<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: about certificate expired date in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/about-certificate-expired-date/m-p/38752#M28409</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Greg,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for reply, I saw a 6 month expiration date on client IE browser, but truly, it shows 10 years expiration date on PA after I generate it, it's the point that I confuse.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In addition, the PA is running PanOS 4.1.9.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Joy&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 09 Dec 2012 09:51:00 GMT</pubDate>
    <dc:creator>paloalto.netfos</dc:creator>
    <dc:date>2012-12-09T09:51:00Z</dc:date>
    <item>
      <title>about certificate expired date</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/about-certificate-expired-date/m-p/38749#M28406</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there any way to custom certificate expired date that generate by paloalto itself ?&amp;nbsp; I saw it on webpage that is too short, it only have six monthes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Joy&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Dec 2012 17:00:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/about-certificate-expired-date/m-p/38749#M28406</guid>
      <dc:creator>paloalto.netfos</dc:creator>
      <dc:date>2012-12-05T17:00:14Z</dc:date>
    </item>
    <item>
      <title>Re: about certificate expired date</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/about-certificate-expired-date/m-p/38750#M28407</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Joy,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you are running version 5.0.0 or higher, you can specify the expiration in the Generate dialog box.&lt;/P&gt;&lt;P&gt;If you are running a version prior to 5.0.0, there is no way to customize the expiration date directly on the firewall. You can create the certificate externally (OpenSSL, Microsoft Certificate Server, etc.) and import the private &amp;amp; public keys. Those externally-generated certificates can use any expiration you would like.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not sure why you are seeing a 6 month expiration date though. On 4.1.9, the default expiration date for a newly created certificate is ten years.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Greg Wesson&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Dec 2012 20:12:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/about-certificate-expired-date/m-p/38750#M28407</guid>
      <dc:creator>gwesson</dc:creator>
      <dc:date>2012-12-05T20:12:18Z</dc:date>
    </item>
    <item>
      <title>Re: about certificate expired date</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/about-certificate-expired-date/m-p/38751#M28408</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Also is this question regarding the https for mgmt-plane or certificates generated on the fly when you use ssl decrypt?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If its the later then the PA will just copy the expiration date from the external cert into the internal (on the fly generated) cert. This internal cert is then signed by the CA you imported into the PA (and the client have this CA public cert added as trusted CA).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Dec 2012 22:14:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/about-certificate-expired-date/m-p/38751#M28408</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-12-05T22:14:35Z</dc:date>
    </item>
    <item>
      <title>Re: about certificate expired date</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/about-certificate-expired-date/m-p/38752#M28409</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Greg,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for reply, I saw a 6 month expiration date on client IE browser, but truly, it shows 10 years expiration date on PA after I generate it, it's the point that I confuse.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In addition, the PA is running PanOS 4.1.9.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Joy&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 09 Dec 2012 09:51:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/about-certificate-expired-date/m-p/38752#M28409</guid>
      <dc:creator>paloalto.netfos</dc:creator>
      <dc:date>2012-12-09T09:51:00Z</dc:date>
    </item>
    <item>
      <title>Re: about certificate expired date</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/about-certificate-expired-date/m-p/38753#M28410</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Joy,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you are doing SSL Decryption as mikand says, the certificate that the firewall presents is just copied from the server. The domain name (common name) and expiration date (validity period) are copied from the destination server's certificate, with the issuer being the Palo Alto Networks firewall. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you are managing the firewall and seeing the 6-month expiration date, that is something I have not seen. I doubt your PC date is wrong or you would have errors on nearly every public HTTPS site. You could always regenerate the certificate, but it sounds like you already verified it is a 10-year cert. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you give us more details about what the certificate is used for and when you see it?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Greg &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Dec 2012 23:42:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/about-certificate-expired-date/m-p/38753#M28410</guid>
      <dc:creator>gwesson</dc:creator>
      <dc:date>2012-12-10T23:42:22Z</dc:date>
    </item>
    <item>
      <title>Re: about certificate expired date</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/about-certificate-expired-date/m-p/38754#M28411</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Greg,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for reply, after confirm it again, I see the correct info about expiration date that is 10 years. the &lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;6 month expiration date that I saw should be&amp;nbsp; signed from PA for client use.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;I am sorry about that, and thanks for your helping.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Joy&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Dec 2012 01:36:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/about-certificate-expired-date/m-p/38754#M28411</guid>
      <dc:creator>paloalto.netfos</dc:creator>
      <dc:date>2012-12-12T01:36:42Z</dc:date>
    </item>
  </channel>
</rss>

