<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Change forward decrypt trust cert to a new one. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/change-forward-decrypt-trust-cert-to-a-new-one/m-p/528252#M109084</link>
    <description>&lt;P&gt;You don't need to "deselect and commit".&lt;/P&gt;
&lt;P&gt;Just change cert and commit will work (at least worked on my lab / pan-os 10.1.6-h6)&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Image 001.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/47350i3003FE41D02EB884/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Image 001.png" alt="Image 001.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 24 Jan 2023 00:42:19 GMT</pubDate>
    <dc:creator>emr_1</dc:creator>
    <dc:date>2023-01-24T00:42:19Z</dc:date>
    <item>
      <title>Change forward decrypt trust cert to a new one.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/change-forward-decrypt-trust-cert-to-a-new-one/m-p/528249#M109083</link>
      <description>&lt;P&gt;I have forward ssl decrypt running and I want to change the cert I use. Can only have one forward trust cert at a time. If I deselect forward trust box I get commit error because my ssl decrypt policies don't have a forward trust cert. I can't select forward trust on the new cert until the old cert has forward trust deselected.&lt;/P&gt;
&lt;P&gt;So now what do I do? Thanks.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jan 2023 00:18:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/change-forward-decrypt-trust-cert-to-a-new-one/m-p/528249#M109083</guid>
      <dc:creator>djon</dc:creator>
      <dc:date>2023-01-24T00:18:14Z</dc:date>
    </item>
    <item>
      <title>Re: Change forward decrypt trust cert to a new one.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/change-forward-decrypt-trust-cert-to-a-new-one/m-p/528252#M109084</link>
      <description>&lt;P&gt;You don't need to "deselect and commit".&lt;/P&gt;
&lt;P&gt;Just change cert and commit will work (at least worked on my lab / pan-os 10.1.6-h6)&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Image 001.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/47350i3003FE41D02EB884/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Image 001.png" alt="Image 001.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jan 2023 00:42:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/change-forward-decrypt-trust-cert-to-a-new-one/m-p/528252#M109084</guid>
      <dc:creator>emr_1</dc:creator>
      <dc:date>2023-01-24T00:42:19Z</dc:date>
    </item>
    <item>
      <title>Re: Change forward decrypt trust cert to a new one.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/change-forward-decrypt-trust-cert-to-a-new-one/m-p/528422#M109110</link>
      <description>&lt;P&gt;Thanks for response. I am not able to select Forward Trust Cert option.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="djon_0-1674597524676.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/47380i157F2F121C79F6AE/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="djon_0-1674597524676.png" alt="djon_0-1674597524676.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;The new cert is the Issuing CA Trusted Root chained from the Root CA if this makes ant sense.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jan 2023 22:12:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/change-forward-decrypt-trust-cert-to-a-new-one/m-p/528422#M109110</guid>
      <dc:creator>djon</dc:creator>
      <dc:date>2023-01-24T22:12:27Z</dc:date>
    </item>
    <item>
      <title>Re: Change forward decrypt trust cert to a new one.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/change-forward-decrypt-trust-cert-to-a-new-one/m-p/528439#M109113</link>
      <description>&lt;P&gt;Do you have private key for it?&lt;/P&gt;
&lt;P&gt;Following two screenshots are sample that shows what happens if you did not import private key ( looks same as your result):&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Image 001.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/47382iFC91CC65BB057593/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Image 001.png" alt="Image 001.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Image 002.png" style="width: 606px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/47383i63FFCF8ED90330E9/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Image 002.png" alt="Image 002.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2023 00:38:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/change-forward-decrypt-trust-cert-to-a-new-one/m-p/528439#M109113</guid>
      <dc:creator>emr_1</dc:creator>
      <dc:date>2023-01-25T00:38:31Z</dc:date>
    </item>
    <item>
      <title>Re: Change forward decrypt trust cert to a new one.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/change-forward-decrypt-trust-cert-to-a-new-one/m-p/528458#M109115</link>
      <description>&lt;P&gt;No priv. key. We are making a new cert from our CA and including keys so we can d/l the cert and key. We just have to figure the flavor of cert (usage etc). We made the current one so we should be able to make a new one. Thanks for the tip on needing the priv key to qual for Forward trust.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2023 02:08:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/change-forward-decrypt-trust-cert-to-a-new-one/m-p/528458#M109115</guid>
      <dc:creator>djon</dc:creator>
      <dc:date>2023-01-25T02:08:27Z</dc:date>
    </item>
  </channel>
</rss>

