<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Fighting the cli ... sigh - how to import a cert via the cli in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/fighting-the-cli-sigh-how-to-import-a-cert-via-the-cli/m-p/272803#M74958</link>
    <description>&lt;P&gt;Scripting mode is recommended when doing multiple lines of commands via CLI. I’m not sure if it is a cure for your issue though.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As for the cert requirement. Is it just that the certificate is no longer trusted and your browser won’t allow a connection? The cert is still there just expired right?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can generate a new Panorama web-server certificate with the command:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;SPAN&gt;run request certificate generate for-use-by panorama-server&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;More detail on what you are trying would be helpful.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also agree that just enabling HTTP management would be a quick way in. Deleting the SSL service profile probably won’t even commit since it would be referenced by the configured features to be using it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;*** &amp;nbsp;Another option would be to SCP export the configuration to another device and replace the existing certificate in the XML configuration file and reimport.&lt;/P&gt;</description>
    <pubDate>Mon, 24 Jun 2019 22:40:58 GMT</pubDate>
    <dc:creator>bspilde</dc:creator>
    <dc:date>2019-06-24T22:40:58Z</dc:date>
    <item>
      <title>Fighting the cli ... sigh - how to import a cert via the cli</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/fighting-the-cli-sigh-how-to-import-a-cert-via-the-cli/m-p/272466#M74924</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So, silly me I manage my cert in panorama, so when my int CA for my management ports came up for renewal, i renewed, and pushed out to all the devices ... except for my panorama &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;P&gt;now I have cli access only.&lt;/P&gt;&lt;P&gt;I have found the location&amp;nbsp;&lt;/P&gt;&lt;P&gt;configure&lt;/P&gt;&lt;P&gt;panorama certificate&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;but when it comes time to add my multiline public key ... it will not take multiline entries ... how do I enter a multi line.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My god how hard .. there is an open quote that doesn't work. or &amp;lt;space&amp;gt;\ that doesn't work.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;any help would be welcome ...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jun 2019 01:55:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/fighting-the-cli-sigh-how-to-import-a-cert-via-the-cli/m-p/272466#M74924</guid>
      <dc:creator>Alex_Samad</dc:creator>
      <dc:date>2019-06-24T01:55:34Z</dc:date>
    </item>
    <item>
      <title>Re: Fighting the cli ... sigh - how to import a cert via the cli</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/fighting-the-cli-sigh-how-to-import-a-cert-via-the-cli/m-p/272780#M74952</link>
      <description>&lt;P&gt;Ok, am going to ask the obvious and dumb question first.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Why not, temporarily, disable the need to use a Cert to manage the Panorama?&lt;/P&gt;&lt;P&gt;You have CLI access, remove the line that references the cert.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;for me, that line is&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;set deviceconfig system ssl-tls-service-profile SecureGUI (SecureGui is my cert profile)&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;delete that line.&amp;nbsp; commit.&lt;/P&gt;&lt;P&gt;Now the Panorama would not be looking for a valid cert to manage on it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Certainly will keep an eye on this message response, but should not be too difficult.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I am misunderstanding the issue, please provide greater detail.&amp;nbsp; &lt;span class="lia-unicode-emoji" title=":face_with_tongue:"&gt;😛&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jun 2019 20:56:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/fighting-the-cli-sigh-how-to-import-a-cert-via-the-cli/m-p/272780#M74952</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2019-06-24T20:56:26Z</dc:date>
    </item>
    <item>
      <title>Re: Fighting the cli ... sigh - how to import a cert via the cli</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/fighting-the-cli-sigh-how-to-import-a-cert-via-the-cli/m-p/272797#M74955</link>
      <description>&lt;P&gt;Good tip Steve, probably the easiest option.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If pasting over CLI still though you might need&amp;nbsp;"set cli scripting-mode on".&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jun 2019 21:45:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/fighting-the-cli-sigh-how-to-import-a-cert-via-the-cli/m-p/272797#M74955</guid>
      <dc:creator>bspilde</dc:creator>
      <dc:date>2019-06-24T21:45:07Z</dc:date>
    </item>
    <item>
      <title>Re: Fighting the cli ... sigh - how to import a cert via the cli</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/fighting-the-cli-sigh-how-to-import-a-cert-via-the-cli/m-p/272801#M74957</link>
      <description>&lt;P&gt;Good call I was going to try removing the ssl from there. but delete a ssl cert how will it present ssl traffic then.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I was thinking maybe to allow port 80 access .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;as for scripting mode ... hadn't tried that.&amp;nbsp; is that how you insert certs ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I will give it a go&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jun 2019 22:03:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/fighting-the-cli-sigh-how-to-import-a-cert-via-the-cli/m-p/272801#M74957</guid>
      <dc:creator>Alex_Samad</dc:creator>
      <dc:date>2019-06-24T22:03:16Z</dc:date>
    </item>
    <item>
      <title>Re: Fighting the cli ... sigh - how to import a cert via the cli</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/fighting-the-cli-sigh-how-to-import-a-cert-via-the-cli/m-p/272803#M74958</link>
      <description>&lt;P&gt;Scripting mode is recommended when doing multiple lines of commands via CLI. I’m not sure if it is a cure for your issue though.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As for the cert requirement. Is it just that the certificate is no longer trusted and your browser won’t allow a connection? The cert is still there just expired right?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can generate a new Panorama web-server certificate with the command:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;SPAN&gt;run request certificate generate for-use-by panorama-server&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;More detail on what you are trying would be helpful.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also agree that just enabling HTTP management would be a quick way in. Deleting the SSL service profile probably won’t even commit since it would be referenced by the configured features to be using it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;*** &amp;nbsp;Another option would be to SCP export the configuration to another device and replace the existing certificate in the XML configuration file and reimport.&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jun 2019 22:40:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/fighting-the-cli-sigh-how-to-import-a-cert-via-the-cli/m-p/272803#M74958</guid>
      <dc:creator>bspilde</dc:creator>
      <dc:date>2019-06-24T22:40:58Z</dc:date>
    </item>
    <item>
      <title>Re: Fighting the cli ... sigh - how to import a cert via the cli</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/fighting-the-cli-sigh-how-to-import-a-cert-via-the-cli/m-p/272804#M74959</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;No, the intermediary CA was expired.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I recently renews the int ca and the management cert.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;but forgot to update the int ca on panorama and I did upgrade the cert.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;scp .. yes i found this in my google'ing&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think the crux of the question is how to do cert management from CLI&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;it looks like the only way to import a cert properly is to scp in.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the set commands don't work !&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jun 2019 22:45:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/fighting-the-cli-sigh-how-to-import-a-cert-via-the-cli/m-p/272804#M74959</guid>
      <dc:creator>Alex_Samad</dc:creator>
      <dc:date>2019-06-24T22:45:22Z</dc:date>
    </item>
    <item>
      <title>Re: Fighting the cli ... sigh - how to import a cert via the cli</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/fighting-the-cli-sigh-how-to-import-a-cert-via-the-cli/m-p/272805#M74960</link>
      <description>&lt;P&gt;To get the proper syntax of the configuration including all the carriage returns etc. do the following to get the configuration output in set format. Then you can take just that section of the config to paste into Notepad++ or SublimeText so that you get the correct line requirements such as right after the BEGIN CERTIFICATE --- &amp;nbsp;line.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;admin@M100-01(primary-active)&amp;gt; set cli config-output-format set&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;admin@M100-01(primary-active)&amp;gt; set cli scripting-mode on&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;admin@M100-01(primary-active)&amp;gt; configure&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Entering configuration mode&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;[edit] &lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;admin@M100-01(primary-active)# show&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The private key is a single line but the public key is fixed width.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jun 2019 22:52:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/fighting-the-cli-sigh-how-to-import-a-cert-via-the-cli/m-p/272805#M74960</guid>
      <dc:creator>bspilde</dc:creator>
      <dc:date>2019-06-24T22:52:31Z</dc:date>
    </item>
    <item>
      <title>Re: Fighting the cli ... sigh - how to import a cert via the cli</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/fighting-the-cli-sigh-how-to-import-a-cert-via-the-cli/m-p/272806#M74961</link>
      <description>&lt;P&gt;Shoot! Ok, good to know. If you have successful steps please post.&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jun 2019 22:56:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/fighting-the-cli-sigh-how-to-import-a-cert-via-the-cli/m-p/272806#M74961</guid>
      <dc:creator>bspilde</dc:creator>
      <dc:date>2019-06-24T22:56:28Z</dc:date>
    </item>
    <item>
      <title>Re: Fighting the cli ... sigh - how to import a cert via the cli</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/fighting-the-cli-sigh-how-to-import-a-cert-via-the-cli/m-p/273358#M75025</link>
      <description>&lt;P&gt;This is what i did - set show and copy paste.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;it doesn't work.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jun 2019 04:27:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/fighting-the-cli-sigh-how-to-import-a-cert-via-the-cli/m-p/273358#M75025</guid>
      <dc:creator>Alex_Samad</dc:creator>
      <dc:date>2019-06-27T04:27:13Z</dc:date>
    </item>
    <item>
      <title>Re: Fighting the cli ... sigh - how to import a cert via the cli</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/fighting-the-cli-sigh-how-to-import-a-cert-via-the-cli/m-p/313188#M80894</link>
      <description>&lt;P&gt;I know this is old, but I was struggling with it as well.&amp;nbsp; The advice from here (CTRL-V followed by CTRL-M at the end of each line) worked:&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.reddit.com/r/paloaltonetworks/comments/4ojbsh/cli_assistance_with_banner_text/" target="_blank"&gt;https://www.reddit.com/r/paloaltonetworks/comments/4ojbsh/cli_assistance_with_banner_text/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Feb 2020 19:58:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/fighting-the-cli-sigh-how-to-import-a-cert-via-the-cli/m-p/313188#M80894</guid>
      <dc:creator>GregDetweiler</dc:creator>
      <dc:date>2020-02-26T19:58:06Z</dc:date>
    </item>
  </channel>
</rss>

