<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How do people manage certificates for the MGMT interface at scale? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-do-people-manage-certificates-for-the-mgmt-interface-at/m-p/590763#M117665</link>
    <description>&lt;P&gt;you created a DNS record for each FW you used the wildcard cert for or somehow used a wildcard cert for the ip address?&lt;/P&gt;</description>
    <pubDate>Sun, 30 Jun 2024 18:40:15 GMT</pubDate>
    <dc:creator>jeffrolc</dc:creator>
    <dc:date>2024-06-30T18:40:15Z</dc:date>
    <item>
      <title>How do people manage certificates for the MGMT interface at scale?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-do-people-manage-certificates-for-the-mgmt-interface-at/m-p/564843#M114281</link>
      <description>&lt;P&gt;Wondering how other manage the SSL/TLS Service profile that you attach under Device&amp;gt;Setup&amp;gt;Management&amp;gt;General Settings at any sort of scale.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We manage quite a few firewall, via panorama, and the intent would be for each firewall to have a unique certificate for this? Is there a way we can template this would using SCEP in some way? The hope would have been to use SCEP in someway so the firewall could auto renew itself. Or would we individually need an object for each template stack and have to manage numerous objects?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Im able to create a scep profile, generate a cert, create an ssl/tls service profile, at attach it to the management interface on the firewall itself and this works as intended. But I wouldnt want to have to individually go to all of our firewall and do this and have objects that arent controller by panorama.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Are people taking the route of either not attaching a cert to the management interface at all or possibly throwing a wildcard cert on it? Or are people creating individual certs signed by an enterprise CA and manually rotating them every X number of days/years?&lt;/P&gt;</description>
      <pubDate>Wed, 08 Nov 2023 17:22:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-do-people-manage-certificates-for-the-mgmt-interface-at/m-p/564843#M114281</guid>
      <dc:creator>Claw4609</dc:creator>
      <dc:date>2023-11-08T17:22:31Z</dc:date>
    </item>
    <item>
      <title>Re: How do people manage certificates for the MGMT interface at scale?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-do-people-manage-certificates-for-the-mgmt-interface-at/m-p/565954#M114412</link>
      <description>&lt;P&gt;I push the certs out from panorama but i've had to set the SSL-TLS-Profile and select the certificate locally along with setting the secure communications settings. I can't figure another way of doing it either.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Nov 2023 09:30:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-do-people-manage-certificates-for-the-mgmt-interface-at/m-p/565954#M114412</guid>
      <dc:creator>GLSparks</dc:creator>
      <dc:date>2023-11-16T09:30:01Z</dc:date>
    </item>
    <item>
      <title>Re: How do people manage certificates for the MGMT interface at scale?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-do-people-manage-certificates-for-the-mgmt-interface-at/m-p/565961#M114413</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/227075"&gt;@Claw4609&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I use a wildcard certificate and push it from Panorama.&amp;nbsp; It is in my "Global" template.&amp;nbsp; So, I change it once and push it to every NGFW.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The most common enterprise CA server is Microsoft.&amp;nbsp; It supports SCEP.&amp;nbsp; If you want unique certificates for each NGFW, you can go that route.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Thu, 16 Nov 2023 10:34:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-do-people-manage-certificates-for-the-mgmt-interface-at/m-p/565961#M114413</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-11-16T10:34:58Z</dc:date>
    </item>
    <item>
      <title>Re: How do people manage certificates for the MGMT interface at scale?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-do-people-manage-certificates-for-the-mgmt-interface-at/m-p/590763#M117665</link>
      <description>&lt;P&gt;you created a DNS record for each FW you used the wildcard cert for or somehow used a wildcard cert for the ip address?&lt;/P&gt;</description>
      <pubDate>Sun, 30 Jun 2024 18:40:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-do-people-manage-certificates-for-the-mgmt-interface-at/m-p/590763#M117665</guid>
      <dc:creator>jeffrolc</dc:creator>
      <dc:date>2024-06-30T18:40:15Z</dc:date>
    </item>
    <item>
      <title>Re: How do people manage certificates for the MGMT interface at scale?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-do-people-manage-certificates-for-the-mgmt-interface-at/m-p/590771#M117666</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/26722"&gt;@jeffrolc&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The wildcard cert is *.mydomain.com.&amp;nbsp; The is applied to the management interface.&amp;nbsp; I have DNS records for each NGFW management interface, e.g. fw01.mydomain.com, fw02.mydomain.com, etc.&amp;nbsp; As long as I bring up the FQDN in the browser, it trusts the wildcard certificate.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Sun, 30 Jun 2024 21:28:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-do-people-manage-certificates-for-the-mgmt-interface-at/m-p/590771#M117666</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2024-06-30T21:28:35Z</dc:date>
    </item>
  </channel>
</rss>

