<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Unable to delete Certificate in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-delete-certificate/m-p/300941#M78598</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/75039"&gt;@MP18&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;In instances like this I would simply put a lock on the configuration, export the candidate-config.xml on the device and manually remove the certificate from the XML file. You can then import and load the configuration.&lt;/P&gt;</description>
    <pubDate>Wed, 27 Nov 2019 03:43:39 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2019-11-27T03:43:39Z</dc:date>
    <item>
      <title>Unable to delete Certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-delete-certificate/m-p/176748#M55225</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I need to delete a certificate from a PA-3050. The certificate is currently EXPIRED. When I try to delete it it says this message&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;1-&amp;nbsp;Failed to delete Certificate - MYCOMPANYWildcard 2014-2017-FOR_DELETION.&lt;BR /&gt;&amp;nbsp;&amp;nbsp;° &amp;nbsp;MYCOMPANY Wildcard 2014-2017-FOR_DELETION cannot be deleted because of references from:&lt;BR /&gt;&amp;nbsp;&amp;nbsp;°&amp;nbsp; ssl-tls-service-profile -&amp;gt; MYCOMPANYWildcard 2014-2017-ssl-tls-service-profile -&amp;gt; certificate&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In Device-Certificate Management-SSL/TLS Service Profile doesn't appear it. &amp;nbsp;i download a copy of the current running config and it appear,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;lt;ssl-tls-service-profile&amp;gt;&lt;BR /&gt;&amp;lt;entry name="MYCOMPANYWildcard 2014-2017-ssl-tls-service-profile"&amp;gt;&lt;BR /&gt;&amp;lt;certificate&amp;gt;MYCOMPANYWildcard 2014-2017-FOR_DELETION&amp;lt;/certificate&amp;gt;&lt;BR /&gt;&amp;lt;protocol-settings/&amp;gt;&lt;BR /&gt;&amp;lt;/entry&amp;gt;&lt;BR /&gt;&amp;lt;/ssl-tls-service-profile&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;but I don't know where could it be. Do anybody knows where could it be?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;best Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;P.D&lt;/P&gt;&lt;P&gt;I also try to revoke it but appear this message "Certificate is not locally issued."&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Sep 2017 14:16:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-delete-certificate/m-p/176748#M55225</guid>
      <dc:creator>SOC_CSG</dc:creator>
      <dc:date>2017-09-15T14:16:53Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to delete Certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-delete-certificate/m-p/176768#M55230</link>
      <description>&lt;P&gt;If you can see the certificate inside of &lt;STRONG&gt;Device &amp;gt; Certificate Management &amp;gt; Certificates&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;But you cannot delete it.. question.. if you can click on the certificate to get more information.. what is checked?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also, inside of the CLI, you should be able to list out:&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&amp;gt; show shared ssl-decrypt&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;it should show you all of your certificates who have some form or fashion of being associated with ssl-decrypt.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can run this command from the CLI to get it removed:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&amp;gt; configure&lt;BR /&gt;&amp;gt; delete shared ssl-decrypt trusted-root-CA 123Test&lt;/FONT&gt;&amp;nbsp; (where 123Test was the name of the cert in question)&lt;/P&gt;</description>
      <pubDate>Fri, 15 Sep 2017 15:58:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-delete-certificate/m-p/176768#M55230</guid>
      <dc:creator>jdelio</dc:creator>
      <dc:date>2017-09-15T15:58:59Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to delete Certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-delete-certificate/m-p/177269#M55302</link>
      <description>&lt;P&gt;Hi.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There are the questions for your answer.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1.&amp;nbsp;&lt;SPAN&gt;if you can click on the certificate to get more information.. what is checked?. There is nothing checked.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2.&amp;nbsp;acuntia@FW2(active)# show shared ssl-decrypt&lt;BR /&gt;ssl-decrypt {&lt;BR /&gt;ssl-exclude-cert;&lt;BR /&gt;forward-untrust-certificate "Forward untrust";&lt;BR /&gt;forward-trust-certificate SSL_Decrypt;&lt;BR /&gt;}&lt;BR /&gt;[edit]&lt;BR /&gt;acuntia@FW2(active)#&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;3. I try to delete, option "shared" now appears but I have this output (see attachment"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Ssl-certificate.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/11338i2B7EE414E2F4810A/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Ssl-certificate.png" alt="Ssl-certificate.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;best regards&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Sep 2017 10:49:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-delete-certificate/m-p/177269#M55302</guid>
      <dc:creator>SOC_CSG</dc:creator>
      <dc:date>2017-09-18T10:49:41Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to delete Certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-delete-certificate/m-p/178956#M55612</link>
      <description>&lt;P&gt;Hi.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Still impossible to delete the certificate. Anybody knows what could be happening?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;best regards&lt;/P&gt;</description>
      <pubDate>Wed, 27 Sep 2017 13:41:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-delete-certificate/m-p/178956#M55612</guid>
      <dc:creator>SOC_CSG</dc:creator>
      <dc:date>2017-09-27T13:41:48Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to delete Certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-delete-certificate/m-p/300887#M78594</link>
      <description>&lt;P&gt;i also tried to delete cert no luck&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Nov 2019 23:31:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-delete-certificate/m-p/300887#M78594</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-11-26T23:31:19Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to delete Certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-delete-certificate/m-p/300941#M78598</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/75039"&gt;@MP18&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;In instances like this I would simply put a lock on the configuration, export the candidate-config.xml on the device and manually remove the certificate from the XML file. You can then import and load the configuration.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Nov 2019 03:43:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-delete-certificate/m-p/300941#M78598</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-11-27T03:43:39Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to delete Certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-delete-certificate/m-p/301080#M78619</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;First I deleted the cert from the CLI it got deleted but GUI&amp;nbsp; still shows cert.&lt;/P&gt;&lt;P&gt;Then i was able to delete it from the GUI also.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Nov 2019 16:29:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-delete-certificate/m-p/301080#M78619</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-11-27T16:29:08Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to delete Certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-delete-certificate/m-p/301717#M78704</link>
      <description>&lt;P&gt;Also, if not stated before, any cert that you are trying to delete cannot be "in use" in the config, or&amp;nbsp; you will not be able to delete it.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Dec 2019 18:41:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-delete-certificate/m-p/301717#M78704</guid>
      <dc:creator>jdelio</dc:creator>
      <dc:date>2019-12-02T18:41:23Z</dc:date>
    </item>
  </channel>
</rss>

