<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Wildcard certificate on PA firewalls in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/wildcard-certificate-on-pa-firewalls/m-p/237928#M68172</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/92520"&gt;@AlexandroDelAngel&lt;/a&gt;&lt;/P&gt;&lt;P&gt;I was asking about the version and the permissions because may be you are seeing this bug (which is fixes in PAN-OS 8.0.10):&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_20181031-124755_Chrome.jpg" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/17373iE8570409C1CE7CCE/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Screenshot_20181031-124755_Chrome.jpg" alt="Screenshot_20181031-124755_Chrome.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 31 Oct 2018 11:52:03 GMT</pubDate>
    <dc:creator>Remo</dc:creator>
    <dc:date>2018-10-31T11:52:03Z</dc:date>
    <item>
      <title>Wildcard certificate on PA firewalls</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildcard-certificate-on-pa-firewalls/m-p/237857#M68156</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm trying to create a CSR in Panorama in order to get a wildcard certificate from our third party CA.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In order platforms, I define as common name the format *.mydomain.com but in Palo Alto I'm getting an error:&amp;nbsp;&lt;SPAN&gt;Failed to generate certificate and key.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;When I change the common name to .mydomain.com it allows me to create the CSR.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I just wanted to touch base with you guys in order to know about your experience working with wildcards on Palo Alto Plattform.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Any response will be very appreciated.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thank you,&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Oct 2018 22:51:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildcard-certificate-on-pa-firewalls/m-p/237857#M68156</guid>
      <dc:creator>AlexandroDelAngel</dc:creator>
      <dc:date>2018-10-30T22:51:44Z</dc:date>
    </item>
    <item>
      <title>Re: Wildcard certificate on PA firewalls</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildcard-certificate-on-pa-firewalls/m-p/237880#M68160</link>
      <description>&lt;P&gt;Are you choosing Signed by&amp;nbsp;External Authority (CSR)?&lt;/P&gt;&lt;P&gt;Try to change Certificate Name to something else but leave Common Name to&amp;nbsp;&lt;SPAN&gt;*.mydomain.com&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 31 Oct 2018 00:12:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildcard-certificate-on-pa-firewalls/m-p/237880#M68160</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2018-10-31T00:12:00Z</dc:date>
    </item>
    <item>
      <title>Re: Wildcard certificate on PA firewalls</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildcard-certificate-on-pa-firewalls/m-p/237885#M68161</link>
      <description>&lt;P&gt;Yup, just tested it as described by &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/15603"&gt;@Raido_Rattameister&lt;/a&gt;&amp;nbsp;and it successfully generated a CSR for a wildcard cert.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;(Remember to add *.mydomaim.com also as "hostname" when you generate the CSR)&lt;/P&gt;</description>
      <pubDate>Wed, 31 Oct 2018 00:33:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildcard-certificate-on-pa-firewalls/m-p/237885#M68161</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-10-31T00:33:02Z</dc:date>
    </item>
    <item>
      <title>Re: Wildcard certificate on PA firewalls</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildcard-certificate-on-pa-firewalls/m-p/237886#M68162</link>
      <description>&lt;P&gt;Thanks for your feedback Raido,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes Sir, I'm choosing Signed by External Authority (CSR) and I'm still getting the same error. The error clears out when I change the Common name to .mydomain.com (removing the *).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For the Certificate Name I'm adding wildcard-mydomain-com.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Other thing I forgot to mention was that I'm choosing Algorithm Elliptic Curve DSA.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Wed, 31 Oct 2018 00:35:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildcard-certificate-on-pa-firewalls/m-p/237886#M68162</guid>
      <dc:creator>AlexandroDelAngel</dc:creator>
      <dc:date>2018-10-31T00:35:54Z</dc:date>
    </item>
    <item>
      <title>Re: Wildcard certificate on PA firewalls</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildcard-certificate-on-pa-firewalls/m-p/237888#M68163</link>
      <description>&lt;P&gt;Thanks vsys,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I just tested that and got error: "&lt;SPAN&gt;request -&amp;gt; certificate -&amp;gt; generate -&amp;gt; hostname '*.mydomain.com' is invalid"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Could you test it for an Elliptic Curve DSA cert?&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks,&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 31 Oct 2018 00:39:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildcard-certificate-on-pa-firewalls/m-p/237888#M68163</guid>
      <dc:creator>AlexandroDelAngel</dc:creator>
      <dc:date>2018-10-31T00:39:51Z</dc:date>
    </item>
    <item>
      <title>Re: Wildcard certificate on PA firewalls</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildcard-certificate-on-pa-firewalls/m-p/237889#M68164</link>
      <description>&lt;P&gt;What PAN-OS version do you have installed and are you logged in with a user that has "superuser" privileges?&lt;/P&gt;</description>
      <pubDate>Wed, 31 Oct 2018 00:56:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildcard-certificate-on-pa-firewalls/m-p/237889#M68164</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-10-31T00:56:36Z</dc:date>
    </item>
    <item>
      <title>Re: Wildcard certificate on PA firewalls</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildcard-certificate-on-pa-firewalls/m-p/237894#M68165</link>
      <description>&lt;P&gt;It would help to know Panorama version as&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;&amp;nbsp;mentioned.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In my case Panorama 8.1.4&lt;/P&gt;&lt;P&gt;Works like a charm.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="wildcard1.PNG" style="width: 414px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/17369iD8C61C62E62DD807/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="wildcard1.PNG" alt="wildcard1.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="wildcard2.PNG" style="width: 487px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/17367iF00D4558E4E56CE1/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="wildcard2.PNG" alt="wildcard2.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="wildcard3.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/17368iB1721CB253D97432/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="wildcard3.PNG" alt="wildcard3.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 31 Oct 2018 01:28:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildcard-certificate-on-pa-firewalls/m-p/237894#M68165</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2018-10-31T01:28:02Z</dc:date>
    </item>
    <item>
      <title>Re: Wildcard certificate on PA firewalls</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildcard-certificate-on-pa-firewalls/m-p/237911#M68170</link>
      <description>&lt;P&gt;Works fine on PAN OS 7.1.16 too. Defined *.mydomain.com&amp;nbsp;in both CN and hostname feilds with superuser account and it was generated successfully. So was the commit&amp;nbsp;too.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="pic1.PNG" style="width: 392px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/17370iB9AC0259915E83D7/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="pic1.PNG" alt="pic1.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="pic2.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/17371i50C5F30D8C1E4CF0/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="pic2.PNG" alt="pic2.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 31 Oct 2018 07:13:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildcard-certificate-on-pa-firewalls/m-p/237911#M68170</guid>
      <dc:creator>Rajesh12</dc:creator>
      <dc:date>2018-10-31T07:13:32Z</dc:date>
    </item>
    <item>
      <title>Re: Wildcard certificate on PA firewalls</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildcard-certificate-on-pa-firewalls/m-p/237928#M68172</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/92520"&gt;@AlexandroDelAngel&lt;/a&gt;&lt;/P&gt;&lt;P&gt;I was asking about the version and the permissions because may be you are seeing this bug (which is fixes in PAN-OS 8.0.10):&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_20181031-124755_Chrome.jpg" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/17373iE8570409C1CE7CCE/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Screenshot_20181031-124755_Chrome.jpg" alt="Screenshot_20181031-124755_Chrome.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 31 Oct 2018 11:52:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildcard-certificate-on-pa-firewalls/m-p/237928#M68172</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-10-31T11:52:03Z</dc:date>
    </item>
    <item>
      <title>Re: Wildcard certificate on PA firewalls</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildcard-certificate-on-pa-firewalls/m-p/237946#M68174</link>
      <description>&lt;P&gt;Thanks for your feedback Team,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Our Panorama is already in 8.0.10 and yes, my account is a superuser. I guess it's time to escalate to PA Support, I just don't want to purchase a useless wildcard certificate.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind Regards,&lt;/P&gt;</description>
      <pubDate>Wed, 31 Oct 2018 13:13:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildcard-certificate-on-pa-firewalls/m-p/237946#M68174</guid>
      <dc:creator>AlexandroDelAngel</dc:creator>
      <dc:date>2018-10-31T13:13:54Z</dc:date>
    </item>
    <item>
      <title>Re: Wildcard certificate on PA firewalls</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildcard-certificate-on-pa-firewalls/m-p/237957#M68178</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/92520"&gt;@AlexandroDelAngel&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, looks like there is something wrong. (Did you try the generation with another browser?, if you're using windows - as bad as this sounds - try it once with IE)&lt;/P&gt;&lt;P&gt;And while you talk about this with PA support ... you could simply use tools like openssl to generate the key and CSR for you.&lt;/P&gt;</description>
      <pubDate>Wed, 31 Oct 2018 13:56:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildcard-certificate-on-pa-firewalls/m-p/237957#M68178</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-10-31T13:56:01Z</dc:date>
    </item>
    <item>
      <title>Re: Wildcard certificate on PA firewalls</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildcard-certificate-on-pa-firewalls/m-p/237961#M68180</link>
      <description>&lt;P&gt;Thanks for the recommendation vsys,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I just tried with IE and got the same error, OpenSSL will work fine for sure.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind Regards,&lt;/P&gt;</description>
      <pubDate>Wed, 31 Oct 2018 14:24:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildcard-certificate-on-pa-firewalls/m-p/237961#M68180</guid>
      <dc:creator>AlexandroDelAngel</dc:creator>
      <dc:date>2018-10-31T14:24:11Z</dc:date>
    </item>
    <item>
      <title>Re: Wildcard certificate on PA firewalls</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildcard-certificate-on-pa-firewalls/m-p/238400#M68300</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you very much everyone for your support, I left the Common Name as .mydomain.com and then on the CA directly you can indicate this is a wildcard certificate and they will prepend the * for you so the final result will be *.mydomain.com.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Then when I imported the signed certificate it was successful.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind Regards!&lt;/P&gt;</description>
      <pubDate>Fri, 02 Nov 2018 19:20:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildcard-certificate-on-pa-firewalls/m-p/238400#M68300</guid>
      <dc:creator>AlexandroDelAngel</dc:creator>
      <dc:date>2018-11-02T19:20:51Z</dc:date>
    </item>
  </channel>
</rss>

