<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic &amp;quot;The Block Private Key Export&amp;quot; option - Strange Behavior in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/quot-the-block-private-key-export-quot-option-strange-behavior/m-p/572914#M2424</link>
    <description>&lt;P&gt;I read the following explanation about the&amp;nbsp;"The Block Private Key Export" option :&amp;nbsp; You can permanently block the export of private keys for certificates when you generate them in or import them into PAN-OS or Panorama.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I tested this option for the certificate generated by an external CA as shown below:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1.png" style="width: 491px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56472i03FC03B6B6912442/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="1.png" alt="1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I submitted the CSR to the CA server using a template to generate a Subordinate CA so that the Firewall will be able to use it for SSL Decryption for outbound SSL traffic.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When I upload the certificate, &lt;SPAN&gt;&lt;SPAN class="richTextArea slds-text-longform tile__title red-txt"&gt;notice the&amp;nbsp;missing icon that would indicate that the&amp;nbsp;private key &lt;STRONG&gt;can&lt;/STRONG&gt; be exported&lt;/SPAN&gt;&lt;/SPAN&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="3.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56473i685885C4359D9648/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="3.png" alt="3.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Now when I export the certificate, the firewall invite me to export the private key and the export is successful.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What's wrong?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Because for the Self Signed Certificate, the "The Block Private Key Export" option works fine as shown below:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Capture d'écran 2024-01-12 230321.png" style="width: 854px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56474i9F136DCBE2FD7999/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Capture d'écran 2024-01-12 230321.png" alt="Capture d'écran 2024-01-12 230321.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="6.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56475i3C2852EABC0E3362/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="6.png" alt="6.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 12 Jan 2024 22:10:57 GMT</pubDate>
    <dc:creator>rmeddane</dc:creator>
    <dc:date>2024-01-12T22:10:57Z</dc:date>
    <item>
      <title>"The Block Private Key Export" option - Strange Behavior</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/quot-the-block-private-key-export-quot-option-strange-behavior/m-p/572914#M2424</link>
      <description>&lt;P&gt;I read the following explanation about the&amp;nbsp;"The Block Private Key Export" option :&amp;nbsp; You can permanently block the export of private keys for certificates when you generate them in or import them into PAN-OS or Panorama.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I tested this option for the certificate generated by an external CA as shown below:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1.png" style="width: 491px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56472i03FC03B6B6912442/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="1.png" alt="1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I submitted the CSR to the CA server using a template to generate a Subordinate CA so that the Firewall will be able to use it for SSL Decryption for outbound SSL traffic.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When I upload the certificate, &lt;SPAN&gt;&lt;SPAN class="richTextArea slds-text-longform tile__title red-txt"&gt;notice the&amp;nbsp;missing icon that would indicate that the&amp;nbsp;private key &lt;STRONG&gt;can&lt;/STRONG&gt; be exported&lt;/SPAN&gt;&lt;/SPAN&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="3.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56473i685885C4359D9648/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="3.png" alt="3.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Now when I export the certificate, the firewall invite me to export the private key and the export is successful.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What's wrong?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Because for the Self Signed Certificate, the "The Block Private Key Export" option works fine as shown below:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Capture d'écran 2024-01-12 230321.png" style="width: 854px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56474i9F136DCBE2FD7999/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Capture d'écran 2024-01-12 230321.png" alt="Capture d'écran 2024-01-12 230321.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="6.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56475i3C2852EABC0E3362/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="6.png" alt="6.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jan 2024 22:10:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/quot-the-block-private-key-export-quot-option-strange-behavior/m-p/572914#M2424</guid>
      <dc:creator>rmeddane</dc:creator>
      <dc:date>2024-01-12T22:10:57Z</dc:date>
    </item>
  </channel>
</rss>

