<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Web-gui access with no secure certificate. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/web-gui-access-with-no-secure-certificate/m-p/291745#M77307</link>
    <description>&lt;P&gt;I'll Perform the test as indicated, the firewall management IP is a private IP even if I will try.&lt;/P&gt;</description>
    <pubDate>Mon, 07 Oct 2019 17:28:00 GMT</pubDate>
    <dc:creator>SaulGlz</dc:creator>
    <dc:date>2019-10-07T17:28:00Z</dc:date>
    <item>
      <title>Web-gui access with no secure certificate.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/web-gui-access-with-no-secure-certificate/m-p/291241#M77261</link>
      <description>&lt;P&gt;I access via GUI from Chrome and observe that the connection is not secure.&lt;/P&gt;&lt;P&gt;I created the certificate for the firewall, but Chrome keeps saying that my connection is not secure.&lt;/P&gt;&lt;P&gt;How can I solve this problem if the AC I have is internal to the company?&lt;/P&gt;&lt;P&gt;Is there any way to generate certificates with AES-GCM?&lt;/P&gt;&lt;P&gt;in chrome, the following legend appears to me.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image005.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21647iE066B8012A22FD92/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image005.png" alt="image005.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image002.png" style="width: 445px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21648iE77E39E1D5131297/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image002.png" alt="image002.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image006.png" style="width: 420px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21649iAF5F739146E3C4F6/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image006.png" alt="image006.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image007.png" style="width: 420px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21650i7396F34262CADEF5/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image007.png" alt="image007.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image009.png" style="width: 418px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21651iE005247BE75503A1/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image009.png" alt="image009.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Oct 2019 00:20:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/web-gui-access-with-no-secure-certificate/m-p/291241#M77261</guid>
      <dc:creator>SaulGlz</dc:creator>
      <dc:date>2019-10-04T00:20:03Z</dc:date>
    </item>
    <item>
      <title>Re: Web-gui access with no secure certificate.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/web-gui-access-with-no-secure-certificate/m-p/291307#M77268</link>
      <description>Hello Chrome insists on seeing the fqdn also in the SAN value (subject alt(ernative) name). As long as this data is not there, it is treated as invalid.</description>
      <pubDate>Fri, 04 Oct 2019 08:10:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/web-gui-access-with-no-secure-certificate/m-p/291307#M77268</guid>
      <dc:creator>JoergSchuetter</dc:creator>
      <dc:date>2019-10-04T08:10:48Z</dc:date>
    </item>
    <item>
      <title>Re: Web-gui access with no secure certificate.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/web-gui-access-with-no-secure-certificate/m-p/291421#M77275</link>
      <description>&lt;P&gt;Just enter an alternative name, I'll try to place the same FQDN in the alternative name.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image010.png" style="width: 418px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21673iE84593FD1608203C/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image010.png" alt="image010.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Oct 2019 15:30:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/web-gui-access-with-no-secure-certificate/m-p/291421#M77275</guid>
      <dc:creator>SaulGlz</dc:creator>
      <dc:date>2019-10-04T15:30:36Z</dc:date>
    </item>
    <item>
      <title>Re: Web-gui access with no secure certificate.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/web-gui-access-with-no-secure-certificate/m-p/291560#M77284</link>
      <description>&lt;P&gt;Change the alternative name and chrome already recognized the certificate as valid.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image010.png" style="width: 420px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21697i66E5162FDD804447/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image010.png" alt="image010.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image012.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21698iF1A8F913C30D27E1/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image012.png" alt="image012.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the support.&lt;/P&gt;</description>
      <pubDate>Fri, 04 Oct 2019 21:33:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/web-gui-access-with-no-secure-certificate/m-p/291560#M77284</guid>
      <dc:creator>SaulGlz</dc:creator>
      <dc:date>2019-10-04T21:33:11Z</dc:date>
    </item>
    <item>
      <title>Re: Web-gui access with no secure certificate.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/web-gui-access-with-no-secure-certificate/m-p/291598#M77291</link>
      <description>&lt;P&gt;even if you put ip address in subject alternative name it works.&lt;/P&gt;</description>
      <pubDate>Sun, 06 Oct 2019 14:02:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/web-gui-access-with-no-secure-certificate/m-p/291598#M77291</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-10-06T14:02:04Z</dc:date>
    </item>
    <item>
      <title>Re: Web-gui access with no secure certificate.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/web-gui-access-with-no-secure-certificate/m-p/291745#M77307</link>
      <description>&lt;P&gt;I'll Perform the test as indicated, the firewall management IP is a private IP even if I will try.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Oct 2019 17:28:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/web-gui-access-with-no-secure-certificate/m-p/291745#M77307</guid>
      <dc:creator>SaulGlz</dc:creator>
      <dc:date>2019-10-07T17:28:00Z</dc:date>
    </item>
    <item>
      <title>Re: Web-gui access with no secure certificate.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/web-gui-access-with-no-secure-certificate/m-p/293574#M77594</link>
      <description>&lt;P&gt;Create the certificate by placing the device IP in the SAN and it does not work..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image001.png" style="width: 420px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21855i8472E91BFCDCF9D6/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image001.png" alt="image001.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image002.png" style="width: 420px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21856i1EEDF021C68B3EEA/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image002.png" alt="image002.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image003.png" style="width: 459px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21857iC61AB088A0B00D6A/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image003.png" alt="image003.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It only works by placing the same name on both the CN and the SAN.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Oct 2019 18:05:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/web-gui-access-with-no-secure-certificate/m-p/293574#M77594</guid>
      <dc:creator>SaulGlz</dc:creator>
      <dc:date>2019-10-21T18:05:53Z</dc:date>
    </item>
    <item>
      <title>Re: Web-gui access with no secure certificate.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/web-gui-access-with-no-secure-certificate/m-p/293615#M77598</link>
      <description>&lt;P&gt;When creating SAN entries, you always put the common name as a SAN entry as well.&lt;/P&gt;&lt;P&gt;If you add the IP address as a SAN entry, make sure the type is IP Address (v4) instead of DNS name.&lt;/P&gt;&lt;P&gt;When I create certificates for devices like a PA, I do as shown below. The cert will be valid if you access with FQDN, short name or IP.&lt;/P&gt;&lt;P&gt;Common Name = devicename.domain.com&lt;/P&gt;&lt;P&gt;SAN:&lt;/P&gt;&lt;P&gt;DNS= devicename.domain.com&lt;/P&gt;&lt;P&gt;DNS= devicename&lt;/P&gt;&lt;P&gt;IP Address (v4) = IP Address&lt;/P&gt;</description>
      <pubDate>Mon, 21 Oct 2019 19:46:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/web-gui-access-with-no-secure-certificate/m-p/293615#M77598</guid>
      <dc:creator>rmfalconer</dc:creator>
      <dc:date>2019-10-21T19:46:29Z</dc:date>
    </item>
    <item>
      <title>Re: Web-gui access with no secure certificate.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/web-gui-access-with-no-secure-certificate/m-p/511433#M106322</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I was able to solve the issue by using below KB for adding SAN name in certificate&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CluVCAS" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CluVCAS&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Generated Self-Signed certificate in PA,then in certificate attributes add hostname and IP same as management address.&lt;/P&gt;
&lt;P&gt;Here hostname denotes as SAN name (Subject Alternative Name)&lt;/P&gt;
&lt;P&gt;Attach certificate to TLS Profile and that TLS profile to SSL/TLS management interface to login in GUI via TLS1.1/2&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Attached reference screenshot&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Aug 2022 13:18:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/web-gui-access-with-no-secure-certificate/m-p/511433#M106322</guid>
      <dc:creator>OmkarM</dc:creator>
      <dc:date>2022-08-10T13:18:28Z</dc:date>
    </item>
  </channel>
</rss>

