<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Renewing a Subordinate CA Certificate for firewall, issued by MS Server Enterprise CA in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/renewing-a-subordinate-ca-certificate-for-firewall-issued-by-ms/m-p/445660#M100492</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/105682"&gt;@tonyrobson&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;I don't&amp;nbsp;&lt;I&gt;believe&amp;nbsp;&lt;/I&gt;you really have many options to properly renew a sub-ca. I personally wouldn't have done what you did and use the same certificate name, instead using a new certificate name so that the current certificate and the new certificate a distinctly different things from the firewall's perspective. This allows you to begin transitioning to the new certificate while maintaining the old certificate until everything has been migrated over or it expires.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 05 Nov 2021 03:10:15 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2021-11-05T03:10:15Z</dc:date>
    <item>
      <title>Renewing a Subordinate CA Certificate for firewall, issued by MS Server Enterprise CA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/renewing-a-subordinate-ca-certificate-for-firewall-issued-by-ms/m-p/445526#M100481</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've been looking all over for some guidance on this, without much joy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am trying to renew a subordinate-CA certificate on a firewall, that was issued by a Windows Server Enterprise CA.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Obviously there is no Renew function on the firewall for that cert as it was externally issued - and it appears on Windows server you can only renew Subordinate-CA certificates for domain servers (I think?).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So based on the above, I generated a new certificate request, matching the name of the original (the certificate then shows as pending), and went through the signing process the same as last time and re-imported.&amp;nbsp; The certificate shows as having the expected new date and shows as valid, the chain hierarchy remains intact in the GUI, however, all the certificates signed by the previous certificate no longer work at all, for any function, SSL Decryption, GlobalProtect, Secure comms etc, and all need to be re-issued/signed by the new certificate.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So I dugout the original certificate request from a few years ago, and tried to submit that instead, and it also seems to present me with a new certificate rather than one maintaining the serial number.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;So what is the process to renew the certificate without invalidating the signed certificates?&lt;/P&gt;</description>
      <pubDate>Thu, 04 Nov 2021 18:40:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/renewing-a-subordinate-ca-certificate-for-firewall-issued-by-ms/m-p/445526#M100481</guid>
      <dc:creator>tonyrobson</dc:creator>
      <dc:date>2021-11-04T18:40:28Z</dc:date>
    </item>
    <item>
      <title>Re: Renewing a Subordinate CA Certificate for firewall, issued by MS Server Enterprise CA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/renewing-a-subordinate-ca-certificate-for-firewall-issued-by-ms/m-p/445660#M100492</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/105682"&gt;@tonyrobson&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;I don't&amp;nbsp;&lt;I&gt;believe&amp;nbsp;&lt;/I&gt;you really have many options to properly renew a sub-ca. I personally wouldn't have done what you did and use the same certificate name, instead using a new certificate name so that the current certificate and the new certificate a distinctly different things from the firewall's perspective. This allows you to begin transitioning to the new certificate while maintaining the old certificate until everything has been migrated over or it expires.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Nov 2021 03:10:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/renewing-a-subordinate-ca-certificate-for-firewall-issued-by-ms/m-p/445660#M100492</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2021-11-05T03:10:15Z</dc:date>
    </item>
    <item>
      <title>Re: Renewing a Subordinate CA Certificate for firewall, issued by MS Server Enterprise CA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/renewing-a-subordinate-ca-certificate-for-firewall-issued-by-ms/m-p/445782#M100501</link>
      <description>&lt;P&gt;Actually I've found an advantage to using the original CSR; you can renew the child certificates then using the renew button, compared to when you use a new CSR for the Sub-CA, whenever you try renew the child certs it can't sign then, presumably because of the private key change, so you have to generate new certificates individually for each one, doing all the attributes again and typing out names to match etc.&amp;nbsp; If you use the Sub-CA with the original CSR though it allows a single click renew, much quicker and easier.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Nov 2021 15:01:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/renewing-a-subordinate-ca-certificate-for-firewall-issued-by-ms/m-p/445782#M100501</guid>
      <dc:creator>tonyrobson</dc:creator>
      <dc:date>2021-11-05T15:01:24Z</dc:date>
    </item>
  </channel>
</rss>

