<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic is it possible to add a CA in PA device? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-add-a-ca-in-pa-device/m-p/24977#M18220</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello there. &lt;/P&gt;&lt;P&gt;I have a question related to CA for SSL client. &lt;/P&gt;&lt;P&gt;Customer has a certificate which issued by Trusted Root CA, but this trusted root CA is not contained in an ssl client's browser.&lt;/P&gt;&lt;P&gt;And then, the customer certificate was issued by this CA.&lt;/P&gt;&lt;P&gt;So, customer wants to distribute a CA of customer for all SSL VPN clients to avoid ssl certification error. (it was not created by a PA device.)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried to import to the CA at certificates in Device tab, but it&amp;nbsp; was impossible. &lt;/P&gt;&lt;P&gt;Is it possible to do it through PA device?&lt;/P&gt;&lt;P&gt;Please let me know someone who know about it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Eugene. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 13 Jul 2012 06:00:00 GMT</pubDate>
    <dc:creator>willstech</dc:creator>
    <dc:date>2012-07-13T06:00:00Z</dc:date>
    <item>
      <title>is it possible to add a CA in PA device?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-add-a-ca-in-pa-device/m-p/24977#M18220</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello there. &lt;/P&gt;&lt;P&gt;I have a question related to CA for SSL client. &lt;/P&gt;&lt;P&gt;Customer has a certificate which issued by Trusted Root CA, but this trusted root CA is not contained in an ssl client's browser.&lt;/P&gt;&lt;P&gt;And then, the customer certificate was issued by this CA.&lt;/P&gt;&lt;P&gt;So, customer wants to distribute a CA of customer for all SSL VPN clients to avoid ssl certification error. (it was not created by a PA device.)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried to import to the CA at certificates in Device tab, but it&amp;nbsp; was impossible. &lt;/P&gt;&lt;P&gt;Is it possible to do it through PA device?&lt;/P&gt;&lt;P&gt;Please let me know someone who know about it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Eugene. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Jul 2012 06:00:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-add-a-ca-in-pa-device/m-p/24977#M18220</guid>
      <dc:creator>willstech</dc:creator>
      <dc:date>2012-07-13T06:00:00Z</dc:date>
    </item>
    <item>
      <title>Re: is it possible to add a CA in PA device?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-add-a-ca-in-pa-device/m-p/24978#M18221</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There is a trusted CA list within the device but I cant find in the manuals on how to list its content nor how to add your own CA's to this list - perhaps somebody else in here who knows?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regarding importing of stuff, if the web-gui fails you can use scp or tftp like so:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;scp import certificate from user1@10.0.3.4:/tmp/certificatefile&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;tftp import ssl-certificate from user1@10.0.3.4:/tmp/certificatefile&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Jul 2012 07:44:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-add-a-ca-in-pa-device/m-p/24978#M18221</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-07-13T07:44:01Z</dc:date>
    </item>
    <item>
      <title>Re: is it possible to add a CA in PA device?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-add-a-ca-in-pa-device/m-p/24979#M18222</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Through the Webui -&amp;gt; Device -&amp;gt; Certificates .. that shows all of the certs there.&lt;/P&gt;&lt;P&gt;You can take public CA certs and import them with their Key files.&lt;/P&gt;&lt;P&gt;OR you can create local generated CA's,. or the actual SSL certs..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It honestly really depends on what you are trying to accomplish.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Jul 2012 20:30:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-add-a-ca-in-pa-device/m-p/24979#M18222</guid>
      <dc:creator>jdelio</dc:creator>
      <dc:date>2012-07-19T20:30:41Z</dc:date>
    </item>
    <item>
      <title>Re: is it possible to add a CA in PA device?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-add-a-ca-in-pa-device/m-p/24980#M18223</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I hope you mean the public key when you spoke about public CA certs because I seriously doubt they will or should release their private key &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regarding that cert list I have completely missed that, in which version did that show up (and whats the CLI commands to list and modify it)?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Device -&amp;gt; Certificate Management -&amp;gt; Certificates -&amp;gt; Default Trusted Certificate Authorities (tab)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Jul 2012 20:55:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-add-a-ca-in-pa-device/m-p/24980#M18223</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-07-19T20:55:31Z</dc:date>
    </item>
    <item>
      <title>Re: is it possible to add a CA in PA device?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-add-a-ca-in-pa-device/m-p/24981#M18224</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As of 4.1, we do not list the trusted certs that are used by PAN. The tab "&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;Device -&amp;gt; Certificate Management &lt;/SPAN&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;-&amp;gt; Certificates -&amp;gt; Default Trusted Certificate Authorities" is an new feature added in 5.0. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To generate a cert through CLI:&lt;/P&gt;&lt;P&gt;request certificate generate &amp;lt;options&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To modify the cert:&lt;/P&gt;&lt;P&gt;set shared certificate &amp;lt;options&amp;gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Jul 2012 00:59:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-add-a-ca-in-pa-device/m-p/24981#M18224</guid>
      <dc:creator>zarina</dc:creator>
      <dc:date>2012-07-20T00:59:03Z</dc:date>
    </item>
  </channel>
</rss>

