<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSL CSR SAN Multiple Uses in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-csr-san-multiple-uses/m-p/199589#M59130</link>
    <description>&lt;P&gt;8.0 documentation is where I got confused.&amp;nbsp;See bolded text below. Why would a Host Name attribute match the Common Name?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/certificate-management/obtain-certificates/obtain-a-certificate-from-an-external-ca" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/certificate-management/obtain-certificates/obtain-a-certificate-from-an-external-ca&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;9.&amp;nbsp;&lt;SPAN class="ph cmd"&gt;(Optional)&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="ph uicontrol"&gt;Add&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="ph uicontrol"&gt;Certificate Attributes&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;to uniquely identify the firewall and the service that will use the certificate.&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV class="itemgroup info"&gt;&lt;DIV class="note "&gt;&lt;DIV&gt;&lt;DIV class="p"&gt;&lt;STRONG&gt;If you add a&amp;nbsp;&lt;SPAN class="ph uicontrol"&gt;Host Name&lt;/SPAN&gt;&amp;nbsp;attribute, it is a best practice for it to match the&amp;nbsp;&lt;SPAN class="ph uicontrol"&gt;Common Name&lt;/SPAN&gt;&amp;nbsp;(this is mandatory for GlobalProtect). The host name populates the Subject Alternative Name field of the certificate.&lt;/STRONG&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
    <pubDate>Thu, 08 Feb 2018 13:40:10 GMT</pubDate>
    <dc:creator>mike406</dc:creator>
    <dc:date>2018-02-08T13:40:10Z</dc:date>
    <item>
      <title>SSL CSR SAN Multiple Uses</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-csr-san-multiple-uses/m-p/199488#M59120</link>
      <description>&lt;P&gt;PA-5220, 8.0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I need to generate a CSR for a cert that will be used for multiple things - web gui admin, globalprotect vpn, etc. The instructions for how to gen the CSR with subject alternative names are not clear.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Should the common name be one of the uses e.g. vpn.mycompany.com or should the common name be *.mycompany.com with all host names listed as attributes e.g. vpn.mycompany.com, webgui.mycompany.com, etc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Feb 2018 01:07:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-csr-san-multiple-uses/m-p/199488#M59120</guid>
      <dc:creator>mike406</dc:creator>
      <dc:date>2018-02-08T01:07:24Z</dc:date>
    </item>
    <item>
      <title>Re: SSL CSR SAN Multiple Uses</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-csr-san-multiple-uses/m-p/199558#M59125</link>
      <description>&lt;P&gt;i'm not sure what instructions you were following but it may be a mixture of wildcard/SAN cert..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;CN=vpn.mycompany.com&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;certificate attributes&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;hostname=webgui.mycompamy.com&lt;/P&gt;&lt;P&gt;hostname=vpn2.mycompamy.com&lt;/P&gt;&lt;P&gt;hostname=anyfink.mycompamy.com&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;as per...&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/Creating-Certificate-Subject-Alternate-Names/ta-p/58424" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/Creating-Certificate-Subject-Alternate-Names/ta-p/58424&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Feb 2018 10:47:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-csr-san-multiple-uses/m-p/199558#M59125</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-02-08T10:47:34Z</dc:date>
    </item>
    <item>
      <title>Re: SSL CSR SAN Multiple Uses</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-csr-san-multiple-uses/m-p/199589#M59130</link>
      <description>&lt;P&gt;8.0 documentation is where I got confused.&amp;nbsp;See bolded text below. Why would a Host Name attribute match the Common Name?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/certificate-management/obtain-certificates/obtain-a-certificate-from-an-external-ca" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/certificate-management/obtain-certificates/obtain-a-certificate-from-an-external-ca&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;9.&amp;nbsp;&lt;SPAN class="ph cmd"&gt;(Optional)&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="ph uicontrol"&gt;Add&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="ph uicontrol"&gt;Certificate Attributes&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;to uniquely identify the firewall and the service that will use the certificate.&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV class="itemgroup info"&gt;&lt;DIV class="note "&gt;&lt;DIV&gt;&lt;DIV class="p"&gt;&lt;STRONG&gt;If you add a&amp;nbsp;&lt;SPAN class="ph uicontrol"&gt;Host Name&lt;/SPAN&gt;&amp;nbsp;attribute, it is a best practice for it to match the&amp;nbsp;&lt;SPAN class="ph uicontrol"&gt;Common Name&lt;/SPAN&gt;&amp;nbsp;(this is mandatory for GlobalProtect). The host name populates the Subject Alternative Name field of the certificate.&lt;/STRONG&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Thu, 08 Feb 2018 13:40:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-csr-san-multiple-uses/m-p/199589#M59130</guid>
      <dc:creator>mike406</dc:creator>
      <dc:date>2018-02-08T13:40:10Z</dc:date>
    </item>
    <item>
      <title>Re: SSL CSR SAN Multiple Uses</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-csr-san-multiple-uses/m-p/199593#M59131</link>
      <description>&lt;P&gt;I think what its trying to say that if your CN is fred.com and your portal address dns resloves to fred.com then adding joe.com to the SAN will cause a cert issue for GP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;so... your get request is for fred.com but the trusted cert will have a hostname of joe.com...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;in their example you dont need to add a hostname attribute,&amp;nbsp;the SAN of fred.com will be assumed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;so... for the case of a single host cert, if you are going to add hostname attribute (not actually required) then keep it the same as the CN.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the ref doc link you provided is not really for SAN certs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Feb 2018 14:01:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-csr-san-multiple-uses/m-p/199593#M59131</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-02-08T14:01:07Z</dc:date>
    </item>
    <item>
      <title>Re: SSL CSR SAN Multiple Uses</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-csr-san-multiple-uses/m-p/199635#M59137</link>
      <description>&lt;P&gt;Hmmm... just re-read my previous post and I obviously have no idea what I'm talking about...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i need to re-read the statement "9" note in that document.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;below... from Palo...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;If you add a &lt;SPAN class="ph uicontrol"&gt;Host Name&lt;/SPAN&gt; attribute, it is a best practice for it to match the &lt;SPAN class="ph uicontrol"&gt;Common Name&lt;/SPAN&gt; (this is mandatory for GlobalProtect). The host name populates the Subject Alternative Name field of the certificate.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;perhaps someone else can decypher this....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Feb 2018 17:35:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-csr-san-multiple-uses/m-p/199635#M59137</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-02-08T17:35:20Z</dc:date>
    </item>
    <item>
      <title>Re: SSL CSR SAN Multiple Uses</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-csr-san-multiple-uses/m-p/199680#M59149</link>
      <description>&lt;P&gt;I've got the web gui configured for now. Had to gen a new CSR and make sure to include SANs for web gui, etc.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Next step is to configure GlobalProtect with the cert.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Feb 2018 23:13:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-csr-san-multiple-uses/m-p/199680#M59149</guid>
      <dc:creator>mike406</dc:creator>
      <dc:date>2018-02-08T23:13:33Z</dc:date>
    </item>
  </channel>
</rss>

