<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Self-signed Root CA Certificate FQDN? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/self-signed-root-ca-certificate-fqdn/m-p/220030#M63490</link>
    <description>I’m planning a test deployment of a globalprotect vpn, so currently going through the guides to see what’s needed. Part of the requirements if not using a trusted CA is to generate a self-signed root CA.&lt;BR /&gt;&lt;BR /&gt;What should the FQDN be on this cert? The deployment will have inside, outside and mgmt interfaces. Should it be the ip on the mgmt interface?</description>
    <pubDate>Sun, 01 Jul 2018 08:45:01 GMT</pubDate>
    <dc:creator>welly_59</dc:creator>
    <dc:date>2018-07-01T08:45:01Z</dc:date>
    <item>
      <title>Self-signed Root CA Certificate FQDN?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/self-signed-root-ca-certificate-fqdn/m-p/220030#M63490</link>
      <description>I’m planning a test deployment of a globalprotect vpn, so currently going through the guides to see what’s needed. Part of the requirements if not using a trusted CA is to generate a self-signed root CA.&lt;BR /&gt;&lt;BR /&gt;What should the FQDN be on this cert? The deployment will have inside, outside and mgmt interfaces. Should it be the ip on the mgmt interface?</description>
      <pubDate>Sun, 01 Jul 2018 08:45:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/self-signed-root-ca-certificate-fqdn/m-p/220030#M63490</guid>
      <dc:creator>welly_59</dc:creator>
      <dc:date>2018-07-01T08:45:01Z</dc:date>
    </item>
    <item>
      <title>Re: Self-signed Root CA Certificate FQDN?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/self-signed-root-ca-certificate-fqdn/m-p/220037#M63491</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/91200"&gt;@welly_59&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you also plan to implement an internal gateway?&lt;/P&gt;&lt;P&gt;In the root CA cert it does not really matter what you enter as CN. This cert you simply need to install on your computer. As portal and gateway cert you then you need to create another cert which is signed by the previously created root CA cert. In this cert I would use the FQDN or IP of the portal and gateway. Make sure that you also add the same as SAN (server alternative name) to the cert when you create it.&lt;/P&gt;&lt;P&gt;For the management interface cert I recommend to use a different cert than for portal/gateway.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps,&lt;/P&gt;&lt;P&gt;Remo&lt;/P&gt;</description>
      <pubDate>Sun, 01 Jul 2018 10:29:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/self-signed-root-ca-certificate-fqdn/m-p/220037#M63491</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-07-01T10:29:28Z</dc:date>
    </item>
  </channel>
</rss>

