<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to Issue Certificates to GlobalProtect Devices in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-renew-certificates-for-globalprotect-devices/m-p/71128#M40695</link>
    <description>&lt;P&gt;Hello Syadav,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Many thanks for your answer.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just two last questions:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1) In the end users can the new certificate overwrite the old one or is it necessary to remove the old certificate before installing the new one??&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2) If I want to renew the expiration date of the CA root certificate which signed the server and client certificates I guess that I need to export this one to the end users as well, right??&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks and Regards,&lt;/P&gt;
&lt;P&gt;Marcos.&lt;/P&gt;</description>
    <pubDate>Mon, 18 Jan 2016 18:57:22 GMT</pubDate>
    <dc:creator>Carracido</dc:creator>
    <dc:date>2016-01-18T18:57:22Z</dc:date>
    <item>
      <title>How to Renew Certificates for GlobalProtect Devices</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-renew-certificates-for-globalprotect-devices/m-p/71122#M40691</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hi all,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I want to renew the expiration date of the certificates for my globalprotect devices. T&lt;SPAN&gt;he firewall is the CA that issued the certificates.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;My question is whether I have to export and import the certificates after renewing them by following the steps on this article:&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/61/pan-os/pan-os/certificate-management/revoke-and-renew-certificates.html" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/61/pan-os/pan-os/certificate-management/revoke-and-renew-certificates.html&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I don´t know if the certificates renewal requires any installation or the changes will be reflected in the devices without installation.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Many thanks in advance,&lt;/P&gt;
&lt;P&gt;Marcos&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jan 2016 19:39:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-renew-certificates-for-globalprotect-devices/m-p/71122#M40691</guid>
      <dc:creator>Carracido</dc:creator>
      <dc:date>2016-01-18T19:39:12Z</dc:date>
    </item>
    <item>
      <title>Re: How to Issue Certificates to GlobalProtect Devices</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-renew-certificates-for-globalprotect-devices/m-p/71126#M40694</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hi Marcos,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There are two possibilities for which you may be using the Device (locally) generated certificate :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. &amp;nbsp;Server Certificate for Portal and Gateway : In this case the signing CA cert is still the same and has not changed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;Hence the end users would still be able to validate the new server certificates as they have the signing CA cert.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2. &amp;nbsp;Client Certificate for Authentication of End users : If this certificate has expired and renewed then it needs to be imported&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;on the local devices (clients). If not, they would not authenticate the local machine due to expiry.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jan 2016 16:37:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-renew-certificates-for-globalprotect-devices/m-p/71126#M40694</guid>
      <dc:creator>syadav</dc:creator>
      <dc:date>2016-01-18T16:37:16Z</dc:date>
    </item>
    <item>
      <title>Re: How to Issue Certificates to GlobalProtect Devices</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-renew-certificates-for-globalprotect-devices/m-p/71128#M40695</link>
      <description>&lt;P&gt;Hello Syadav,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Many thanks for your answer.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just two last questions:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1) In the end users can the new certificate overwrite the old one or is it necessary to remove the old certificate before installing the new one??&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2) If I want to renew the expiration date of the CA root certificate which signed the server and client certificates I guess that I need to export this one to the end users as well, right??&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks and Regards,&lt;/P&gt;
&lt;P&gt;Marcos.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jan 2016 18:57:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-renew-certificates-for-globalprotect-devices/m-p/71128#M40695</guid>
      <dc:creator>Carracido</dc:creator>
      <dc:date>2016-01-18T18:57:22Z</dc:date>
    </item>
    <item>
      <title>Re: How to Issue Certificates to GlobalProtect Devices</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-renew-certificates-for-globalprotect-devices/m-p/71148#M40703</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hi Marcos,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please find the answers to your questions below :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1) I would recommend you to remove the older certificate from the personal store and add the new one. Certificate management is usually done with GPO, you may use the same to deploy/withdraw the certs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2) Yes, in case the signing CA certificate is renewed, it needs to be imported on the client machines and added in the Trusted &amp;nbsp; &amp;nbsp; Root CA store.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please mark as a solution if it resolves your problem.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jan 2016 13:39:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-renew-certificates-for-globalprotect-devices/m-p/71148#M40703</guid>
      <dc:creator>syadav</dc:creator>
      <dc:date>2016-01-19T13:39:36Z</dc:date>
    </item>
    <item>
      <title>Re: How to Issue Certificates to GlobalProtect Devices</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-renew-certificates-for-globalprotect-devices/m-p/71193#M40716</link>
      <description>&lt;P&gt;Hi Syadav,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks a lot for your help.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Marcos.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jan 2016 15:44:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-renew-certificates-for-globalprotect-devices/m-p/71193#M40716</guid>
      <dc:creator>Carracido</dc:creator>
      <dc:date>2016-01-19T15:44:03Z</dc:date>
    </item>
    <item>
      <title>Re: How to Issue Certificates to GlobalProtect Devices</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-renew-certificates-for-globalprotect-devices/m-p/71196#M40719</link>
      <description>&lt;P&gt;Hi Marcos,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for your response.&lt;/P&gt;
&lt;P&gt;Also make sure that if the Client certificate is generated on firewall you export it in format PKCS12.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If this advice helps your case, please mark it as a solution so that it may help others.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jan 2016 15:51:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-renew-certificates-for-globalprotect-devices/m-p/71196#M40719</guid>
      <dc:creator>syadav</dc:creator>
      <dc:date>2016-01-19T15:51:35Z</dc:date>
    </item>
    <item>
      <title>Re: How to Renew Certificates for GlobalProtect Devices</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-renew-certificates-for-globalprotect-devices/m-p/329512#M83646</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/24977"&gt;@Carracido&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I know it's been a while since you've made this post, so I hope this message finds you well.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Since the certificates were generated on the firewall, we have the ability to renew them directly from the PAN-OS without having to re-deploy them.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've included the document explaining this in further detail below for your reference.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000POioCAG" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000POioCAG&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Stay safe and have a great day!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;-Cheers&lt;/P&gt;</description>
      <pubDate>Fri, 22 May 2020 23:27:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-renew-certificates-for-globalprotect-devices/m-p/329512#M83646</guid>
      <dc:creator>trivers01</dc:creator>
      <dc:date>2020-05-22T23:27:26Z</dc:date>
    </item>
    <item>
      <title>Re: How to Renew Certificates for GlobalProtect Devices</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-renew-certificates-for-globalprotect-devices/m-p/391709#M90802</link>
      <description>&lt;P&gt;If we renewed self-signed cert , will be able to connect GP with expired self-signed cert already installed in user machine ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are able to get certificate warning while connecting GP on new machine.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But on already installed machine its giving server certificate not found error.&amp;nbsp; Also we have enabled installed certificate in trusted root store in Global Protect Portal &amp;gt; Agent but no luck.&lt;/P&gt;&lt;P&gt;Do we require to remove gateway address from GP client and need to reconnect ? in order to get certificate warning or to get renewed cert automatically installed on user machine.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If we install renewed certificate on user machine then we are able to connect GP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Mar 2021 13:10:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-renew-certificates-for-globalprotect-devices/m-p/391709#M90802</guid>
      <dc:creator>Deepak_K</dc:creator>
      <dc:date>2021-03-17T13:10:32Z</dc:date>
    </item>
  </channel>
</rss>

