<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Certificate can not be deleted in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/certificate-can-not-be-deleted/m-p/247020#M70316</link>
    <description>&lt;P&gt;I expereinced something similar, not sure if it's exactly the same.&amp;nbsp; I think if you do a bug scrub there was a bug-id identified for this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I opened a case a while back on this topic:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here are the relevant case notes (&lt;SPAN&gt;00935485 - 7/16/2018&amp;nbsp;- PAN-OS 8.0.10 (at the time))&lt;/SPAN&gt;:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;"Thank you for the time spent on the zoom session today. Below is the summary:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;We checked via GUI and we do not see the two CSRs under &amp;lt;XXX&amp;gt;RootCA&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;We loaded older config from July 5th from when the CSRs were generated, and we saw them in the XML file&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;We loaded yesterday's config(596) and that one had the CSRs too&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;We checked current config via CLI, and the CSRs are not there&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;We tried generating a bogus CSR, and that showed up in GUI correctly&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;You mentioned to just go ahead with generating the CSRs again, and we see both showed up correctly today.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;As discussed, I will now close the case."&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 22 Jan 2019 19:36:05 GMT</pubDate>
    <dc:creator>Brandon_Wertz</dc:creator>
    <dc:date>2019-01-22T19:36:05Z</dc:date>
    <item>
      <title>Certificate can not be deleted</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/certificate-can-not-be-deleted/m-p/246939#M70295</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Im having a weird issue in Palo Alto. First of all, we dont have vsys configured but in the confgi we can see the field &amp;lt;vsys&amp;gt; and many config in it.&lt;/P&gt;&lt;P&gt;Basically whn we run a commit we receive a warning about "certificate duplicate". We go to devices-&amp;gt; certificates and we can only see one certificate with that CN. But if we check the .xml config we can see this certificate in the partition SHARE and VSYS1. so what is happening that? how can delete the nonuse certificate?&lt;/P&gt;</description>
      <pubDate>Tue, 22 Jan 2019 11:29:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/certificate-can-not-be-deleted/m-p/246939#M70295</guid>
      <dc:creator>BigPalo</dc:creator>
      <dc:date>2019-01-22T11:29:01Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate can not be deleted</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/certificate-can-not-be-deleted/m-p/246992#M70312</link>
      <description>&lt;P&gt;Have you imported the configuration from somewhere else, mainly from the Migration tool?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I had something similar when I was working on one migration and had config imported from the Migration tool. I had dublicated object issues (not the certificates). In the GUI there was only one object, but under the xml config there were actually two completely identical.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you have the certificate backup (the private and the public). I would suggest you to:&lt;/P&gt;&lt;P&gt;- Remove the certificate, just form the GUI, select it and delete it&lt;BR /&gt;- Commit&lt;BR /&gt;- Import back the cert.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The other way would probably be to review xml file, delete the dublicate entry for the certificate, by hand and import it back to the fw. But I believe if you do it via the GUI, it will delete everything (both entries) and then you can import it once again.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Jan 2019 17:39:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/certificate-can-not-be-deleted/m-p/246992#M70312</guid>
      <dc:creator>A_Astardzhiev</dc:creator>
      <dc:date>2019-01-22T17:39:02Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate can not be deleted</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/certificate-can-not-be-deleted/m-p/247018#M70315</link>
      <description>&lt;P&gt;You should also be able to delete it from CLI. Run "show shared certificate ?" and you should be able to see both certificates. Run "delete shared certificate &amp;lt;cert name&amp;gt;" to delete it. That would be easier than editing the XML file.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Jan 2019 19:09:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/certificate-can-not-be-deleted/m-p/247018#M70315</guid>
      <dc:creator>tcarlisle-ksa</dc:creator>
      <dc:date>2019-01-22T19:09:41Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate can not be deleted</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/certificate-can-not-be-deleted/m-p/247020#M70316</link>
      <description>&lt;P&gt;I expereinced something similar, not sure if it's exactly the same.&amp;nbsp; I think if you do a bug scrub there was a bug-id identified for this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I opened a case a while back on this topic:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here are the relevant case notes (&lt;SPAN&gt;00935485 - 7/16/2018&amp;nbsp;- PAN-OS 8.0.10 (at the time))&lt;/SPAN&gt;:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;"Thank you for the time spent on the zoom session today. Below is the summary:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;We checked via GUI and we do not see the two CSRs under &amp;lt;XXX&amp;gt;RootCA&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;We loaded older config from July 5th from when the CSRs were generated, and we saw them in the XML file&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;We loaded yesterday's config(596) and that one had the CSRs too&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;We checked current config via CLI, and the CSRs are not there&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;We tried generating a bogus CSR, and that showed up in GUI correctly&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;You mentioned to just go ahead with generating the CSRs again, and we see both showed up correctly today.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;As discussed, I will now close the case."&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Jan 2019 19:36:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/certificate-can-not-be-deleted/m-p/247020#M70316</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2019-01-22T19:36:05Z</dc:date>
    </item>
  </channel>
</rss>

