<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PAN-OS 10.2 API key acquisition without password in URL? in Automation/API Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/pan-os-10-2-api-key-acquisition-without-password-in-url/m-p/513764#M3103</link>
    <description>&lt;P&gt;Giving the authentication information via body in a POST is still supported in PAN-OS v10.2.&amp;nbsp; Both the pan-os-python and pango libraries do it this way, and still supply the API key as part of the body in API requests.&lt;/P&gt;</description>
    <pubDate>Thu, 01 Sep 2022 17:58:24 GMT</pubDate>
    <dc:creator>gfreeman</dc:creator>
    <dc:date>2022-09-01T17:58:24Z</dc:date>
    <item>
      <title>PAN-OS 10.2 API key acquisition without password in URL?</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/pan-os-10-2-api-key-acquisition-without-password-in-url/m-p/513743#M3101</link>
      <description>&lt;P&gt;Is it possible to request an API key via&amp;nbsp;"&lt;SPAN&gt;/api/?type=keygen"&lt;/SPAN&gt; without providing the account password in the URL? This seems like a notable security issue since the URL is not encrypted. These pages suggest it is possible:&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-panorama-api/get-started-with-the-pan-os-xml-api/authenticate-your-api-requests" target="_blank" rel="noopener"&gt;Authenticate Your API Requests&lt;/A&gt;,&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-panorama-api/about-the-pan-os-xml-api/structure-of-a-pan-os-xml-api-request/api-authentication-and-security#id12582d9a-f80e-42c3-a028-2fdbb5ff0bdd" target="_blank" rel="noopener"&gt;API Authentication and Security&lt;/A&gt;. However, my testing of the "Authentication: Bearer" header via "&lt;SPAN&gt;/api/?type=keygen"&amp;nbsp;&lt;/SPAN&gt;results in an error about a missing user parameter.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Edit: Typing from memory - bad. That header should be "Authorization: Basic ..."&lt;/P&gt;</description>
      <pubDate>Thu, 01 Sep 2022 18:43:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/pan-os-10-2-api-key-acquisition-without-password-in-url/m-p/513743#M3101</guid>
      <dc:creator>SSargent_ICTWA</dc:creator>
      <dc:date>2022-09-01T18:43:56Z</dc:date>
    </item>
    <item>
      <title>Re: PAN-OS 10.2 API key acquisition without password in URL?</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/pan-os-10-2-api-key-acquisition-without-password-in-url/m-p/513764#M3103</link>
      <description>&lt;P&gt;Giving the authentication information via body in a POST is still supported in PAN-OS v10.2.&amp;nbsp; Both the pan-os-python and pango libraries do it this way, and still supply the API key as part of the body in API requests.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Sep 2022 17:58:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/pan-os-10-2-api-key-acquisition-without-password-in-url/m-p/513764#M3103</guid>
      <dc:creator>gfreeman</dc:creator>
      <dc:date>2022-09-01T17:58:24Z</dc:date>
    </item>
    <item>
      <title>Re: PAN-OS 10.2 API key acquisition without password in URL?</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/pan-os-10-2-api-key-acquisition-without-password-in-url/m-p/513776#M3104</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/46544"&gt;@gfreeman&lt;/a&gt;&amp;nbsp;Thanks for mentioning the POST/body option. I found the specifics in the third example here:&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-panorama-api/about-the-pan-os-xml-api/structure-of-a-pan-os-xml-api-request" target="_blank"&gt;Structure of a PAN-OS XML API Request&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Sep 2022 19:00:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/pan-os-10-2-api-key-acquisition-without-password-in-url/m-p/513776#M3104</guid>
      <dc:creator>SSargent_ICTWA</dc:creator>
      <dc:date>2022-09-01T19:00:02Z</dc:date>
    </item>
  </channel>
</rss>

