<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ssl decryption and temp cert management in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-and-temp-cert-management/m-p/229317#M65924</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I ran into an issue with the decryption cert being provide by my PA it had expired.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;it was 30 days in. I believe this is an issue with the date time comparision and timezones as it has fixed itself today.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How do i find / look at these temp certs via the cli&lt;/P&gt;&lt;P&gt;how can i delete / renew or purge them from the cli&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A&lt;/P&gt;</description>
    <pubDate>Tue, 04 Sep 2018 02:18:49 GMT</pubDate>
    <dc:creator>Alex_Samad</dc:creator>
    <dc:date>2018-09-04T02:18:49Z</dc:date>
    <item>
      <title>ssl decryption and temp cert management</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-and-temp-cert-management/m-p/229317#M65924</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I ran into an issue with the decryption cert being provide by my PA it had expired.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;it was 30 days in. I believe this is an issue with the date time comparision and timezones as it has fixed itself today.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How do i find / look at these temp certs via the cli&lt;/P&gt;&lt;P&gt;how can i delete / renew or purge them from the cli&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A&lt;/P&gt;</description>
      <pubDate>Tue, 04 Sep 2018 02:18:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-and-temp-cert-management/m-p/229317#M65924</guid>
      <dc:creator>Alex_Samad</dc:creator>
      <dc:date>2018-09-04T02:18:49Z</dc:date>
    </item>
    <item>
      <title>Re: ssl decryption and temp cert management</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-and-temp-cert-management/m-p/229455#M65967</link>
      <description>&lt;P&gt;Renew:&lt;/P&gt;&lt;PRE&gt;request certificate renew certificate-name &amp;lt;value&amp;gt; days-till-expiry &amp;lt;1-7300&amp;gt;&lt;/PRE&gt;&lt;P&gt;Revoke:&lt;/P&gt;&lt;PRE&gt;request certificate revoke certificate-name &amp;lt;value&amp;gt;&lt;/PRE&gt;&lt;P&gt;Show:&lt;/P&gt;&lt;PRE&gt;configure&lt;BR /&gt;show shared certificate-profile &amp;lt;name&amp;gt;&lt;/PRE&gt;&lt;P&gt;Show the expiration dates of all certs on the firewall:&lt;/P&gt;&lt;PRE&gt;set cli config-output-format set
configure
show shared certificate | match not-valid-after&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the CLI you can use this command to find other commands:&lt;/P&gt;&lt;PRE&gt;find command keyword &amp;lt;value&amp;gt;&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Sep 2018 21:01:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-and-temp-cert-management/m-p/229455#M65967</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-09-04T21:01:12Z</dc:date>
    </item>
    <item>
      <title>Re: ssl decryption and temp cert management</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-and-temp-cert-management/m-p/230796#M66294</link>
      <description>&lt;P&gt;These are not the certs created by the ssl proxy&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Should add my Support Engineer basically said you can't see them.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Sep 2018 01:17:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-and-temp-cert-management/m-p/230796#M66294</guid>
      <dc:creator>Alex_Samad</dc:creator>
      <dc:date>2018-09-14T01:17:47Z</dc:date>
    </item>
    <item>
      <title>Re: ssl decryption and temp cert management</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-and-temp-cert-management/m-p/230822#M66299</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/62286"&gt;@Alex_Samad&lt;/a&gt;&lt;/P&gt;&lt;P&gt;Ups ... I (completely) misunderstood something here &lt;span class="lia-unicode-emoji" title=":face_with_tongue:"&gt;😛&lt;/span&gt;&lt;/P&gt;&lt;P&gt;... in this case the possible commands you can find here:&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-View-SSL-Decryption-Information-from-the-CLI/ta-p/53276" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-View-SSL-Decryption-Information-from-the-CLI/ta-p/53276&lt;/A&gt;&lt;/P&gt;&lt;P&gt;With this command you can show at least some of the information that you asked for:&lt;/P&gt;&lt;PRE&gt;show system setting ssl-decrypt certificate-cache&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And yes, a certificate managment isn't really possible with these dynamically created certs.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Sep 2018 07:39:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-and-temp-cert-management/m-p/230822#M66299</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-09-14T07:39:17Z</dc:date>
    </item>
    <item>
      <title>Re: ssl decryption and temp cert management</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-and-temp-cert-management/m-p/230823#M66300</link>
      <description>&lt;P&gt;Or also always a good start to find TLS decryption informations:&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/SSL-decryption-resource-list/ta-p/70397" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/SSL-decryption-resource-list/ta-p/70397&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Sep 2018 07:41:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-and-temp-cert-management/m-p/230823#M66300</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-09-14T07:41:35Z</dc:date>
    </item>
    <item>
      <title>Re: ssl decryption and temp cert management</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-and-temp-cert-management/m-p/230824#M66301</link>
      <description>&lt;P&gt;thats strange&lt;/P&gt;&lt;P&gt;I do this&lt;/P&gt;&lt;PRE&gt;show system setting ssl-decrypt certificate-cache | match flynumber&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I know flynumber is in there , but this comes back with nothing&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Sep 2018 07:50:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-and-temp-cert-management/m-p/230824#M66301</guid>
      <dc:creator>Alex_Samad</dc:creator>
      <dc:date>2018-09-14T07:50:52Z</dc:date>
    </item>
  </channel>
</rss>

