<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Trying to understand how a certificate profile is used for External Dynamic Lists (EDL) in Panorama Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/panorama-discussions/trying-to-understand-how-a-certificate-profile-is-used-for/m-p/555527#M1782</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/118216"&gt;@SteveBallantyne&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The phrase "certificate profile" in my opinion is not a very good description.&amp;nbsp; Certificate profiles contain the CA certificates that were used to create the certificate being verified, in this case the EDL server.&amp;nbsp; It is a way to verify no one has tampered with the EDL site.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For an EDL, you would browse to the site, examine the certificate, and download the CA certificates in the chain.&amp;nbsp; Install them on your NGFW, and add them to your certificate profile.&amp;nbsp; When the NGFW goes to the EDL, it says, "Yep.&amp;nbsp; That is the correct certificate."&amp;nbsp; I don't see it as a critical security feature, but I like to get rid of my commit warnings.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Some versions of PAN-OS have had issues with the EDL certificate profile working.&amp;nbsp; I am on 10.2.4, and they are working fine.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
    <pubDate>Mon, 28 Aug 2023 14:37:30 GMT</pubDate>
    <dc:creator>TomYoung</dc:creator>
    <dc:date>2023-08-28T14:37:30Z</dc:date>
    <item>
      <title>Trying to understand how a certificate profile is used for External Dynamic Lists (EDL)</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/trying-to-understand-how-a-certificate-profile-is-used-for/m-p/555520#M1776</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;
&lt;P&gt;I currently have an issue with my firewalls not downloading External Dynamic Lists. Seems to be a certificate profile issue that arose from migrating into Panorama. I am guessing something went wonky with importing the certs, and then pushing them back out to the devices in a device template. I am still working on that!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But can someone help me understand this concept of using a device hosted certificate to retrieve data from an SSL connection? It seems to me that the server you are connecting to has it's own certificate and that is what is being used to set up a secure connection and retrieve the data. How would my self-signed or internally CA signed certificate even be used in that conversation between the PA device and the SSL server?&lt;/P&gt;</description>
      <pubDate>Mon, 28 Aug 2023 13:40:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/trying-to-understand-how-a-certificate-profile-is-used-for/m-p/555520#M1776</guid>
      <dc:creator>SteveBallantyne</dc:creator>
      <dc:date>2023-08-28T13:40:25Z</dc:date>
    </item>
    <item>
      <title>Re: Trying to understand how a certificate profile is used for External Dynamic Lists (EDL)</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/trying-to-understand-how-a-certificate-profile-is-used-for/m-p/555523#M1778</link>
      <description>&lt;P&gt;Maybe I am just a bonehead ... I thought that the EDL *required* a certificate profile. But I was able to change it to "None", commit, push, etc. And now the lists work fine. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Turns out that it DOESN'T make sense to use a self-signed device certificate in this case!&lt;/P&gt;</description>
      <pubDate>Mon, 28 Aug 2023 14:13:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/trying-to-understand-how-a-certificate-profile-is-used-for/m-p/555523#M1778</guid>
      <dc:creator>SteveBallantyne</dc:creator>
      <dc:date>2023-08-28T14:13:38Z</dc:date>
    </item>
    <item>
      <title>Re: Trying to understand how a certificate profile is used for External Dynamic Lists (EDL)</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/trying-to-understand-how-a-certificate-profile-is-used-for/m-p/555527#M1782</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/118216"&gt;@SteveBallantyne&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The phrase "certificate profile" in my opinion is not a very good description.&amp;nbsp; Certificate profiles contain the CA certificates that were used to create the certificate being verified, in this case the EDL server.&amp;nbsp; It is a way to verify no one has tampered with the EDL site.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For an EDL, you would browse to the site, examine the certificate, and download the CA certificates in the chain.&amp;nbsp; Install them on your NGFW, and add them to your certificate profile.&amp;nbsp; When the NGFW goes to the EDL, it says, "Yep.&amp;nbsp; That is the correct certificate."&amp;nbsp; I don't see it as a critical security feature, but I like to get rid of my commit warnings.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Some versions of PAN-OS have had issues with the EDL certificate profile working.&amp;nbsp; I am on 10.2.4, and they are working fine.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Mon, 28 Aug 2023 14:37:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/trying-to-understand-how-a-certificate-profile-is-used-for/m-p/555527#M1782</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-08-28T14:37:30Z</dc:date>
    </item>
    <item>
      <title>Re: Trying to understand how a certificate profile is used for External Dynamic Lists (EDL)</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/trying-to-understand-how-a-certificate-profile-is-used-for/m-p/555529#M1784</link>
      <description>&lt;P&gt;Thank you, Tom. What you said makes perfect sense, and it also explains why in the drop-down for certificates to use inside the certificate profile are only certificates in which there is a private key.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Aug 2023 14:42:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/trying-to-understand-how-a-certificate-profile-is-used-for/m-p/555529#M1784</guid>
      <dc:creator>SteveBallantyne</dc:creator>
      <dc:date>2023-08-28T14:42:31Z</dc:date>
    </item>
    <item>
      <title>Re: Trying to understand how a certificate profile is used for External Dynamic Lists (EDL)</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/trying-to-understand-how-a-certificate-profile-is-used-for/m-p/555530#M1785</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/118216"&gt;@SteveBallantyne&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Probably because the only CA certificates on your NGFW contain private keys.&amp;nbsp; It only allows CA certificates to be installed.&amp;nbsp; You can add public CA certificates with no private key.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Mon, 28 Aug 2023 14:45:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/trying-to-understand-how-a-certificate-profile-is-used-for/m-p/555530#M1785</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-08-28T14:45:06Z</dc:date>
    </item>
  </channel>
</rss>

