<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Certificate Expired Warning in Deploy but all certificates are good in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/certificate-expired-warning-in-deploy-but-all-certificates-are/m-p/996489#M122382</link>
    <description>&lt;P&gt;The Sub CA Certificate of our old internal PKI expired a few days ago. It didn't have any impact and wasn't a security risk, but today i cleaned everything up.&lt;/P&gt;
&lt;P&gt;Problem is, i still get a warning on one of our firewalls.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN&gt;Certificate %redacted% in shared expired on %redacted%&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;I triple checked the configuration and the new certificate i configured under &lt;STRONG&gt;Device - Certificate Management - Certificates&lt;/STRONG&gt;&amp;nbsp;for this Device is up and Valid.&lt;/P&gt;
&lt;P&gt;All other firewalls are now green over the whole board, just this one throws that warning. I also checked locally on the device and it got the new certificate and everything looks right.&lt;/P&gt;
&lt;P&gt;There could be a chance that there is a special configuration i can't see because over the years a good few admins worked on this firewall.&lt;/P&gt;
&lt;P&gt;Any Idea what it could be before i open a support case?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Edit: Forgot this: Version is 10.2.7-h6 (upgrading to h18 tonight)&lt;/P&gt;</description>
    <pubDate>Wed, 04 Dec 2024 13:41:51 GMT</pubDate>
    <dc:creator>Stellinger</dc:creator>
    <dc:date>2024-12-04T13:41:51Z</dc:date>
    <item>
      <title>Certificate Expired Warning in Deploy but all certificates are good</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/certificate-expired-warning-in-deploy-but-all-certificates-are/m-p/996489#M122382</link>
      <description>&lt;P&gt;The Sub CA Certificate of our old internal PKI expired a few days ago. It didn't have any impact and wasn't a security risk, but today i cleaned everything up.&lt;/P&gt;
&lt;P&gt;Problem is, i still get a warning on one of our firewalls.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN&gt;Certificate %redacted% in shared expired on %redacted%&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;I triple checked the configuration and the new certificate i configured under &lt;STRONG&gt;Device - Certificate Management - Certificates&lt;/STRONG&gt;&amp;nbsp;for this Device is up and Valid.&lt;/P&gt;
&lt;P&gt;All other firewalls are now green over the whole board, just this one throws that warning. I also checked locally on the device and it got the new certificate and everything looks right.&lt;/P&gt;
&lt;P&gt;There could be a chance that there is a special configuration i can't see because over the years a good few admins worked on this firewall.&lt;/P&gt;
&lt;P&gt;Any Idea what it could be before i open a support case?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Edit: Forgot this: Version is 10.2.7-h6 (upgrading to h18 tonight)&lt;/P&gt;</description>
      <pubDate>Wed, 04 Dec 2024 13:41:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/certificate-expired-warning-in-deploy-but-all-certificates-are/m-p/996489#M122382</guid>
      <dc:creator>Stellinger</dc:creator>
      <dc:date>2024-12-04T13:41:51Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate Expired Warning in Deploy but all certificates are good</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/certificate-expired-warning-in-deploy-but-all-certificates-are/m-p/997616#M122492</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/322047"&gt;@Stellinger&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Try running a&amp;nbsp;show configuration | match &amp;lt;certificate_name&amp;gt; in the CLI to see all the places the old cert was referenced. You can also try pulling up the config into a text editor to see where the cert is referenced as well.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Dec 2024 05:14:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/certificate-expired-warning-in-deploy-but-all-certificates-are/m-p/997616#M122492</guid>
      <dc:creator>JayGolf</dc:creator>
      <dc:date>2024-12-11T05:14:59Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate Expired Warning in Deploy but all certificates are good</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/certificate-expired-warning-in-deploy-but-all-certificates-are/m-p/997929#M122516</link>
      <description>&lt;P&gt;HI &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/322047"&gt;@Stellinger&lt;/a&gt; &lt;BR /&gt;&lt;BR /&gt;According to the warning, you have a multi vsys firewall where the cert is located in shared context and therefore (in theory) should be visible in all vsys. You wrote that you checked locally and the new cert is there. Sorry for the dumb question but you did look for the cert name of the expiration warning? If the configuration is pushed from panorama as far as I understood) you need to execute "show config pushed-tenplate | match &amp;lt;certname&amp;gt;" instead of "show configuration".&lt;/P&gt;</description>
      <pubDate>Thu, 12 Dec 2024 00:28:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/certificate-expired-warning-in-deploy-but-all-certificates-are/m-p/997929#M122516</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2024-12-12T00:28:20Z</dc:date>
    </item>
  </channel>
</rss>

