<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Certificate Bundle in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/certificate-bundle/m-p/4743#M3501</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Asabadin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You need to export "&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 12.7272720336914px;"&gt;Mercedes_Bundle&lt;/SPAN&gt;" along with the key from the firewall. You can use PEM format and give it a passphrase. Once exported you should be able to open it in notepad. You will see following format :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-----BEGIN CERTIFICATE-----&lt;/P&gt;&lt;P&gt;MIIC5zCCAc+gAwIBAgIBFD..&lt;/P&gt;&lt;P&gt;-----END CERTIFICATE-----&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-----BEGIN RSA PRIVATE KEY-----&lt;/P&gt;&lt;P&gt;Proc-Type: 4,ENCRYPTED&lt;/P&gt;&lt;P&gt;DEK-Info: AES-256-CBC,A35588EF895&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;bPd92JfJYc407emq4&lt;/P&gt;&lt;P&gt;-----END RSA PRIVATE KEY-----&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then open the root certificate in the notepad as well. You will NOT need private key of the root cert. Then go ahead and add root cert below RSA key.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-----BEGIN CERTIFICATE-----&lt;/P&gt;&lt;P&gt;&amp;lt;root cert&amp;gt;&lt;/P&gt;&lt;P&gt;-----END CERTIFICATE-----&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So your order should be&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 12.7272720336914px;"&gt;Mercedes_Bundle &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-size: 12.7272720336914px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;Mercedes_Bundle key&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-size: 12.7272720336914px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;Root cert&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-size: 12.7272720336914px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-size: 12.7272720336914px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;If you have intermediate certificate in the chain, then&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-size: 12.7272720336914px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Mercedes_Bundle &lt;/P&gt;&lt;P&gt;Mercedes_Bundle key&lt;/P&gt;&lt;P&gt;Intermediate Cert&lt;/P&gt;&lt;P&gt;Root cert&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Once you have all in one text file, save it and import it to the firewall. While importing you will need to provide key file, this will be the same cert that we just created (that means brose same cert file twice). Passphrase would be same that you used to export. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Follow following document to achieve that :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-4289"&gt;How to Install a Chained Certificate Signed by a Public CA&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Once successfully imported, do a commit one more time. Warning should go away. Hope this helps. Thank you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 15 Oct 2014 02:00:38 GMT</pubDate>
    <dc:creator>ssharma</dc:creator>
    <dc:date>2014-10-15T02:00:38Z</dc:date>
    <item>
      <title>Certificate Bundle</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/certificate-bundle/m-p/4737#M3495</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm get error on commit: "Warning: cannot find complete cerficate chain for certificate Certificate_Bundle"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I notice there are three bundles in the device certificates, but how do I know which bundle is being used?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How to I test this without breaking it.....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Oct 2014 03:52:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/certificate-bundle/m-p/4737#M3495</guid>
      <dc:creator>asabadin</dc:creator>
      <dc:date>2014-10-14T03:52:53Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate Bundle</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/certificate-bundle/m-p/4738#M3496</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/u1/6279"&gt;asabadin&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Usually we use the certificate at the bottom of the chain. Would it be possible for you to attach the snapshot of the certificate bundle ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The warning can be safely ignored in some cases as it is always not necessary to import the root certificate on the device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Oct 2014 03:55:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/certificate-bundle/m-p/4738#M3496</guid>
      <dc:creator>bat</dc:creator>
      <dc:date>2014-10-14T03:55:04Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate Bundle</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/certificate-bundle/m-p/4739#M3497</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;STRONG style="font-size: 12px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;A _jive_internal="true" class="jiveTT-hover-user jive-username-link" data-avatarid="1961" data-externalid="" data-presence="null" data-userid="6279" data-username="asabadin" href="https://live.paloaltonetworks.com/people/asabadin" style="padding: 0 3px 0 0; font-weight: inherit; font-style: inherit; font-size: 1.1em; font-family: inherit; color: #006595;"&gt;asabadin,&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-size: 12px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-size: 12px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;Please follow the documents below that might be of assistance to you :&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-size: 12px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-size: 12px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-4289"&gt;How to Install a Chained Certificate Signed by a Public CA&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-6021"&gt;Fix For Error When Importing Chained PEM Format Certificates - Using Text Editor to Re-order&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The bundle will be imported successfully if the certificate chain is proper. The sirst document shows you what is the proper certificate chain.&lt;/P&gt;&lt;P&gt;The second speaks about using a text editor to create a proper certificate chain if the certificate bundle signed by a CA is does not have a proper chain to be imported into PA firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Oct 2014 06:35:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/certificate-bundle/m-p/4739#M3497</guid>
      <dc:creator>tshiv</dc:creator>
      <dc:date>2014-10-14T06:35:01Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate Bundle</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/certificate-bundle/m-p/4740#M3498</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sure, here you go......screendump attached&lt;IMG alt="cert.jpg" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/16301_cert.jpg" style="height: 135px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The bundle in question is the Mercedes_Bundle.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Oct 2014 22:56:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/certificate-bundle/m-p/4740#M3498</guid>
      <dc:creator>asabadin</dc:creator>
      <dc:date>2014-10-14T22:56:52Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate Bundle</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/certificate-bundle/m-p/4741#M3499</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;STRONG style="font-size: 12px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;A _jive_internal="true" class="jiveTT-hover-user jive-username-link" data-avatarid="1961" data-externalid="" data-presence="null" data-userid="6279" data-username="asabadin" href="https://live.paloaltonetworks.com/people/asabadin" style="padding: 0 3px 0 0; font-weight: inherit; font-style: inherit; font-size: 1.1em; font-family: inherit; color: #006595;"&gt;asabadin&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-size: 12px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-size: 12px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;It seems that the Mercedes_Bundle does not have the proper chain. Can you please refer to the documents I suggested in my previous post? &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-size: 12px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;For you reference:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-size: 12px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;STRONG style="font-size: 12px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;A _jive_internal="true" data-containerid="2027" data-containertype="14" data-objectid="4289" data-objecttype="102" href="https://live.paloaltonetworks.com/docs/DOC-4289" style="font-weight: inherit; font-style: inherit; font-family: inherit; color: #006595;"&gt;How to Install a Chained Certificate Signed by a Public CA&lt;/A&gt;&lt;/STRONG&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-size: 12px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;A _jive_internal="true" data-containerid="20594" data-containertype="2020" data-objectid="6021" data-objecttype="102" href="https://live.paloaltonetworks.com/docs/DOC-6021" style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #006595;"&gt;Fix For Error When Importing Chained PEM Format Certificates - Using Text Editor to Re-order&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-size: 12px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;Thanks&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Oct 2014 00:19:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/certificate-bundle/m-p/4741#M3499</guid>
      <dc:creator>tshiv</dc:creator>
      <dc:date>2014-10-15T00:19:41Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate Bundle</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/certificate-bundle/m-p/4742#M3500</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;A href="https://live.paloaltonetworks.com/u1/6279"&gt;asabadin&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;By any chance was there any upgrade performed recently on this device because the issuer field is somehow blank in all these certificates which should not happen ideally ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Oct 2014 00:50:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/certificate-bundle/m-p/4742#M3500</guid>
      <dc:creator>bat</dc:creator>
      <dc:date>2014-10-15T00:50:45Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate Bundle</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/certificate-bundle/m-p/4743#M3501</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Asabadin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You need to export "&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 12.7272720336914px;"&gt;Mercedes_Bundle&lt;/SPAN&gt;" along with the key from the firewall. You can use PEM format and give it a passphrase. Once exported you should be able to open it in notepad. You will see following format :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-----BEGIN CERTIFICATE-----&lt;/P&gt;&lt;P&gt;MIIC5zCCAc+gAwIBAgIBFD..&lt;/P&gt;&lt;P&gt;-----END CERTIFICATE-----&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-----BEGIN RSA PRIVATE KEY-----&lt;/P&gt;&lt;P&gt;Proc-Type: 4,ENCRYPTED&lt;/P&gt;&lt;P&gt;DEK-Info: AES-256-CBC,A35588EF895&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;bPd92JfJYc407emq4&lt;/P&gt;&lt;P&gt;-----END RSA PRIVATE KEY-----&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then open the root certificate in the notepad as well. You will NOT need private key of the root cert. Then go ahead and add root cert below RSA key.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-----BEGIN CERTIFICATE-----&lt;/P&gt;&lt;P&gt;&amp;lt;root cert&amp;gt;&lt;/P&gt;&lt;P&gt;-----END CERTIFICATE-----&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So your order should be&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 12.7272720336914px;"&gt;Mercedes_Bundle &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-size: 12.7272720336914px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;Mercedes_Bundle key&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-size: 12.7272720336914px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;Root cert&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-size: 12.7272720336914px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-size: 12.7272720336914px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;If you have intermediate certificate in the chain, then&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-size: 12.7272720336914px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Mercedes_Bundle &lt;/P&gt;&lt;P&gt;Mercedes_Bundle key&lt;/P&gt;&lt;P&gt;Intermediate Cert&lt;/P&gt;&lt;P&gt;Root cert&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Once you have all in one text file, save it and import it to the firewall. While importing you will need to provide key file, this will be the same cert that we just created (that means brose same cert file twice). Passphrase would be same that you used to export. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Follow following document to achieve that :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-4289"&gt;How to Install a Chained Certificate Signed by a Public CA&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Once successfully imported, do a commit one more time. Warning should go away. Hope this helps. Thank you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Oct 2014 02:00:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/certificate-bundle/m-p/4743#M3501</guid>
      <dc:creator>ssharma</dc:creator>
      <dc:date>2014-10-15T02:00:38Z</dc:date>
    </item>
  </channel>
</rss>

