<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Generating SSL Decryption Forward Trust Cert for an HA Pair via Panorama? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/generating-ssl-decryption-forward-trust-cert-for-an-ha-pair-via/m-p/302768#M78876</link>
    <description>&lt;P&gt;Hello there.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would have presumed that your CN or Common Name is either IP or FQDN name (which both FW would synch between them)&lt;/P&gt;&lt;P&gt;So in your template, your inside IP for both FWs is the same.. ( right??? ) and the FDQN name (if you used this for your CN) is the same on both FWs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I guess, I am trying to determine if you used a wildcard cert on ALL firewalls?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So no, it should not be a problem to push the cert to both FWs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are there any other details that would create a difference (SNs are not included in differences).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also, what is your methodology to get the cert onto all end user browsers (IE, Edge, Chrome, Firefox, Safari, Opera, etc)&lt;/P&gt;&lt;P&gt;Please advise.&lt;/P&gt;</description>
    <pubDate>Mon, 09 Dec 2019 19:53:53 GMT</pubDate>
    <dc:creator>S.Cantwell</dc:creator>
    <dc:date>2019-12-09T19:53:53Z</dc:date>
    <item>
      <title>Generating SSL Decryption Forward Trust Cert for an HA Pair via Panorama?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/generating-ssl-decryption-forward-trust-cert-for-an-ha-pair-via/m-p/302736#M78874</link>
      <description>&lt;P&gt;&lt;SPAN&gt;I've successfully rolled out SSL Decryption on a bunch of non-HA firewalls via Panorama. Generating the .CSR, signing it with my CA, and then importing the .CER but I'm wondering if this is going to work with my HA Pair because I'm guessing that I'll have to have two different certs because there's two different physical boxes. Has anyone done this before?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Dec 2019 18:53:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/generating-ssl-decryption-forward-trust-cert-for-an-ha-pair-via/m-p/302736#M78874</guid>
      <dc:creator>Thomas_Dzubin</dc:creator>
      <dc:date>2019-12-09T18:53:31Z</dc:date>
    </item>
    <item>
      <title>Re: Generating SSL Decryption Forward Trust Cert for an HA Pair via Panorama?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/generating-ssl-decryption-forward-trust-cert-for-an-ha-pair-via/m-p/302768#M78876</link>
      <description>&lt;P&gt;Hello there.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would have presumed that your CN or Common Name is either IP or FQDN name (which both FW would synch between them)&lt;/P&gt;&lt;P&gt;So in your template, your inside IP for both FWs is the same.. ( right??? ) and the FDQN name (if you used this for your CN) is the same on both FWs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I guess, I am trying to determine if you used a wildcard cert on ALL firewalls?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So no, it should not be a problem to push the cert to both FWs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are there any other details that would create a difference (SNs are not included in differences).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also, what is your methodology to get the cert onto all end user browsers (IE, Edge, Chrome, Firefox, Safari, Opera, etc)&lt;/P&gt;&lt;P&gt;Please advise.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Dec 2019 19:53:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/generating-ssl-decryption-forward-trust-cert-for-an-ha-pair-via/m-p/302768#M78876</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2019-12-09T19:53:53Z</dc:date>
    </item>
  </channel>
</rss>

