<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SCM GP User Certificate Renewal Process in Strata Cloud Manager</title>
    <link>https://live.paloaltonetworks.com/t5/strata-cloud-manager/scm-gp-user-certificate-renewal-process/m-p/1234272#M34</link>
    <description>&lt;DIV class="p-rich_text_section"&gt;The below are the steps to renew GP certificate for Prisma Access on Strata Cloud Manager&lt;/DIV&gt;
&lt;DIV class="p-rich_text_section"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="p-rich_text_section"&gt;&lt;EM&gt;*Note in this example we are using Azure as the IDP&lt;/EM&gt;&lt;/DIV&gt;
&lt;DIV class="p-rich_text_section"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;OL class="p-rich_text_list p-rich_text_list__ordered p-rich_text_list--nested" data-stringify-type="ordered-list" data-list-tree="true" data-indent="0" data-border="0"&gt;
&lt;LI data-stringify-indent="0" data-stringify-border="0"&gt;Make sure to delete the old certificate on the Azure SAML IdP side&lt;/LI&gt;
&lt;LI data-stringify-indent="0" data-stringify-border="0"&gt;Then export the new SAML metadata XML file (which has only the new certificate) from Azure IdP&lt;/LI&gt;
&lt;LI data-stringify-indent="0" data-stringify-border="0"&gt;In Strata Cloud Manager(SCM), navigate to Manage &amp;gt; Configurations &amp;gt; NGFW &amp;amp; Prisma Access &amp;gt; Identity Services &amp;gt; Authentication &amp;gt; Server Profiles &amp;gt; SAML, open the existing SAML profile which you use and click on "Import"&amp;nbsp; under Identity Provider Certificate, to import the new metadata XML file to the SCM console. Now save the SAML profile.&lt;/LI&gt;
&lt;LI data-stringify-indent="0" data-stringify-border="0"&gt;After that, navigate to Objects &amp;gt; Certificate Management to verify and confirm that the Azure SAML IdP certificate is automatically renewed.&lt;/LI&gt;
&lt;LI data-stringify-indent="0" data-stringify-border="0"&gt;Now do an '&lt;STRONG&gt;all-admin&lt;/STRONG&gt;' push to the Mobile Users template to ensure the update is propagated to the Prisma Access backend nodes&lt;/LI&gt;
&lt;/OL&gt;
&lt;DIV class="p-rich_text_section"&gt;&lt;EM&gt;(Note: All-admin push is needed, as it will show the changes done by 'System' since the new SAML certificate is extracted from the recently imported XML file)&lt;/EM&gt;&lt;/DIV&gt;</description>
    <pubDate>Thu, 17 Jul 2025 21:49:22 GMT</pubDate>
    <dc:creator>nayubi</dc:creator>
    <dc:date>2025-07-17T21:49:22Z</dc:date>
    <item>
      <title>SCM GP User Certificate Renewal Process</title>
      <link>https://live.paloaltonetworks.com/t5/strata-cloud-manager/scm-gp-user-certificate-renewal-process/m-p/1234272#M34</link>
      <description>&lt;DIV class="p-rich_text_section"&gt;The below are the steps to renew GP certificate for Prisma Access on Strata Cloud Manager&lt;/DIV&gt;
&lt;DIV class="p-rich_text_section"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="p-rich_text_section"&gt;&lt;EM&gt;*Note in this example we are using Azure as the IDP&lt;/EM&gt;&lt;/DIV&gt;
&lt;DIV class="p-rich_text_section"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;OL class="p-rich_text_list p-rich_text_list__ordered p-rich_text_list--nested" data-stringify-type="ordered-list" data-list-tree="true" data-indent="0" data-border="0"&gt;
&lt;LI data-stringify-indent="0" data-stringify-border="0"&gt;Make sure to delete the old certificate on the Azure SAML IdP side&lt;/LI&gt;
&lt;LI data-stringify-indent="0" data-stringify-border="0"&gt;Then export the new SAML metadata XML file (which has only the new certificate) from Azure IdP&lt;/LI&gt;
&lt;LI data-stringify-indent="0" data-stringify-border="0"&gt;In Strata Cloud Manager(SCM), navigate to Manage &amp;gt; Configurations &amp;gt; NGFW &amp;amp; Prisma Access &amp;gt; Identity Services &amp;gt; Authentication &amp;gt; Server Profiles &amp;gt; SAML, open the existing SAML profile which you use and click on "Import"&amp;nbsp; under Identity Provider Certificate, to import the new metadata XML file to the SCM console. Now save the SAML profile.&lt;/LI&gt;
&lt;LI data-stringify-indent="0" data-stringify-border="0"&gt;After that, navigate to Objects &amp;gt; Certificate Management to verify and confirm that the Azure SAML IdP certificate is automatically renewed.&lt;/LI&gt;
&lt;LI data-stringify-indent="0" data-stringify-border="0"&gt;Now do an '&lt;STRONG&gt;all-admin&lt;/STRONG&gt;' push to the Mobile Users template to ensure the update is propagated to the Prisma Access backend nodes&lt;/LI&gt;
&lt;/OL&gt;
&lt;DIV class="p-rich_text_section"&gt;&lt;EM&gt;(Note: All-admin push is needed, as it will show the changes done by 'System' since the new SAML certificate is extracted from the recently imported XML file)&lt;/EM&gt;&lt;/DIV&gt;</description>
      <pubDate>Thu, 17 Jul 2025 21:49:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/strata-cloud-manager/scm-gp-user-certificate-renewal-process/m-p/1234272#M34</guid>
      <dc:creator>nayubi</dc:creator>
      <dc:date>2025-07-17T21:49:22Z</dc:date>
    </item>
  </channel>
</rss>

