<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic VPN certificate expires in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-certificate-expires/m-p/222901#M64083</link>
    <description>&lt;P&gt;Hey!&lt;/P&gt;&lt;P&gt;My firewall is a PA-3020 with 8.0.7. There is a Global Protect gateway and portal, users can connect via Global Protect.&lt;/P&gt;&lt;P&gt;As portal address in the global protect app, we are using an address that is availabe in public dns.&lt;/P&gt;&lt;P&gt;Additionally, there is a public signed certificate. When I do https://portal-address in a browser, I can see that the certificate expires tomorrow.&lt;/P&gt;&lt;P&gt;Can someone tell me what to do now?&lt;/P&gt;&lt;P&gt;Do I have to make a CSR? And where do I have to replace the certificate?&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;</description>
    <pubDate>Thu, 19 Jul 2018 11:15:25 GMT</pubDate>
    <dc:creator>MPI-AE</dc:creator>
    <dc:date>2018-07-19T11:15:25Z</dc:date>
    <item>
      <title>VPN certificate expires</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-certificate-expires/m-p/222901#M64083</link>
      <description>&lt;P&gt;Hey!&lt;/P&gt;&lt;P&gt;My firewall is a PA-3020 with 8.0.7. There is a Global Protect gateway and portal, users can connect via Global Protect.&lt;/P&gt;&lt;P&gt;As portal address in the global protect app, we are using an address that is availabe in public dns.&lt;/P&gt;&lt;P&gt;Additionally, there is a public signed certificate. When I do https://portal-address in a browser, I can see that the certificate expires tomorrow.&lt;/P&gt;&lt;P&gt;Can someone tell me what to do now?&lt;/P&gt;&lt;P&gt;Do I have to make a CSR? And where do I have to replace the certificate?&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jul 2018 11:15:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-certificate-expires/m-p/222901#M64083</guid>
      <dc:creator>MPI-AE</dc:creator>
      <dc:date>2018-07-19T11:15:25Z</dc:date>
    </item>
    <item>
      <title>Re: VPN certificate expires</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-certificate-expires/m-p/222924#M64087</link>
      <description>&lt;P&gt;Under Network -&amp;gt; GlobalProtect -&amp;gt; Portals -&amp;gt; (Your portal) -&amp;gt; Authentication, take note of the SSL/TLS Service Profile&lt;/P&gt;&lt;P&gt;You should probably do the same for your Gateway, in case it is different&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Under Device -&amp;gt; Certificate Management -&amp;gt; SSL/TLS Service Profile -&amp;gt; (Profile from above), take note of the certificate&lt;/P&gt;&lt;P&gt;This is the certificate used by your Portal or Gateway&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Under Device -&amp;gt; Certificate Management -&amp;gt; Certificates, locate this certificate, and click "renew" at the bottom of the screen to generate a new CSR, export the CSR, submit it to your CA, Import the new certificate (and signing chain, if it changes)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Update the SSL/TLS Service Profile(s) with the new certificate(s)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;you can see the expiration dates of any certificates you have on teh Certificates page, in case any more are expiring soon.&amp;nbsp; It often takes a few days to renew a certificate so it pays to be pro-active here&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jul 2018 11:34:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-certificate-expires/m-p/222924#M64087</guid>
      <dc:creator>JoeAndreini</dc:creator>
      <dc:date>2018-07-19T11:34:32Z</dc:date>
    </item>
    <item>
      <title>Re: VPN certificate expires</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-certificate-expires/m-p/222928#M64088</link>
      <description>&lt;P&gt;Thank you, how much days am I supposed to extend the certificate?&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jul 2018 12:07:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-certificate-expires/m-p/222928#M64088</guid>
      <dc:creator>MPI-AE</dc:creator>
      <dc:date>2018-07-19T12:07:42Z</dc:date>
    </item>
    <item>
      <title>Re: VPN certificate expires</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-certificate-expires/m-p/222939#M64089</link>
      <description>&lt;P&gt;Typical would be one or two years, sometimes three.&amp;nbsp; That is really a policy question for the business - in theory having a certificate out there longer is a risk, but it is more convenient, and usually less expensive per year.&amp;nbsp; The number of days in your CSR is typically ignored by the CA and replaced with whatever you pay them for.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jul 2018 13:32:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-certificate-expires/m-p/222939#M64089</guid>
      <dc:creator>JoeAndreini</dc:creator>
      <dc:date>2018-07-19T13:32:34Z</dc:date>
    </item>
    <item>
      <title>Re: VPN certificate expires</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-certificate-expires/m-p/222940#M64090</link>
      <description>&lt;P&gt;Thank you!&lt;/P&gt;&lt;P&gt;I did the whole procedure and vpn still works.&lt;/P&gt;&lt;P&gt;When I imported the signed certficate, I imported the server certificate itself, not with the complete ca chain.&lt;/P&gt;&lt;P&gt;Under Device -&amp;gt; Certificates, the certificate appears as single certificate, without the ca chain.&lt;/P&gt;&lt;P&gt;Is that a problem?&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jul 2018 13:36:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-certificate-expires/m-p/222940#M64090</guid>
      <dc:creator>MPI-AE</dc:creator>
      <dc:date>2018-07-19T13:36:39Z</dc:date>
    </item>
    <item>
      <title>Re: VPN certificate expires</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-certificate-expires/m-p/222942#M64091</link>
      <description>&lt;P&gt;it can be.&amp;nbsp; your CA should have a package you can download with the root and intermediate certificates you can import to complete the chain.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jul 2018 14:24:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-certificate-expires/m-p/222942#M64091</guid>
      <dc:creator>JoeAndreini</dc:creator>
      <dc:date>2018-07-19T14:24:47Z</dc:date>
    </item>
    <item>
      <title>Re: VPN certificate expires</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-certificate-expires/m-p/222943#M64092</link>
      <description>&lt;P&gt;Yes, there is such a package.&lt;/P&gt;&lt;P&gt;Does the firewall automatically link this package with the new server certificate?&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jul 2018 14:30:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-certificate-expires/m-p/222943#M64092</guid>
      <dc:creator>MPI-AE</dc:creator>
      <dc:date>2018-07-19T14:30:52Z</dc:date>
    </item>
    <item>
      <title>Re: VPN certificate expires</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-certificate-expires/m-p/222958#M64094</link>
      <description>&lt;P&gt;Unzip the package and import the certificates just as you did the server (your GP certificate)&amp;nbsp;certificate, it will show a "tree" with the root and intermediate automatically, based on the information in the server cert.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jul 2018 16:13:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-certificate-expires/m-p/222958#M64094</guid>
      <dc:creator>JoeAndreini</dc:creator>
      <dc:date>2018-07-19T16:13:58Z</dc:date>
    </item>
  </channel>
</rss>

