<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Certificate SSL Self Signed Expired GP SSL-TLS Profile Global Protect in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/certificate-ssl-self-signed-expired-gp-ssl-tls-profile-global/m-p/526863#M108882</link>
    <description>&lt;P&gt;As&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/77347"&gt;@TomYoung&lt;/a&gt;&amp;nbsp;suggested.&lt;/P&gt;
&lt;P&gt;1. Generate new CA cert on Palo.&lt;/P&gt;
&lt;P&gt;2. Push it to clients.&lt;/P&gt;
&lt;P&gt;3. Generate new cert and sign with CA cert from step 1.&lt;/P&gt;
&lt;P&gt;4. Configure new cert for portal and gateway.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Raido_Rattameister_0-1673567182597.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/46962i387273111EC588B4/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Raido_Rattameister_0-1673567182597.png" alt="Raido_Rattameister_0-1673567182597.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 12 Jan 2023 23:46:31 GMT</pubDate>
    <dc:creator>Raido_Rattameister</dc:creator>
    <dc:date>2023-01-12T23:46:31Z</dc:date>
    <item>
      <title>Certificate SSL Self Signed Expired GP SSL-TLS Profile Global Protect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/certificate-ssl-self-signed-expired-gp-ssl-tls-profile-global/m-p/526850#M108880</link>
      <description>&lt;P class=""&gt;Hello Live Community,&amp;nbsp;how are you doing?&lt;/P&gt;
&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=""&gt;I have the following doubt and concern&lt;/P&gt;
&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=""&gt;If I have a PA configured with a Self Signed SSL certificate for Global Protect use, SSL/TLS profile for GP, and that certificate is is close to expiring.&lt;/P&gt;
&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=""&gt;All the workstations that have the global protect client, have the certificate installed, so that it is recognized as a trusted entity, in the computers (since it is self-signed by the same PA).&lt;/P&gt;
&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=""&gt;Now if I renew that certificate Self-Signed in the Palo Alto Networks Firewall, will I have to download and reinstall that certificate on each workstation?&lt;/P&gt;
&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=""&gt;Granted, it's not best practice, but some clients, for better or worse, have it that way.&lt;/P&gt;
&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I think and I want to confirm, in theory I think that when the renewal is done there will be a change, it will cause a change in the self-signed certificate in the FW PA, as is the extension of its period of validity, therefore I think that when the certificate expires and if not installed the certificate that has the time renewal, will not allow the connection to the workstations with the Global Protect client installed, therefore I think if it will be necessary to download and install the certificate once the renewal is done.&lt;/P&gt;
&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=""&gt;Please your comments, suggestions, tips regarding&lt;/P&gt;
&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=""&gt;Thanks for your time&lt;/P&gt;
&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=""&gt;Cheers&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Jan 2023 22:21:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/certificate-ssl-self-signed-expired-gp-ssl-tls-profile-global/m-p/526850#M108880</guid>
      <dc:creator>Metgatz</dc:creator>
      <dc:date>2023-01-12T22:21:36Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate SSL Self Signed Expired GP SSL-TLS Profile Global Protect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/certificate-ssl-self-signed-expired-gp-ssl-tls-profile-global/m-p/526861#M108881</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/179185"&gt;@Metgatz&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You could generate the new cert in advance before you replace the current cert.&amp;nbsp; You will get a duplicate CN commit warning, but nothing will be broken.&amp;nbsp; You could then push the new CA to the clients to trust before the SSL/TLS Profile change.&amp;nbsp; You could even use the Trusted Root CA box under the Portal Agent tab to have GP install the new CA on the clients.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Thu, 12 Jan 2023 23:25:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/certificate-ssl-self-signed-expired-gp-ssl-tls-profile-global/m-p/526861#M108881</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-01-12T23:25:29Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate SSL Self Signed Expired GP SSL-TLS Profile Global Protect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/certificate-ssl-self-signed-expired-gp-ssl-tls-profile-global/m-p/526863#M108882</link>
      <description>&lt;P&gt;As&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/77347"&gt;@TomYoung&lt;/a&gt;&amp;nbsp;suggested.&lt;/P&gt;
&lt;P&gt;1. Generate new CA cert on Palo.&lt;/P&gt;
&lt;P&gt;2. Push it to clients.&lt;/P&gt;
&lt;P&gt;3. Generate new cert and sign with CA cert from step 1.&lt;/P&gt;
&lt;P&gt;4. Configure new cert for portal and gateway.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Raido_Rattameister_0-1673567182597.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/46962i387273111EC588B4/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Raido_Rattameister_0-1673567182597.png" alt="Raido_Rattameister_0-1673567182597.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Jan 2023 23:46:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/certificate-ssl-self-signed-expired-gp-ssl-tls-profile-global/m-p/526863#M108882</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-01-12T23:46:31Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate SSL Self Signed Expired GP SSL-TLS Profile Global Protect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/certificate-ssl-self-signed-expired-gp-ssl-tls-profile-global/m-p/550995#M112266</link>
      <description>&lt;P&gt;Hello &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/15603"&gt;@Raido_Rattameister&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;There is 2 option only We need to push the certificate through GPO only or install manually in the user computers. Am i correct? Is there any other way to push certificate?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jul 2023 05:21:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/certificate-ssl-self-signed-expired-gp-ssl-tls-profile-global/m-p/550995#M112266</guid>
      <dc:creator>KhaleelE</dc:creator>
      <dc:date>2023-07-26T05:21:33Z</dc:date>
    </item>
  </channel>
</rss>

