<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Panorama 8.0 - EDL &amp;amp; Certificate Profile in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-8-0-edl-amp-certificate-profile/m-p/244943#M69861</link>
    <description>&lt;P&gt;I ran into the same issue.&amp;nbsp; Seems to be a design issue depending on your device group hierarchy.&amp;nbsp; In my case my firewalls are in a DG under an organizational DG.&amp;nbsp; For example shared &amp;gt; datacenter firewalls &amp;gt; data center A.&amp;nbsp; The issue is that I am managing security policy in the "&lt;SPAN&gt;datacenter firewalls" DG, which doesn't have any devices assigned to it - this is the issue.&amp;nbsp; &amp;nbsp;But I'm not able to create an EDL in the "datacenter firewalls" DG and reference a cert file from the template.&amp;nbsp; I hope Palo dev fixes this.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 04 Jan 2019 20:50:40 GMT</pubDate>
    <dc:creator>ice-quake</dc:creator>
    <dc:date>2019-01-04T20:50:40Z</dc:date>
    <item>
      <title>Panorama 8.0 - EDL &amp; Certificate Profile</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-8-0-edl-amp-certificate-profile/m-p/148098#M49516</link>
      <description>&lt;P&gt;Hi all,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I just ran into an issue while creating an External Dynamic List in Panorama 8.0. The source is a HTTPS address that requries a certificate profile for validation, so far so good. The problem is that I can't select any certificate profile, the list is empty. There's a certificate profile created under Device &amp;gt; Certificate Management &amp;gt; Certificate Profile for a template.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any suggestion what can be wrong or how to do this in a correct way?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture.JPG" style="width: 610px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/8183iF68C4B8D0CC6BCAB/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Capture.JPG" alt="Capture.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture.JPG" style="width: 619px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/8184iF015E0EC6897BF28/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Capture.JPG" alt="Capture.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Br,&lt;/P&gt;&lt;P&gt;Per Tenggren&lt;/P&gt;</description>
      <pubDate>Thu, 16 Mar 2017 19:48:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panorama-8-0-edl-amp-certificate-profile/m-p/148098#M49516</guid>
      <dc:creator>PerTenggren</dc:creator>
      <dc:date>2017-03-16T19:48:30Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama 8.0 - EDL &amp; Certificate Profile</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-8-0-edl-amp-certificate-profile/m-p/148107#M49518</link>
      <description>&lt;P&gt;Hi PerTenggren,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for posting in the community forums!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tested this out.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Verify if the firewall is also running 8.0. I can replicate this behavior if the Panorama is 8.0 while the firewall is pre-8.0. Secondly, check from the firewall itself, if you are able to create a EDL(with https link) and associate a certificate profile. This is an excerpt from the Admin Guide of the Panorama:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class="body_table"&gt;&lt;EM&gt;If the external dynamic list has an HTTPS URL, select an existing certificate profile (firewall and Panorama) or create a new &lt;SPAN class="GUI_Screen_Text"&gt;Certificate Profile&lt;/SPAN&gt; (firewall only) for authenticating the web server that hosts the list. For more information on configuring a certificate profile, see &lt;A title="" target="_blank"&gt;Device &amp;gt; Certificate Management &amp;gt; Certificate Profile&lt;/A&gt;.&lt;/EM&gt;&lt;/DIV&gt;&lt;DIV class="body_table"&gt;&lt;EM&gt;Default: &lt;SPAN class="GUI_Screen_Text"&gt;None (Disable Cert profile)&lt;/SPAN&gt;&lt;/EM&gt;&lt;/DIV&gt;&lt;DIV class="body_table"&gt;&lt;EM&gt;To maximize the number of external dynamic lists that you can use to enforce policy, use the same certificate profile to authenticate external dynamic lists that use the same source URL so that the lists count as only one external dynamic list. External dynamic lists from the same source URL that use different certificate profiles are counted as unique external dynamic lists.&lt;/EM&gt;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Anurag&lt;/P&gt;</description>
      <pubDate>Thu, 16 Mar 2017 20:37:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panorama-8-0-edl-amp-certificate-profile/m-p/148107#M49518</guid>
      <dc:creator>ansharma</dc:creator>
      <dc:date>2017-03-16T20:37:51Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama 8.0 - EDL &amp; Certificate Profile</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-8-0-edl-amp-certificate-profile/m-p/148109#M49519</link>
      <description>&lt;P&gt;First guess would be that you are missing the intermediate cert on your cert profile. The full chain needs to be included ...because reasons &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Mar 2017 20:40:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panorama-8-0-edl-amp-certificate-profile/m-p/148109#M49519</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-03-16T20:40:42Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama 8.0 - EDL &amp; Certificate Profile</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-8-0-edl-amp-certificate-profile/m-p/148120#M49521</link>
      <description>&lt;P&gt;After&amp;nbsp;further investigation it seems&amp;nbsp;that EDL created as "shared" can't list any certificate profile, but it works if assigning the EDL to a specific device group.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Mar 2017 21:36:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panorama-8-0-edl-amp-certificate-profile/m-p/148120#M49521</guid>
      <dc:creator>PerTenggren</dc:creator>
      <dc:date>2017-03-16T21:36:22Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama 8.0 - EDL &amp; Certificate Profile</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-8-0-edl-amp-certificate-profile/m-p/148121#M49522</link>
      <description>Tested that and yes, you are correct! This makes sense to me, as it cannot check whether it's present on a particular device group or not, within a configuration piece.&lt;BR /&gt;</description>
      <pubDate>Thu, 16 Mar 2017 21:46:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panorama-8-0-edl-amp-certificate-profile/m-p/148121#M49522</guid>
      <dc:creator>ansharma</dc:creator>
      <dc:date>2017-03-16T21:46:30Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama 8.0 - EDL &amp; Certificate Profile</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-8-0-edl-amp-certificate-profile/m-p/244943#M69861</link>
      <description>&lt;P&gt;I ran into the same issue.&amp;nbsp; Seems to be a design issue depending on your device group hierarchy.&amp;nbsp; In my case my firewalls are in a DG under an organizational DG.&amp;nbsp; For example shared &amp;gt; datacenter firewalls &amp;gt; data center A.&amp;nbsp; The issue is that I am managing security policy in the "&lt;SPAN&gt;datacenter firewalls" DG, which doesn't have any devices assigned to it - this is the issue.&amp;nbsp; &amp;nbsp;But I'm not able to create an EDL in the "datacenter firewalls" DG and reference a cert file from the template.&amp;nbsp; I hope Palo dev fixes this.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Jan 2019 20:50:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panorama-8-0-edl-amp-certificate-profile/m-p/244943#M69861</guid>
      <dc:creator>ice-quake</dc:creator>
      <dc:date>2019-01-04T20:50:40Z</dc:date>
    </item>
  </channel>
</rss>

