<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic MANDATORY ACTION REQUIRED: Device Certificate Enforcement affects PA-440 in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/mandatory-action-required-device-certificate-enforcement-affects/m-p/1244777#M125773</link>
    <description>&lt;P&gt;Hi everyone,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have a pair of PA-440 and when we login to the dashbaord we are greeted with a notification on the Device Certificate enforcement (I have attached a screenshot of the warning).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When I have gone through the Customer advisory they clearly stated that the PA-4xx series are not affected by this enforcement.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Now we do have the following CDSS features like (Threat prevention, URL filtering, Global Protect, and More) where they all will expire on Jul 2026.&lt;/P&gt;
&lt;P&gt;Besides there is an active and valid Device certificate in the Status Tab.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Now my questions are here:&lt;BR /&gt;1. is PA-440 affected by this?&lt;BR /&gt;2. are there any additional methods for me to confirm they are not affected as safeguard?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you.&lt;/P&gt;
&lt;P&gt;Looking forward to hearing from you.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 02 Jan 2026 09:19:00 GMT</pubDate>
    <dc:creator>S.Alizada</dc:creator>
    <dc:date>2026-01-02T09:19:00Z</dc:date>
    <item>
      <title>MANDATORY ACTION REQUIRED: Device Certificate Enforcement affects PA-440</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/mandatory-action-required-device-certificate-enforcement-affects/m-p/1244777#M125773</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have a pair of PA-440 and when we login to the dashbaord we are greeted with a notification on the Device Certificate enforcement (I have attached a screenshot of the warning).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When I have gone through the Customer advisory they clearly stated that the PA-4xx series are not affected by this enforcement.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Now we do have the following CDSS features like (Threat prevention, URL filtering, Global Protect, and More) where they all will expire on Jul 2026.&lt;/P&gt;
&lt;P&gt;Besides there is an active and valid Device certificate in the Status Tab.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Now my questions are here:&lt;BR /&gt;1. is PA-440 affected by this?&lt;BR /&gt;2. are there any additional methods for me to confirm they are not affected as safeguard?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you.&lt;/P&gt;
&lt;P&gt;Looking forward to hearing from you.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Jan 2026 09:19:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/mandatory-action-required-device-certificate-enforcement-affects/m-p/1244777#M125773</guid>
      <dc:creator>S.Alizada</dc:creator>
      <dc:date>2026-01-02T09:19:00Z</dc:date>
    </item>
    <item>
      <title>Re: MANDATORY ACTION REQUIRED: Device Certificate Enforcement affects PA-440</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/mandatory-action-required-device-certificate-enforcement-affects/m-p/1244786#M125774</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/374392237"&gt;@S.Alizada&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P data-start="155" data-end="384"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-start="161" data-end="390"&gt;The notification banner you’re seeing is a generic, global message and isn’t dynamically filtered by platform type, which is why it can still appear on models like the PA-440 that are explicitly excluded from enforcement.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P data-start="392" data-end="580"&gt;The PA-440 is not subject to the Device Certificate enforcement for CDSS, as it already uses the newer cert architecture with automated onboarding and renewal built into PAN-OS.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P data-start="582" data-end="910"&gt;Regarding the July 2026 expiry you’re seeing... that’s related to your CDSS subscription licenses, not the device cert. License duration and expiration controls which features you can use and for how long.&amp;nbsp;The device cert is used solely for secure authentication to PANW cloud services&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P data-start="912" data-end="1093"&gt;You’ve already confirmed that you have an active and valid device cert, so you’re good to go. If you’d like an extra sanity check, you can also verify the status via CLI:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;show device-certificate status
&lt;/LI-CODE&gt;
&lt;P data-start="912" data-end="1093"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-start="1135" data-end="1166"&gt;Hope this helps clarify things!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Jan 2026 16:17:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/mandatory-action-required-device-certificate-enforcement-affects/m-p/1244786#M125774</guid>
      <dc:creator>JayGolf</dc:creator>
      <dc:date>2026-01-02T16:17:41Z</dc:date>
    </item>
  </channel>
</rss>

