<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic unable to change the web-gui certificate in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-change-the-web-gui-certificate/m-p/15725#M11502</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi ,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;recently i wanted to changed the web-gui certificate i followed the procedure on how to create a certificate in openssl ( for panos 4.x) the certificate created successfully. i event imported into the appliance but whenever i click on the checkbox &lt;STRONG&gt;Certificate for Secure Web GUI &lt;/STRONG&gt;i receive the following error &lt;STRONG&gt;system -&amp;gt; web-server-certificate 'cert' is not a valid reference, &lt;/STRONG&gt;do i have to upload the main CA cert before uploading the certificate i created ?...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;appreciate the help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BR&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 17 Nov 2013 18:21:12 GMT</pubDate>
    <dc:creator>LCMember4717</dc:creator>
    <dc:date>2013-11-17T18:21:12Z</dc:date>
    <item>
      <title>unable to change the web-gui certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-change-the-web-gui-certificate/m-p/15725#M11502</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi ,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;recently i wanted to changed the web-gui certificate i followed the procedure on how to create a certificate in openssl ( for panos 4.x) the certificate created successfully. i event imported into the appliance but whenever i click on the checkbox &lt;STRONG&gt;Certificate for Secure Web GUI &lt;/STRONG&gt;i receive the following error &lt;STRONG&gt;system -&amp;gt; web-server-certificate 'cert' is not a valid reference, &lt;/STRONG&gt;do i have to upload the main CA cert before uploading the certificate i created ?...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;appreciate the help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BR&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 17 Nov 2013 18:21:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-change-the-web-gui-certificate/m-p/15725#M11502</guid>
      <dc:creator>LCMember4717</dc:creator>
      <dc:date>2013-11-17T18:21:12Z</dc:date>
    </item>
    <item>
      <title>Re: unable to change the web-gui certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-change-the-web-gui-certificate/m-p/15726#M11503</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Fahad,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;You may want to ensure that they imported both keys. If you just imported the public key (certificate) it won't work. We need the private key to be able to be able to encrypt outbound data. &lt;/SPAN&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 10pt; line-height: 1.5em;"&gt;Verify that the certificate you are importing is of the same key length/type and has the similar hash algorithm to the one generated by the firewall.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;The certificate should be RSA 2048 with SHA1 hash.&amp;nbsp; The firewall generates certificates with usage as: Digital Signature, Key Encipherment, Key Agreement, Certificate Signing, Off-line CRL Signing, CRL Signing (ae)&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;Hope that helps!&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;Thanks and regards,&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;Kunal Adak &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Nov 2013 19:25:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-change-the-web-gui-certificate/m-p/15726#M11503</guid>
      <dc:creator>kadak</dc:creator>
      <dc:date>2013-11-18T19:25:58Z</dc:date>
    </item>
    <item>
      <title>Re: unable to change the web-gui certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-change-the-web-gui-certificate/m-p/15727#M11504</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You will need the root certificate.&amp;nbsp; You can export this from SSL, it will only be the public key but that is ok, import it into the Palo Alto and mark it as a trusted root ca.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 14 Dec 2013 01:00:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-change-the-web-gui-certificate/m-p/15727#M11504</guid>
      <dc:creator>JimS2</dc:creator>
      <dc:date>2013-12-14T01:00:16Z</dc:date>
    </item>
  </channel>
</rss>

