<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Panorama Certificate question in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-certificate-question/m-p/181505#M56057</link>
    <description>&lt;P&gt;In pamorama&amp;nbsp;I created a default template with basic configuration settings for all firewalls and then create a site specific template and put them both in a template stack to apply the stack to each firewall. This way the default settings apply to all firewalls for consistancy and we can apply site specific settings like individual rules. This works great so far.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;One of the default settings we pushed out is a wildcard cert and a ssl/tls service profile so that we can use our domain to secure communication to the management web sites over SSL. This works great.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Later I setup global protect vpn for remote clients to connect. I&amp;nbsp; am doing this on only 1 locaiton currnetly so I made these changes to the site specific template and not the default template. When I go to add the cert and the TLS profile in the site sepecific template it doesnt see the cert or ssl/tls service profile pushed out with the default template even though its the same wildcard cert. I installed the cert and in the site specific template and created a new service profile and global protect works fine.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The issue is every time I commit to this firewall group now I get an error saying duplicate certificate subject found.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What is the best way to fix this? I thought maybe I had to make the change on the stack rather than the individual certs but everything is read only when I go to modify the stack.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Everything is working fine but my OCD finds it really annoying that the commit comes back with succedeed with warnings.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 12 Oct 2017 14:39:38 GMT</pubDate>
    <dc:creator>dstjames</dc:creator>
    <dc:date>2017-10-12T14:39:38Z</dc:date>
    <item>
      <title>Panorama Certificate question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-certificate-question/m-p/181505#M56057</link>
      <description>&lt;P&gt;In pamorama&amp;nbsp;I created a default template with basic configuration settings for all firewalls and then create a site specific template and put them both in a template stack to apply the stack to each firewall. This way the default settings apply to all firewalls for consistancy and we can apply site specific settings like individual rules. This works great so far.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;One of the default settings we pushed out is a wildcard cert and a ssl/tls service profile so that we can use our domain to secure communication to the management web sites over SSL. This works great.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Later I setup global protect vpn for remote clients to connect. I&amp;nbsp; am doing this on only 1 locaiton currnetly so I made these changes to the site specific template and not the default template. When I go to add the cert and the TLS profile in the site sepecific template it doesnt see the cert or ssl/tls service profile pushed out with the default template even though its the same wildcard cert. I installed the cert and in the site specific template and created a new service profile and global protect works fine.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The issue is every time I commit to this firewall group now I get an error saying duplicate certificate subject found.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What is the best way to fix this? I thought maybe I had to make the change on the stack rather than the individual certs but everything is read only when I go to modify the stack.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Everything is working fine but my OCD finds it really annoying that the commit comes back with succedeed with warnings.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Oct 2017 14:39:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panorama-certificate-question/m-p/181505#M56057</guid>
      <dc:creator>dstjames</dc:creator>
      <dc:date>2017-10-12T14:39:38Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama Certificate question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-certificate-question/m-p/181649#M56066</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/45395"&gt;@dstjames&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes that is how it would work you cant reference template values across in a stack.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have you kept the same name while importing the certificates (Display Name) in both the templates ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you&amp;nbsp;keep the same name (&lt;STRONG&gt;try rename&lt;/STRONG&gt;) in both the templates then the default template should supersede and only one certificate should get imported which should take care of your Warning.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The old certificate should ideally be deleted with Panorama push and only one certificate should reflect in the Firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Oct 2017 04:08:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panorama-certificate-question/m-p/181649#M56066</guid>
      <dc:creator>hpunjabi</dc:creator>
      <dc:date>2017-10-13T04:08:42Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama Certificate question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-certificate-question/m-p/181744#M56073</link>
      <description>&lt;P&gt;Thanks for the reply.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yeah I put them in as different names.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I go to the firewall directly rather than through panorama I do see that it installed both certs and both tls serivce profiles. Since these are technically both the same cert thats why when I commit its telling me I have a duplicate subject name.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just not sure what the best practice is to use the same cert in both scenarios? I guess I could remove it from the default template and put all the cert settings in the site specific template. I was just hoping there was a better way.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Oct 2017 13:59:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panorama-certificate-question/m-p/181744#M56073</guid>
      <dc:creator>dstjames</dc:creator>
      <dc:date>2017-10-13T13:59:56Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama Certificate question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-certificate-question/m-p/181889#M56097</link>
      <description>&lt;P&gt;Yes usually as best practice it is recommended to use different certificates.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Using it in individual templates than default in the stack will also solve this problem or the other way is to keep same display name for the certificate in default template and nested template, this way you can still deploy the certificates through default template to other firewalls.&lt;/P&gt;</description>
      <pubDate>Sat, 14 Oct 2017 12:25:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panorama-certificate-question/m-p/181889#M56097</guid>
      <dc:creator>hpunjabi</dc:creator>
      <dc:date>2017-10-14T12:25:31Z</dc:date>
    </item>
  </channel>
</rss>

