<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic External Certificate Renewal in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/external-certificate-renewal/m-p/226326#M65158</link>
    <description>&lt;P&gt;I can't for the life of me figure out the process to renew a certificate issued from an external CA.&amp;nbsp; We have a cert purchased from Thawte for our Global Protect gateway.&amp;nbsp; It will expire shortly and Thawte wants a csr file for the renewal.&amp;nbsp; Selecting renew in the Certificates tab only allows me to select how many days, which is not helpful.&amp;nbsp; I have gone through the online docs and find many options for a new cert, but nothing on the process to renew.&amp;nbsp; Seems like I am missing something really simple.&lt;/P&gt;</description>
    <pubDate>Tue, 07 Aug 2018 17:44:42 GMT</pubDate>
    <dc:creator>ToddJohnsen</dc:creator>
    <dc:date>2018-08-07T17:44:42Z</dc:date>
    <item>
      <title>External Certificate Renewal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/external-certificate-renewal/m-p/226326#M65158</link>
      <description>&lt;P&gt;I can't for the life of me figure out the process to renew a certificate issued from an external CA.&amp;nbsp; We have a cert purchased from Thawte for our Global Protect gateway.&amp;nbsp; It will expire shortly and Thawte wants a csr file for the renewal.&amp;nbsp; Selecting renew in the Certificates tab only allows me to select how many days, which is not helpful.&amp;nbsp; I have gone through the online docs and find many options for a new cert, but nothing on the process to renew.&amp;nbsp; Seems like I am missing something really simple.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Aug 2018 17:44:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/external-certificate-renewal/m-p/226326#M65158</guid>
      <dc:creator>ToddJohnsen</dc:creator>
      <dc:date>2018-08-07T17:44:42Z</dc:date>
    </item>
    <item>
      <title>Re: External Certificate Renewal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/external-certificate-renewal/m-p/226335#M65161</link>
      <description>&lt;P&gt;It can be simple, but it depends on the CA. I'm not all that familiar with how Thawte works these days, but most public CAs have the option of just renewing now instead of having to submit a new CSR.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you do have that option at Thawte, have them issue the new certificate to you. When you get the PEM or DER cert, just import it using the&amp;nbsp;&lt;U&gt;&lt;STRONG&gt;exact&lt;/STRONG&gt;&lt;/U&gt; same name as the one you're renewing. When you do that, the import overwrites the public key only, leaving your existing private key in tact.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If Thawte requires a new CSR, then it gets more complicated. I find it easier to just generate a brand new CSR and just update the certificate profiles and such to the new cert. If you still have the original CSR you submitted to Thawte, you can actually resubmit that same one and the signed cert should import just fine.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Aug 2018 17:54:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/external-certificate-renewal/m-p/226335#M65161</guid>
      <dc:creator>gwesson</dc:creator>
      <dc:date>2018-08-07T17:54:01Z</dc:date>
    </item>
    <item>
      <title>Re: External Certificate Renewal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/external-certificate-renewal/m-p/226342#M65162</link>
      <description>&lt;P&gt;Someone over in Contracts is doing the process.&amp;nbsp; I feel like they only have ever done new certs so i am pushing back.&amp;nbsp; Just needed to make sure I am not crazy.&amp;nbsp; Once I figure it out I will post back to confirm.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Aug 2018 18:01:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/external-certificate-renewal/m-p/226342#M65162</guid>
      <dc:creator>ToddJohnsen</dc:creator>
      <dc:date>2018-08-07T18:01:18Z</dc:date>
    </item>
    <item>
      <title>Re: External Certificate Renewal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/external-certificate-renewal/m-p/227052#M65347</link>
      <description>&lt;P&gt;So, turns out that Thawte and a few others really do require a full csr for renewal.&amp;nbsp; My mistake was creating the cert on the Palo Alto itself.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Long story short, don't create an external cert that you plan to renew on the Palo Alto itself.&amp;nbsp; I did find the original csr and did use it to create a new cert.&amp;nbsp; Imported it over the old with the exact same name, but the commit failed due to key mismatch.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;= Don't create external certificates on the Palo Alto =&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have installed openssl on a vm&amp;nbsp;in order to create the cert from now on.&amp;nbsp; I also documented the crap out of it since I will only do this every two years.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Again,&amp;nbsp;&lt;SPAN&gt;Don't create external certificates on the Palo Alto.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;In case you missed it, this was ridiculously over complicated.&amp;nbsp; I finally found something to complain about with my Palo Alto.&amp;nbsp; This would also explain why there is no documentation on this process at all.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Aug 2018 15:50:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/external-certificate-renewal/m-p/227052#M65347</guid>
      <dc:creator>ToddJohnsen</dc:creator>
      <dc:date>2018-08-14T15:50:13Z</dc:date>
    </item>
    <item>
      <title>Re: External Certificate Renewal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/external-certificate-renewal/m-p/385492#M90155</link>
      <description>&lt;P&gt;Let me add, that you will have to force users to reconnect after this change.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Feb 2021 20:42:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/external-certificate-renewal/m-p/385492#M90155</guid>
      <dc:creator>Sec101</dc:creator>
      <dc:date>2021-02-11T20:42:09Z</dc:date>
    </item>
  </channel>
</rss>

