<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Self-Signed Certificate Issues in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/self-signed-certificate-issues/m-p/565047#M114295</link>
    <description>&lt;P&gt;Hello everyone,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am trying to make a self-signed cert for use with Global-Protect in my lab. I go into Device, Certificates, Generate, give the cert a name, Root_GP_Cert, common name of 192.168.189.155 which is the WAN side IP Address. Click the Certificate Authority box and click ok. Then I click on Generate again, this time I use a different name, common name is 192.168.189.155 and I select the Root_GP_Cert in the Signed By drop-down box and I give a Certificate Attribute of IP Address 192.168.189.155 but it gives me the error of: &lt;SPAN class="ext-mb-text"&gt;Failed to insert certificate into configuration. Only self signed CA certificates can have identical subject and issuer fields.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I watch youtube videos and follow along, works for them, not for me! Suggestions? Really easy but can't figure it out! Thanks - Geoff&lt;/P&gt;</description>
    <pubDate>Fri, 10 Nov 2023 01:56:34 GMT</pubDate>
    <dc:creator>GWynn</dc:creator>
    <dc:date>2023-11-10T01:56:34Z</dc:date>
    <item>
      <title>Self-Signed Certificate Issues</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/self-signed-certificate-issues/m-p/565047#M114295</link>
      <description>&lt;P&gt;Hello everyone,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am trying to make a self-signed cert for use with Global-Protect in my lab. I go into Device, Certificates, Generate, give the cert a name, Root_GP_Cert, common name of 192.168.189.155 which is the WAN side IP Address. Click the Certificate Authority box and click ok. Then I click on Generate again, this time I use a different name, common name is 192.168.189.155 and I select the Root_GP_Cert in the Signed By drop-down box and I give a Certificate Attribute of IP Address 192.168.189.155 but it gives me the error of: &lt;SPAN class="ext-mb-text"&gt;Failed to insert certificate into configuration. Only self signed CA certificates can have identical subject and issuer fields.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I watch youtube videos and follow along, works for them, not for me! Suggestions? Really easy but can't figure it out! Thanks - Geoff&lt;/P&gt;</description>
      <pubDate>Fri, 10 Nov 2023 01:56:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/self-signed-certificate-issues/m-p/565047#M114295</guid>
      <dc:creator>GWynn</dc:creator>
      <dc:date>2023-11-10T01:56:34Z</dc:date>
    </item>
    <item>
      <title>Re: Self-Signed Certificate Issues</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/self-signed-certificate-issues/m-p/565215#M114309</link>
      <description>&lt;P&gt;You need to get the naming convention correct. If you create a root authority on the PA, make the CN something like firewall.domain_root_ca.domain.com. Then when you click on it, you'll see the CN and issuer are the same. No other cert can have the name firewall1.domain.com_root_ca.domain.com or it will conflict with the common name of the root.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After you create the issuing authority, it can issue the cert you want to use for testing with the IP address as the CN.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do you not have internal PKI that can issue certificates for use on the PA? Whatever endpoint you'll use for testing won't trust the certificate bound for GP unless you export the root certificate from the PA and import on your test machine.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Nov 2023 21:33:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/self-signed-certificate-issues/m-p/565215#M114309</guid>
      <dc:creator>rmfalconer</dc:creator>
      <dc:date>2023-11-10T21:33:37Z</dc:date>
    </item>
    <item>
      <title>Re: Self-Signed Certificate Issues</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/self-signed-certificate-issues/m-p/565253#M114323</link>
      <description>&lt;P&gt;Hello &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/55733"&gt;@rmfalconer&lt;/a&gt; you are (as you know) correct! I watched a Beacon Module on this last night. Yes I was doing it wrong, even though on youtube I was following along. In any case, may thanks for replying and pointing me in the right direction!&lt;/P&gt;</description>
      <pubDate>Sun, 12 Nov 2023 05:51:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/self-signed-certificate-issues/m-p/565253#M114323</guid>
      <dc:creator>GWynn</dc:creator>
      <dc:date>2023-11-12T05:51:25Z</dc:date>
    </item>
  </channel>
</rss>

