p/1250878#M7327</link>
    <description>&lt;P&gt;Thanks for the tips and links, Tom. I'll look into them and see if I can make it work.At least there's a starting point, and even if I am not real savvy on the code side, I have people who are and can probably help&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It's a shame that PA can't/won't build this into the product automatically - a security company who can't simplify maintaining one of the core requirements for security is not real impressive.&lt;/P&gt;</description>
    <pubDate>Tue, 24 Mar 2026 23:38:45 GMT</pubDate>
    <dc:creator>darren_g</dc:creator>
    <dc:date>2026-03-24T23:38:45Z</dc:date>
    <item>
      <title>Portal/Gateway certificate renewals - automation?</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/portal-gateway-certificate-renewals-automation/m-p/1250800#M7325</link>
      <description>&lt;P&gt;Greetings&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;With the continued push for shorter and shorter SSL certificate validation periods coming rapidly to a head (in case you missed it - maximum SSL certificate validity is now 200 days, will go down to 100 days in March 2027, and 47 days in 2029), I'm looking for a way to automate SSL certificate renewals on my Global Protect gateways/portals.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Has anyone com up with a solution that works? Some way of automating SSL renewal - be it via something like LetsEncrypt or a regular CA's process?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please, if you have - share your magic! Having to remember to renew portal/gateway certs every 46 days is going to suck.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Mar 2026 04:42:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/portal-gateway-certificate-renewals-automation/m-p/1250800#M7325</guid>
      <dc:creator>darren_g</dc:creator>
      <dc:date>2026-03-24T04:42:39Z</dc:date>
    </item>
    <item>
      <title>Re: Portal/Gateway certificate renewals - automation?</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/portal-gateway-certificate-renewals-automation/m-p/1250844#M7326</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/2280"&gt;@darren_g&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I haven't tried it. but this looks easy and effective.&amp;nbsp;&amp;nbsp;&lt;A href="https://www.linkedin.com/pulse/can-we-configure-palo-alto-firewalls-automatically-obtain-joe-brunner-qrxoe/" target="_blank"&gt;https://www.linkedin.com/pulse/can-we-configure-palo-alto-firewalls-automatically-obtain-joe-brunner-qrxoe/&lt;/A&gt;&amp;nbsp; It looks like it could use a couple tweaks.&amp;nbsp; I could easily come up with CURL commands to do the tasks via API in step 6.&amp;nbsp; You don't need to update the GP portal or gateway, only update the current SSL/TLS Service profile to use the new certificate.&amp;nbsp; With the CURL commands, everything could be done in one bash script.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here is a similar article.&amp;nbsp;&amp;nbsp;&lt;A href="https://medium.com/palo-alto-networks-developer-blog/costless-automated-trusted-certificates-on-palo-alto-networks-firewalls-5b2930b2893f" target="_blank"&gt;https://medium.com/palo-alto-networks-developer-blog/costless-automated-trusted-certificates-on-palo-alto-networks-firewalls-5b2930b2893f&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Let's see if anyone posts a fully developed and tested script.&amp;nbsp; Otherwise, I may work on it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;More and more CAs are using ACMEv2.&amp;nbsp; So, the method should work with a lot of different CAs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;PANW has some Next-Gen Trust Security feature that integrates with SCM (for a fee?).&amp;nbsp;&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/next-gen-trust-security/next-gen-trust-security/about-vaas/configurations-overview/acme-server-overview/configure-acme-server-connection" target="_blank"&gt;https://docs.paloaltonetworks.com/next-gen-trust-security/next-gen-trust-security/about-vaas/configurations-overview/acme-server-overview/configure-acme-server-connection&lt;/A&gt;&amp;nbsp;&amp;nbsp;At the bottom it says that it does not support automated certificate renewal! What's the point?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do we really want a built-in ACMEv2 client on each NGFW?&amp;nbsp; Then each will try to renew the same certificate multiple times?&amp;nbsp; This may be a good feature for Panorama, or SCM once they get the bugs worked out.&amp;nbsp; Doing it once for the organization makes sense.&amp;nbsp; If you don't use either, a standalone Linux server and script should be easy enough.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Tue, 24 Mar 2026 19:04:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/portal-gateway-certificate-renewals-automation/m-p/1250844#M7326</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2026-03-24T19:04:30Z</dc:date>
    </item>
    <item>
      <title>Re: Portal/Gateway certificate renewals - automation?</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/portal-gateway-certificate-renewals-automation/m-p/1250878#M7327</link>
      <description>&lt;P&gt;Thanks for the tips and links, Tom. I'll look into them and see if I can make it work.At least there's a starting point, and even if I am not real savvy on the code side, I have people who are and can probably help&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It's a shame that PA can't/won't build this into the product automatically - a security company who can't simplify maintaining one of the core requirements for security is not real impressive.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Mar 2026 23:38:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/portal-gateway-certificate-renewals-automation/m-p/1250878#M7327</guid>
      <dc:creator>darren_g</dc:creator>
      <dc:date>2026-03-24T23:38:45Z</dc:date>
    </item>
  </channel>
</rss>

