<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Creating New Cert from local trusted root CA in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/creating-new-cert-from-local-trusted-root-ca/m-p/249159#M70863</link>
    <description>&lt;P&gt;You can generate a new certificate for GUI as well, but you need not to. you can use the same root cert for GUI as well. call it under ssl/tls service profile. use it under management configuration.&lt;/P&gt;</description>
    <pubDate>Thu, 07 Feb 2019 08:38:12 GMT</pubDate>
    <dc:creator>Abdul_Razaq</dc:creator>
    <dc:date>2019-02-07T08:38:12Z</dc:date>
    <item>
      <title>Creating New Cert from local trusted root CA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/creating-new-cert-from-local-trusted-root-ca/m-p/249072#M70850</link>
      <description>&lt;P&gt;i have local trusted root CA on the PA.&lt;/P&gt;&lt;P&gt;Also i have ssl decryption cert on the PA.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is it possible i can create new cert from root and use it for web gui?&lt;/P&gt;</description>
      <pubDate>Wed, 06 Feb 2019 20:34:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/creating-new-cert-from-local-trusted-root-ca/m-p/249072#M70850</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-02-06T20:34:57Z</dc:date>
    </item>
    <item>
      <title>Re: Creating New Cert from local trusted root CA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/creating-new-cert-from-local-trusted-root-ca/m-p/249159#M70863</link>
      <description>&lt;P&gt;You can generate a new certificate for GUI as well, but you need not to. you can use the same root cert for GUI as well. call it under ssl/tls service profile. use it under management configuration.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Feb 2019 08:38:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/creating-new-cert-from-local-trusted-root-ca/m-p/249159#M70863</guid>
      <dc:creator>Abdul_Razaq</dc:creator>
      <dc:date>2019-02-07T08:38:12Z</dc:date>
    </item>
    <item>
      <title>Re: Creating New Cert from local trusted root CA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/creating-new-cert-from-local-trusted-root-ca/m-p/249191#M70870</link>
      <description>&lt;P&gt;it do not work.&lt;/P&gt;&lt;P&gt;under ssl/tls profile the CA root ceret does not show up?&lt;/P&gt;</description>
      <pubDate>Thu, 07 Feb 2019 12:55:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/creating-new-cert-from-local-trusted-root-ca/m-p/249191#M70870</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-02-07T12:55:46Z</dc:date>
    </item>
    <item>
      <title>Re: Creating New Cert from local trusted root CA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/creating-new-cert-from-local-trusted-root-ca/m-p/249202#M70874</link>
      <description>&lt;P&gt;Do you have private key of same certificate inside PA ? . then only you can use the certificate for web access&lt;/P&gt;</description>
      <pubDate>Thu, 07 Feb 2019 13:54:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/creating-new-cert-from-local-trusted-root-ca/m-p/249202#M70874</guid>
      <dc:creator>Abdul_Razaq</dc:creator>
      <dc:date>2019-02-07T13:54:02Z</dc:date>
    </item>
    <item>
      <title>Re: Creating New Cert from local trusted root CA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/creating-new-cert-from-local-trusted-root-ca/m-p/249386#M70920</link>
      <description>&lt;P&gt;No CA root cert has no private key checked.&lt;/P&gt;</description>
      <pubDate>Fri, 08 Feb 2019 03:39:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/creating-new-cert-from-local-trusted-root-ca/m-p/249386#M70920</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-02-08T03:39:39Z</dc:date>
    </item>
    <item>
      <title>Re: Creating New Cert from local trusted root CA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/creating-new-cert-from-local-trusted-root-ca/m-p/250287#M71186</link>
      <description>&lt;P&gt;any one can answer this?&lt;/P&gt;</description>
      <pubDate>Fri, 15 Feb 2019 21:09:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/creating-new-cert-from-local-trusted-root-ca/m-p/250287#M71186</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-02-15T21:09:32Z</dc:date>
    </item>
    <item>
      <title>Re: Creating New Cert from local trusted root CA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/creating-new-cert-from-local-trusted-root-ca/m-p/250293#M71190</link>
      <description>&lt;P&gt;Abdul eluded to it - you can't generate a new cert from that root without the private key. If that was a thing you could do, you could just grab GoDaddy or Letsencrypt's public root cert and create a valid cert for any domain. It's a fundamental part of PKI - ff you don't have the private key, you can't sign a new cert issued by that CA.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Feb 2019 22:04:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/creating-new-cert-from-local-trusted-root-ca/m-p/250293#M71190</guid>
      <dc:creator>gwesson</dc:creator>
      <dc:date>2019-02-15T22:04:48Z</dc:date>
    </item>
    <item>
      <title>Re: Creating New Cert from local trusted root CA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/creating-new-cert-from-local-trusted-root-ca/m-p/250295#M71192</link>
      <description>&lt;P&gt;Many thanks for answering the question.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Feb 2019 22:23:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/creating-new-cert-from-local-trusted-root-ca/m-p/250295#M71192</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-02-15T22:23:44Z</dc:date>
    </item>
    <item>
      <title>Re: Creating New Cert from local trusted root CA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/creating-new-cert-from-local-trusted-root-ca/m-p/250309#M71196</link>
      <description>&lt;P&gt;Besides the fact that the whole trust system of the PKI wouln't work if everyone could sign certs with a publoc key, the money-making machine of the public CA also wouln't work &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 16 Feb 2019 13:13:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/creating-new-cert-from-local-trusted-root-ca/m-p/250309#M71196</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2019-02-16T13:13:35Z</dc:date>
    </item>
  </channel>
</rss>

