<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cert key import in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/cert-key-import/m-p/150418#M49949</link>
    <description>&lt;P&gt;so then generate a new certificate, making sure you don't check the CA button to create and export the CSR, run the CSR through your enterprise CA and then import the resulting public key.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Featured-Articles/How-to-Generate-a-CSR-Certificate-Signing-Request-amp-Import-the/ta-p/53593" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Featured-Articles/How-to-Generate-a-CSR-Certificate-Signing-Request-amp-Import-the/ta-p/53593&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 30 Mar 2017 14:49:00 GMT</pubDate>
    <dc:creator>bradk14</dc:creator>
    <dc:date>2017-03-30T14:49:00Z</dc:date>
    <item>
      <title>Cert key import</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cert-key-import/m-p/149694#M49826</link>
      <description>&lt;P&gt;What is the best way to import a key for a globalprotect portal? I already have CA installed.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Mar 2017 18:54:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cert-key-import/m-p/149694#M49826</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2017-03-27T18:54:19Z</dc:date>
    </item>
    <item>
      <title>Re: Cert key import</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cert-key-import/m-p/149735#M49829</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just did recently. I used COMODO (think it is 4-5 £ per year). So generated CSR, sent to comodo. Received&amp;nbsp;back signed cert (did only DV check) imported the&amp;nbsp;cert to the&amp;nbsp;firewall&amp;nbsp;as well as the private key (i used .txt file). Private key will be encrypted l think by Master Key on PA. Created an SSL Profile and used with GP configuration.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Mar 2017 20:33:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cert-key-import/m-p/149735#M49829</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-03-27T20:33:39Z</dc:date>
    </item>
    <item>
      <title>Re: Cert key import</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cert-key-import/m-p/149744#M49830</link>
      <description>&lt;P&gt;yeah I believe I only need to add the key &amp;nbsp;not the cert.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Mar 2017 20:38:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cert-key-import/m-p/149744#M49830</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2017-03-27T20:38:03Z</dc:date>
    </item>
    <item>
      <title>Re: Cert key import</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cert-key-import/m-p/149751#M49831</link>
      <description>&lt;P&gt;When using a public CA, the chain is vitally important to get right. It can be done wrong, and cause some issues. Here's a doc I wrote a few years that goes into the details:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/How-to-Install-a-Chained-Certificate-Signed-by-a-Public-CA/ta-p/55523" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/How-to-Install-a-Chained-Certificate-Signed-by-a-Public-CA/ta-p/55523&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Mar 2017 20:48:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cert-key-import/m-p/149751#M49831</guid>
      <dc:creator>gwesson</dc:creator>
      <dc:date>2017-03-27T20:48:37Z</dc:date>
    </item>
    <item>
      <title>Re: Cert key import</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cert-key-import/m-p/149753#M49832</link>
      <description>&lt;P&gt;I am using a internal CA , we have our own CA server setup in our networkl I created the key on it&lt;/P&gt;</description>
      <pubDate>Mon, 27 Mar 2017 20:55:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cert-key-import/m-p/149753#M49832</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2017-03-27T20:55:50Z</dc:date>
    </item>
    <item>
      <title>Re: Cert key import</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cert-key-import/m-p/150191#M49902</link>
      <description>&lt;P&gt;so do i choose import and then browse to the key or do I need to chain it to the CA that is already installed on the PA&lt;/P&gt;</description>
      <pubDate>Wed, 29 Mar 2017 16:38:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cert-key-import/m-p/150191#M49902</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2017-03-29T16:38:23Z</dc:date>
    </item>
    <item>
      <title>Re: Cert key import</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cert-key-import/m-p/150199#M49903</link>
      <description>&lt;P&gt;So l had a .crt&amp;nbsp;certificate &amp;nbsp;+ .txt private key. Imported both and&amp;nbsp;everything works as it should&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Mar 2017 16:54:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cert-key-import/m-p/150199#M49903</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-03-29T16:54:21Z</dc:date>
    </item>
    <item>
      <title>Re: Cert key import</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cert-key-import/m-p/150249#M49914</link>
      <description>&lt;P&gt;There is already an existing .crt on the box I just need to add the key but I am not sure what the right procedure is&lt;/P&gt;</description>
      <pubDate>Wed, 29 Mar 2017 19:50:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cert-key-import/m-p/150249#M49914</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2017-03-29T19:50:45Z</dc:date>
    </item>
    <item>
      <title>Re: Cert key import</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cert-key-import/m-p/150278#M49921</link>
      <description>&lt;P&gt;As far as l know you should have your private key as a separate file and while importing the certificate into the&amp;nbsp;box use the option to add a private key as below:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="TEST.PNG" style="width: 491px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/8567i851489647EF8748F/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="TEST.PNG" alt="TEST.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When you finish you should see cert with private key uploaded&amp;nbsp;and ready to be used:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="CERT.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/8568iD81227EB76C76D2D/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="CERT.PNG" alt="CERT.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you uploaded the cert without the key l don't think you can use it as you will not be able to decrypt the data.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Re-upload the cert same time importing the&amp;nbsp;private key.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Mar 2017 21:02:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cert-key-import/m-p/150278#M49921</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-03-29T21:02:11Z</dc:date>
    </item>
    <item>
      <title>Re: Cert key import</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cert-key-import/m-p/150279#M49922</link>
      <description>&lt;P&gt;Okay that makes sense and thanks for the screen shots. So are you basically chain it to the existing cert?&lt;/P&gt;</description>
      <pubDate>Wed, 29 Mar 2017 21:09:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cert-key-import/m-p/150279#M49922</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2017-03-29T21:09:10Z</dc:date>
    </item>
    <item>
      <title>Re: Cert key import</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cert-key-import/m-p/150283#M49924</link>
      <description>&lt;P&gt;l don't really know what exactly is happening behind the scenes but to me you uploading a digital certificate (its signed by trusted authority as well as contains a public key):&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="CERCER.PNG" style="width: 406px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/8569i5FE2314F19D37225/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="CERCER.PNG" alt="CERCER.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When SSL handshake is completed, the client will&amp;nbsp;encrypt the data with the Public Key taken from the cert. For you to be able to decrypt you need to have a private key. Is it chained&amp;nbsp;with cert when you uploading or not I am not sure and don't&amp;nbsp;know&amp;nbsp;much about the certs format. Sorry&lt;/P&gt;</description>
      <pubDate>Wed, 29 Mar 2017 21:37:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cert-key-import/m-p/150283#M49924</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-03-29T21:37:08Z</dc:date>
    </item>
    <item>
      <title>Re: Cert key import</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cert-key-import/m-p/150295#M49926</link>
      <description>&lt;P&gt;if I am understanding everything correctly, if you've already generated the CSR on the PA and thus it already has the private key installed, then yes, just import the public key from the CA. The PA should marry the two automatically.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Mar 2017 00:03:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cert-key-import/m-p/150295#M49926</guid>
      <dc:creator>bradk14</dc:creator>
      <dc:date>2017-03-30T00:03:11Z</dc:date>
    </item>
    <item>
      <title>Re: Cert key import</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cert-key-import/m-p/150393#M49942</link>
      <description>&lt;P&gt;I have my own trusted root CA server and can generate my own certs and keys. Currently it has a the trusted root CA certificate installed and I want to add another key for another global protect portal on the &amp;nbsp;PA and would like to add a cert and key to it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Mar 2017 13:10:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cert-key-import/m-p/150393#M49942</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2017-03-30T13:10:47Z</dc:date>
    </item>
    <item>
      <title>Re: Cert key import</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cert-key-import/m-p/150418#M49949</link>
      <description>&lt;P&gt;so then generate a new certificate, making sure you don't check the CA button to create and export the CSR, run the CSR through your enterprise CA and then import the resulting public key.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Featured-Articles/How-to-Generate-a-CSR-Certificate-Signing-Request-amp-Import-the/ta-p/53593" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Featured-Articles/How-to-Generate-a-CSR-Certificate-Signing-Request-amp-Import-the/ta-p/53593&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Mar 2017 14:49:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cert-key-import/m-p/150418#M49949</guid>
      <dc:creator>bradk14</dc:creator>
      <dc:date>2017-03-30T14:49:00Z</dc:date>
    </item>
    <item>
      <title>Re: Cert key import</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cert-key-import/m-p/150611#M49987</link>
      <description>&lt;P&gt;can I add a key to an existing csr since we have global one?&lt;/P&gt;</description>
      <pubDate>Fri, 31 Mar 2017 16:30:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cert-key-import/m-p/150611#M49987</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2017-03-31T16:30:35Z</dc:date>
    </item>
  </channel>
</rss>

