<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Best Practice for Managing Short-Lived Public Certificates on Panorama-Managed Firewalls? in Panorama Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/panorama-discussions/best-practice-for-managing-short-lived-public-certificates-on/m-p/1259373#M3123</link>
    <description>&lt;P&gt;Hi everyone,&lt;/P&gt;
&lt;P&gt;With the industry moving toward shorter validity periods for publicly issued SSL/TLS certificates, I'm trying to plan ahead for certificate management on our Palo Alto firewalls.&lt;/P&gt;
&lt;P&gt;We have several firewalls that are managed through Panorama, and some of them will also be using SAML for authentication. Since public certificates will need to be renewed more frequently, I'm looking for the most efficient way to handle the certificate replacement process across multiple devices.&lt;/P&gt;
&lt;P&gt;I've come across a few discussions describing different methods, but many of them are older or use different deployment scenarios. Before implementing anything, I'd like to hear how others are approaching this today.&lt;/P&gt;
&lt;P&gt;A few questions I have:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;
&lt;P&gt;What is the current best practice for updating certificates on Panorama-managed firewalls?&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Are you automating certificate deployment and renewal? If so, what tools or workflows are you using?&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;For SAML integrations, are there any considerations or common pitfalls when replacing certificates regularly?&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Has anyone successfully integrated ACME or another automated certificate management solution with PAN-OS?&lt;/P&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;I'd appreciate hearing about real-world experiences and any recommendations that have helped reduce the operational overhead.&lt;/P&gt;
&lt;P&gt;Thanks in advance!&lt;/P&gt;</description>
    <pubDate>Mon, 20 Jul 2026 12:22:31 GMT</pubDate>
    <dc:creator>kosarbnu</dc:creator>
    <dc:date>2026-07-20T12:22:31Z</dc:date>
    <item>
      <title>Best Practice for Managing Short-Lived Public Certificates on Panorama-Managed Firewalls?</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/best-practice-for-managing-short-lived-public-certificates-on/m-p/1259373#M3123</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;
&lt;P&gt;With the industry moving toward shorter validity periods for publicly issued SSL/TLS certificates, I'm trying to plan ahead for certificate management on our Palo Alto firewalls.&lt;/P&gt;
&lt;P&gt;We have several firewalls that are managed through Panorama, and some of them will also be using SAML for authentication. Since public certificates will need to be renewed more frequently, I'm looking for the most efficient way to handle the certificate replacement process across multiple devices.&lt;/P&gt;
&lt;P&gt;I've come across a few discussions describing different methods, but many of them are older or use different deployment scenarios. Before implementing anything, I'd like to hear how others are approaching this today.&lt;/P&gt;
&lt;P&gt;A few questions I have:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;
&lt;P&gt;What is the current best practice for updating certificates on Panorama-managed firewalls?&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Are you automating certificate deployment and renewal? If so, what tools or workflows are you using?&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;For SAML integrations, are there any considerations or common pitfalls when replacing certificates regularly?&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Has anyone successfully integrated ACME or another automated certificate management solution with PAN-OS?&lt;/P&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;I'd appreciate hearing about real-world experiences and any recommendations that have helped reduce the operational overhead.&lt;/P&gt;
&lt;P&gt;Thanks in advance!&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jul 2026 12:22:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/best-practice-for-managing-short-lived-public-certificates-on/m-p/1259373#M3123</guid>
      <dc:creator>kosarbnu</dc:creator>
      <dc:date>2026-07-20T12:22:31Z</dc:date>
    </item>
  </channel>
</rss>

