<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Understand the &amp;quot;Block Private Key Export&amp;quot; option with three scenarios in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/understand-the-quot-block-private-key-export-quot-option-with/m-p/572951#M2426</link>
    <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Capture d'écran 2024-01-13 155814.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56499i9E3D72733061063B/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Capture d'écran 2024-01-13 155814.png" alt="Capture d'écran 2024-01-13 155814.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The firewall uses a certificate with the role of CA Certificate of Authority to perform SSL Decryption for outbound traffic.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There are three methods to generate this certificate.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;STRONG&gt;Method 1&amp;nbsp;:&lt;/STRONG&gt; You can use a self-signed certificate. The firewall will generate a Certificate with the Public / Private keys automatically without involving an external CA.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL start="2"&gt;
&lt;LI&gt;&lt;STRONG&gt;Method 2&amp;nbsp;:&lt;/STRONG&gt; Using an external CA. The firewall generates a CSR Certificate Signed Request with the Public/Private keys, then you submit only the CSR / Public key, while the Private key is kept on the firewall, finally you upload the generate certificate with the embedded Public key.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL start="3"&gt;
&lt;LI&gt;&lt;STRONG&gt;Method 3&amp;nbsp;:&lt;/STRONG&gt; Using an external CA. You generate the CSR or the certifcate with the Public / Private keys. Then you upload the Certificate with the Public / Private Key.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The &lt;STRONG&gt;«&amp;nbsp;Block Private Key Export&amp;nbsp;»&lt;/STRONG&gt; option on the firewall allows the administrators to prevent rogue admins to export the private key, keeping it security on the firewall.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Let’s see with which method does the &lt;STRONG&gt;«&amp;nbsp;Block Private Key Export&amp;nbsp;»&lt;/STRONG&gt; work ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Method 1&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Generate a Self Signed Certificate, to be able to perform SSL Decryption for outbound traffic, check the &lt;STRONG&gt;Certificate Authority&lt;/STRONG&gt; option.&lt;/P&gt;
&lt;P&gt;To prevent the private key to be exported, check the &lt;STRONG&gt;Block Private Key Export&lt;/STRONG&gt; option.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rmeddane_0-1705158156795.jpeg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56484iAC762DDBC233F714/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="rmeddane_0-1705158156795.jpeg" alt="rmeddane_0-1705158156795.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The self signed certificate is generated automatically.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rmeddane_1-1705158156797.jpeg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56485iF138051D40E8FC6F/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="rmeddane_1-1705158156797.jpeg" alt="rmeddane_1-1705158156797.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Select the certificate and click on the &lt;STRONG&gt;Export Certficate&lt;/STRONG&gt; button.&lt;/P&gt;
&lt;P&gt;The firewall does not include the option to export the private key because the &lt;STRONG&gt;Block Private Key Export&lt;/STRONG&gt; option is enabled.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rmeddane_2-1705158156803.jpeg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56486iB4D3419852A6DF64/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="rmeddane_2-1705158156803.jpeg" alt="rmeddane_2-1705158156803.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Method 2&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Generate a Certificate Signing Request CSR using the option &lt;STRONG&gt;Signed by External Autthority (CSR) &lt;/STRONG&gt;and check the&lt;STRONG&gt; Block Private Key Export &lt;/STRONG&gt;option.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The CSR contains only the Public key, the Private key is kept in the firewall.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rmeddane_3-1705158156815.jpeg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56487i62DE7DC686471F2F/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="rmeddane_3-1705158156815.jpeg" alt="rmeddane_3-1705158156815.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The CSR is in the state of pending, waiting to submit it into an external CA.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Click the &lt;STRONG&gt;Export Certificate&lt;/STRONG&gt; button to export the CSR.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rmeddane_4-1705158156819.jpeg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56488i39A50456B16D82A6/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="rmeddane_4-1705158156819.jpeg" alt="rmeddane_4-1705158156819.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rmeddane_5-1705158156830.jpeg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56489i3CD2B9AE6F9F081C/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="rmeddane_5-1705158156830.jpeg" alt="rmeddane_5-1705158156830.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Access the CA-1 server, and submit the CSR, you need to select the Certificate Template &lt;STRONG&gt;Subordinate Certificate Authority&lt;/STRONG&gt; to make this certificate as a CA so that the firewall can use it to sign the spoofed server certificate.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rmeddane_6-1705158156839.jpeg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56491i9F8F703666458512/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="rmeddane_6-1705158156839.jpeg" alt="rmeddane_6-1705158156839.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Retrieve the generated certificate from the CA-1 server and click on the &lt;STRONG&gt;Import&lt;/STRONG&gt; button. In this scenario, the private key is kept the firewall so you dont need to use the Import Private Key option.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rmeddane_7-1705158156846.jpeg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56492i372D91C71CD67BFD/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="rmeddane_7-1705158156846.jpeg" alt="rmeddane_7-1705158156846.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Notice the icon below that indicates that the&amp;nbsp;private key cannot be exported.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rmeddane_8-1705158156848.jpeg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56490iCE049C614234A1DC/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="rmeddane_8-1705158156848.jpeg" alt="rmeddane_8-1705158156848.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But when you try to export the certificate, the firewall displays the option to export the Private key which confirms that the &lt;STRONG&gt;Block Private Key Export&lt;/STRONG&gt; option didnt work with this method.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rmeddane_9-1705158156855.jpeg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56494iC77AD72DCFE29F36/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="rmeddane_9-1705158156855.jpeg" alt="rmeddane_9-1705158156855.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Method 3&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Access the CA-2 server command line, generate a certificate with the role CA. The CA-2 server generates the certificate including the public key and the Private key. With this method, you need to import both the certificate and the Private key into the firewall.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rmeddane_10-1705158156859.jpeg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56493i5A8F3EDEC5F784CA/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="rmeddane_10-1705158156859.jpeg" alt="rmeddane_10-1705158156859.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Retrieves the Certifcate and the Private key as shown below.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rmeddane_11-1705158156860.jpeg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56495i50581DC4EAE5AEAF/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="rmeddane_11-1705158156860.jpeg" alt="rmeddane_11-1705158156860.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On the firewall, click the &lt;STRONG&gt;Import&lt;/STRONG&gt; button, locate the Certificate and the Private key files.&lt;/P&gt;
&lt;P&gt;Check the &lt;STRONG&gt;Block Private Key Export&lt;/STRONG&gt; option.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rmeddane_12-1705158156862.jpeg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56496i0144720FD7FA1650/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="rmeddane_12-1705158156862.jpeg" alt="rmeddane_12-1705158156862.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Notice the icon below that indicates that the&amp;nbsp;private key cannot be exported. Click the &lt;STRONG&gt;Export&lt;/STRONG&gt; &lt;STRONG&gt;Certifcate&lt;/STRONG&gt; button.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rmeddane_13-1705158156870.jpeg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56498i29AED97F2062E318/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="rmeddane_13-1705158156870.jpeg" alt="rmeddane_13-1705158156870.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Notice that the firewall does not allow to export the Private key because &lt;STRONG&gt;the Block Private Key Export&lt;/STRONG&gt; enabled.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rmeddane_14-1705158156874.jpeg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56497iAA467A95837479BF/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="rmeddane_14-1705158156874.jpeg" alt="rmeddane_14-1705158156874.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sat, 13 Jan 2024 15:18:29 GMT</pubDate>
    <dc:creator>rmeddane</dc:creator>
    <dc:date>2024-01-13T15:18:29Z</dc:date>
    <item>
      <title>Understand the "Block Private Key Export" option with three scenarios</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/understand-the-quot-block-private-key-export-quot-option-with/m-p/572951#M2426</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Capture d'écran 2024-01-13 155814.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56499i9E3D72733061063B/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Capture d'écran 2024-01-13 155814.png" alt="Capture d'écran 2024-01-13 155814.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The firewall uses a certificate with the role of CA Certificate of Authority to perform SSL Decryption for outbound traffic.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There are three methods to generate this certificate.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;STRONG&gt;Method 1&amp;nbsp;:&lt;/STRONG&gt; You can use a self-signed certificate. The firewall will generate a Certificate with the Public / Private keys automatically without involving an external CA.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL start="2"&gt;
&lt;LI&gt;&lt;STRONG&gt;Method 2&amp;nbsp;:&lt;/STRONG&gt; Using an external CA. The firewall generates a CSR Certificate Signed Request with the Public/Private keys, then you submit only the CSR / Public key, while the Private key is kept on the firewall, finally you upload the generate certificate with the embedded Public key.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL start="3"&gt;
&lt;LI&gt;&lt;STRONG&gt;Method 3&amp;nbsp;:&lt;/STRONG&gt; Using an external CA. You generate the CSR or the certifcate with the Public / Private keys. Then you upload the Certificate with the Public / Private Key.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The &lt;STRONG&gt;«&amp;nbsp;Block Private Key Export&amp;nbsp;»&lt;/STRONG&gt; option on the firewall allows the administrators to prevent rogue admins to export the private key, keeping it security on the firewall.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Let’s see with which method does the &lt;STRONG&gt;«&amp;nbsp;Block Private Key Export&amp;nbsp;»&lt;/STRONG&gt; work ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Method 1&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Generate a Self Signed Certificate, to be able to perform SSL Decryption for outbound traffic, check the &lt;STRONG&gt;Certificate Authority&lt;/STRONG&gt; option.&lt;/P&gt;
&lt;P&gt;To prevent the private key to be exported, check the &lt;STRONG&gt;Block Private Key Export&lt;/STRONG&gt; option.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rmeddane_0-1705158156795.jpeg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56484iAC762DDBC233F714/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="rmeddane_0-1705158156795.jpeg" alt="rmeddane_0-1705158156795.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The self signed certificate is generated automatically.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rmeddane_1-1705158156797.jpeg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56485iF138051D40E8FC6F/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="rmeddane_1-1705158156797.jpeg" alt="rmeddane_1-1705158156797.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Select the certificate and click on the &lt;STRONG&gt;Export Certficate&lt;/STRONG&gt; button.&lt;/P&gt;
&lt;P&gt;The firewall does not include the option to export the private key because the &lt;STRONG&gt;Block Private Key Export&lt;/STRONG&gt; option is enabled.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rmeddane_2-1705158156803.jpeg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56486iB4D3419852A6DF64/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="rmeddane_2-1705158156803.jpeg" alt="rmeddane_2-1705158156803.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Method 2&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Generate a Certificate Signing Request CSR using the option &lt;STRONG&gt;Signed by External Autthority (CSR) &lt;/STRONG&gt;and check the&lt;STRONG&gt; Block Private Key Export &lt;/STRONG&gt;option.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The CSR contains only the Public key, the Private key is kept in the firewall.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rmeddane_3-1705158156815.jpeg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56487i62DE7DC686471F2F/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="rmeddane_3-1705158156815.jpeg" alt="rmeddane_3-1705158156815.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The CSR is in the state of pending, waiting to submit it into an external CA.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Click the &lt;STRONG&gt;Export Certificate&lt;/STRONG&gt; button to export the CSR.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rmeddane_4-1705158156819.jpeg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56488i39A50456B16D82A6/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="rmeddane_4-1705158156819.jpeg" alt="rmeddane_4-1705158156819.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rmeddane_5-1705158156830.jpeg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56489i3CD2B9AE6F9F081C/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="rmeddane_5-1705158156830.jpeg" alt="rmeddane_5-1705158156830.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Access the CA-1 server, and submit the CSR, you need to select the Certificate Template &lt;STRONG&gt;Subordinate Certificate Authority&lt;/STRONG&gt; to make this certificate as a CA so that the firewall can use it to sign the spoofed server certificate.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rmeddane_6-1705158156839.jpeg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56491i9F8F703666458512/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="rmeddane_6-1705158156839.jpeg" alt="rmeddane_6-1705158156839.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Retrieve the generated certificate from the CA-1 server and click on the &lt;STRONG&gt;Import&lt;/STRONG&gt; button. In this scenario, the private key is kept the firewall so you dont need to use the Import Private Key option.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rmeddane_7-1705158156846.jpeg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56492i372D91C71CD67BFD/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="rmeddane_7-1705158156846.jpeg" alt="rmeddane_7-1705158156846.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Notice the icon below that indicates that the&amp;nbsp;private key cannot be exported.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rmeddane_8-1705158156848.jpeg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56490iCE049C614234A1DC/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="rmeddane_8-1705158156848.jpeg" alt="rmeddane_8-1705158156848.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But when you try to export the certificate, the firewall displays the option to export the Private key which confirms that the &lt;STRONG&gt;Block Private Key Export&lt;/STRONG&gt; option didnt work with this method.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rmeddane_9-1705158156855.jpeg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56494iC77AD72DCFE29F36/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="rmeddane_9-1705158156855.jpeg" alt="rmeddane_9-1705158156855.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Method 3&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Access the CA-2 server command line, generate a certificate with the role CA. The CA-2 server generates the certificate including the public key and the Private key. With this method, you need to import both the certificate and the Private key into the firewall.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rmeddane_10-1705158156859.jpeg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56493i5A8F3EDEC5F784CA/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="rmeddane_10-1705158156859.jpeg" alt="rmeddane_10-1705158156859.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Retrieves the Certifcate and the Private key as shown below.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rmeddane_11-1705158156860.jpeg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56495i50581DC4EAE5AEAF/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="rmeddane_11-1705158156860.jpeg" alt="rmeddane_11-1705158156860.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On the firewall, click the &lt;STRONG&gt;Import&lt;/STRONG&gt; button, locate the Certificate and the Private key files.&lt;/P&gt;
&lt;P&gt;Check the &lt;STRONG&gt;Block Private Key Export&lt;/STRONG&gt; option.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rmeddane_12-1705158156862.jpeg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56496i0144720FD7FA1650/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="rmeddane_12-1705158156862.jpeg" alt="rmeddane_12-1705158156862.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Notice the icon below that indicates that the&amp;nbsp;private key cannot be exported. Click the &lt;STRONG&gt;Export&lt;/STRONG&gt; &lt;STRONG&gt;Certifcate&lt;/STRONG&gt; button.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rmeddane_13-1705158156870.jpeg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56498i29AED97F2062E318/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="rmeddane_13-1705158156870.jpeg" alt="rmeddane_13-1705158156870.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Notice that the firewall does not allow to export the Private key because &lt;STRONG&gt;the Block Private Key Export&lt;/STRONG&gt; enabled.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rmeddane_14-1705158156874.jpeg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56497iAA467A95837479BF/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="rmeddane_14-1705158156874.jpeg" alt="rmeddane_14-1705158156874.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 13 Jan 2024 15:18:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/understand-the-quot-block-private-key-export-quot-option-with/m-p/572951#M2426</guid>
      <dc:creator>rmeddane</dc:creator>
      <dc:date>2024-01-13T15:18:29Z</dc:date>
    </item>
  </channel>
</rss>

