<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: &amp;quot;Only self signed CA cert can have identical sub and issuer fields&amp;quot; when uploading a c in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/quot-only-self-signed-ca-cert-can-have-identical-sub-and-issuer/m-p/305702#M79456</link>
    <description>&lt;P&gt;Yes we need that cert for response and assertion to work correctly.&lt;/P&gt;&lt;P&gt;I have no CA checked for these certs under the certificates.&lt;/P&gt;&lt;P&gt;Seems there are many ways to make the SAML work with VPN.&lt;/P&gt;</description>
    <pubDate>Mon, 06 Jan 2020 04:38:56 GMT</pubDate>
    <dc:creator>MP18</dc:creator>
    <dc:date>2020-01-06T04:38:56Z</dc:date>
    <item>
      <title>"Only self signed CA cert can have identical sub and issuer fields" when uploading a certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/quot-only-self-signed-ca-cert-can-have-identical-sub-and-issuer/m-p/276749#M75376</link>
      <description>&lt;P&gt;This message appears when uploading an external CA certificate to the sistem. "Only self signed CA certificates can have identical subject and issuer fields". It's a Microsoft-adfs autosigned CA certificate used to sign SAML messages and we can't not change that, you know if there's any way to upload this certificate to the system in order we can use it? thanks!&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jul 2019 10:56:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/quot-only-self-signed-ca-cert-can-have-identical-sub-and-issuer/m-p/276749#M75376</guid>
      <dc:creator>LuisMateosCaro</dc:creator>
      <dc:date>2019-07-16T10:56:15Z</dc:date>
    </item>
    <item>
      <title>Re: "Only self signed CA cert can have identical sub and issuer fields" when uploading a c</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/quot-only-self-signed-ca-cert-can-have-identical-sub-and-issuer/m-p/276907#M75388</link>
      <description>&lt;P&gt;Having this same issue. Anyone help with this?&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jul 2019 19:54:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/quot-only-self-signed-ca-cert-can-have-identical-sub-and-issuer/m-p/276907#M75388</guid>
      <dc:creator>BH6678</dc:creator>
      <dc:date>2019-07-16T19:54:15Z</dc:date>
    </item>
    <item>
      <title>Re: "Only self signed CA cert can have identical sub and issuer fields" when uploading a c</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/quot-only-self-signed-ca-cert-can-have-identical-sub-and-issuer/m-p/304522#M79166</link>
      <description>&lt;P&gt;Snap same issue, did anyone resolve this?&lt;/P&gt;</description>
      <pubDate>Fri, 20 Dec 2019 11:11:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/quot-only-self-signed-ca-cert-can-have-identical-sub-and-issuer/m-p/304522#M79166</guid>
      <dc:creator>AndyFlatt</dc:creator>
      <dc:date>2019-12-20T11:11:29Z</dc:date>
    </item>
    <item>
      <title>Re: "Only self signed CA cert can have identical sub and issuer fields" when uploading a c</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/quot-only-self-signed-ca-cert-can-have-identical-sub-and-issuer/m-p/305568#M79409</link>
      <description>&lt;P&gt;Had same issue but managed to work around this.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1) Export XML config.&amp;nbsp;&lt;/P&gt;&lt;P&gt;2) Set the CA flag.&lt;/P&gt;&lt;P&gt;3) Re-Import XML config.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Jan 2020 16:25:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/quot-only-self-signed-ca-cert-can-have-identical-sub-and-issuer/m-p/305568#M79409</guid>
      <dc:creator>Nehmaan</dc:creator>
      <dc:date>2020-01-03T16:25:50Z</dc:date>
    </item>
    <item>
      <title>Re: "Only self signed CA cert can have identical sub and issuer fields" when uploading a c</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/quot-only-self-signed-ca-cert-can-have-identical-sub-and-issuer/m-p/305578#M79412</link>
      <description>&lt;P&gt;If you are configuring Microsoft SAML&amp;nbsp; for&amp;nbsp; MFA then you just need to&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1&amp;gt;Export the XML file under SAML IDentity provider.&lt;/P&gt;&lt;P&gt;This will automatically create the certificate for you.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2&amp;gt;You do not need to check the CA under the certificates.&lt;/P&gt;</description>
      <pubDate>Fri, 03 Jan 2020 17:58:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/quot-only-self-signed-ca-cert-can-have-identical-sub-and-issuer/m-p/305578#M79412</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2020-01-03T17:58:59Z</dc:date>
    </item>
    <item>
      <title>Re: "Only self signed CA cert can have identical sub and issuer fields" when uploading a c</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/quot-only-self-signed-ca-cert-can-have-identical-sub-and-issuer/m-p/305634#M79433</link>
      <description>&lt;P&gt;Have you tried it yourself ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There is no "export" option under "SAML Identity Provider". I think you meant "Import". Even if you "Import" the XML from Azure, It doesn't set the CA flag.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You still get an error on commit as well. Only way around it that I've worked out is what I mentioned previously.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Jan 2020 22:26:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/quot-only-self-signed-ca-cert-can-have-identical-sub-and-issuer/m-p/305634#M79433</guid>
      <dc:creator>Nehmaan</dc:creator>
      <dc:date>2020-01-03T22:26:53Z</dc:date>
    </item>
    <item>
      <title>Re: "Only self signed CA cert can have identical sub and issuer fields" when uploading a c</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/quot-only-self-signed-ca-cert-can-have-identical-sub-and-issuer/m-p/305635#M79434</link>
      <description>&lt;P&gt;Sorry i Mean Import the XML file to PA&lt;/P&gt;&lt;P&gt;Yes i tried in my environment and it works.&lt;/P&gt;&lt;P&gt;Also you do not want the CA Flag to check.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Jan 2020 22:40:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/quot-only-self-signed-ca-cert-can-have-identical-sub-and-issuer/m-p/305635#M79434</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2020-01-03T22:40:00Z</dc:date>
    </item>
    <item>
      <title>Re: "Only self signed CA cert can have identical sub and issuer fields" when uploading a c</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/quot-only-self-signed-ca-cert-can-have-identical-sub-and-issuer/m-p/305636#M79435</link>
      <description>&lt;P&gt;How have you defined your certificates under authentication profile ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have used a wildcard cert to sign SAML messages to IDP and the Azure Cert selected under "Certificate Profile".&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The only way to select the Azure Cert for "Certificate Profile" is to ensure it has the CA flag set.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can confirm that&amp;nbsp;SAML response and assertion work.&lt;/P&gt;</description>
      <pubDate>Fri, 03 Jan 2020 23:03:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/quot-only-self-signed-ca-cert-can-have-identical-sub-and-issuer/m-p/305636#M79435</guid>
      <dc:creator>Nehmaan</dc:creator>
      <dc:date>2020-01-03T23:03:21Z</dc:date>
    </item>
    <item>
      <title>Re: "Only self signed CA cert can have identical sub and issuer fields" when uploading a c</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/quot-only-self-signed-ca-cert-can-have-identical-sub-and-issuer/m-p/305637#M79436</link>
      <description>&lt;P&gt;Yes the Certificate which is created automatically is defined under Authentication Profile and also under SSL/TLS profile.&lt;/P&gt;&lt;P&gt;Are you using Azure SAML for MFA or Global protect VPN?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Jan 2020 23:08:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/quot-only-self-signed-ca-cert-can-have-identical-sub-and-issuer/m-p/305637#M79436</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2020-01-03T23:08:05Z</dc:date>
    </item>
    <item>
      <title>Re: "Only self signed CA cert can have identical sub and issuer fields" when uploading a c</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/quot-only-self-signed-ca-cert-can-have-identical-sub-and-issuer/m-p/305638#M79437</link>
      <description>&lt;P&gt;How did you define it within the authentication profile, certificate profile and SSL/TLS Service Profile ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can only select certs which have the CA flag set under "Certificate Profiles" which is then referenced within the "authentication profile".&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For the "SSL/TLS service profile" the same applies but I've used a signed wildcard cert instead and imported the chain under "Certificates" to complete the trust.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Using SAML for Global Protect VPN.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Jan 2020 23:17:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/quot-only-self-signed-ca-cert-can-have-identical-sub-and-issuer/m-p/305638#M79437</guid>
      <dc:creator>Nehmaan</dc:creator>
      <dc:date>2020-01-03T23:17:52Z</dc:date>
    </item>
    <item>
      <title>Re: "Only self signed CA cert can have identical sub and issuer fields" when uploading a c</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/quot-only-self-signed-ca-cert-can-have-identical-sub-and-issuer/m-p/305639#M79438</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Correction&lt;/P&gt;&lt;P&gt;Typo Cert which is automatically generated from XML file is not used in Authentication profile and SSL/TLS profile&lt;/P&gt;</description>
      <pubDate>Fri, 03 Jan 2020 23:24:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/quot-only-self-signed-ca-cert-can-have-identical-sub-and-issuer/m-p/305639#M79438</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2020-01-03T23:24:45Z</dc:date>
    </item>
    <item>
      <title>Re: "Only self signed CA cert can have identical sub and issuer fields" when uploading a c</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/quot-only-self-signed-ca-cert-can-have-identical-sub-and-issuer/m-p/305640#M79439</link>
      <description>&lt;P&gt;No worries. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Think you need it for response and assertion to work correctly. Therefore, You'll need to ensure the CA flag is set.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm not 100% sure if that's how your supposed certs for this as neither Palo Alto nor Azure actually tell you how to do the certs correctly. &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Jan 2020 23:33:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/quot-only-self-signed-ca-cert-can-have-identical-sub-and-issuer/m-p/305640#M79439</guid>
      <dc:creator>Nehmaan</dc:creator>
      <dc:date>2020-01-03T23:33:22Z</dc:date>
    </item>
    <item>
      <title>Re: "Only self signed CA cert can have identical sub and issuer fields" when uploading a c</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/quot-only-self-signed-ca-cert-can-have-identical-sub-and-issuer/m-p/305702#M79456</link>
      <description>&lt;P&gt;Yes we need that cert for response and assertion to work correctly.&lt;/P&gt;&lt;P&gt;I have no CA checked for these certs under the certificates.&lt;/P&gt;&lt;P&gt;Seems there are many ways to make the SAML work with VPN.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jan 2020 04:38:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/quot-only-self-signed-ca-cert-can-have-identical-sub-and-issuer/m-p/305702#M79456</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2020-01-06T04:38:56Z</dc:date>
    </item>
    <item>
      <title>Re: "Only self signed CA cert can have identical sub and issuer fields" when uploading a c</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/quot-only-self-signed-ca-cert-can-have-identical-sub-and-issuer/m-p/319371#M81906</link>
      <description>&lt;P&gt;Ok, so it seems lots of people would have this problem since self signed certs for SAML Identity providers are probably best practice.&amp;nbsp; &amp;nbsp; (We started with a CA signed cert but then after doing certificate rollover with 40+ service providers a year and a half later decided this was insane.)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Palo Alto support tells me to either use a CA cert or generate a new cert in PaloAlto. Either way would force me into the certificate rollover process with all my service providers)&amp;nbsp; &amp;nbsp;Did anyone ever figure out a trick or workaround for this?&amp;nbsp; &amp;nbsp;This thread is not auspicious.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Mar 2020 12:54:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/quot-only-self-signed-ca-cert-can-have-identical-sub-and-issuer/m-p/319371#M81906</guid>
      <dc:creator>JohnWade</dc:creator>
      <dc:date>2020-03-30T12:54:56Z</dc:date>
    </item>
    <item>
      <title>Re: "Only self signed CA cert can have identical sub and issuer fields" when uploading a c</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/quot-only-self-signed-ca-cert-can-have-identical-sub-and-issuer/m-p/319552#M81938</link>
      <description>&lt;P&gt;You tried the workaround I mentioned ?&lt;/P&gt;</description>
      <pubDate>Tue, 31 Mar 2020 11:26:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/quot-only-self-signed-ca-cert-can-have-identical-sub-and-issuer/m-p/319552#M81938</guid>
      <dc:creator>Nehmaan</dc:creator>
      <dc:date>2020-03-31T11:26:37Z</dc:date>
    </item>
    <item>
      <title>Re: "Only self signed CA cert can have identical sub and issuer fields" when uploading a c</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/quot-only-self-signed-ca-cert-can-have-identical-sub-and-issuer/m-p/319553#M81939</link>
      <description>&lt;P&gt;Thanks for replying, I really appreciate it.&amp;nbsp; &amp;nbsp;As to the workaround, maybe I am dense, but I dumped out the xml and reviewed the &amp;lt;certificate&amp;gt; block.&amp;nbsp; &amp;nbsp; &amp;nbsp;Each existing certificate is present and I can see how to change the the &amp;lt;ca&amp;gt;&amp;lt;/ca&amp;gt; flag, but since I can't import the certificate I need, it is not in this section.&amp;nbsp; &amp;nbsp;I thought I could just manually add the needed certificate to this section since I have the PEM encoded public key for the certificate, and I can pull most of the fields from the cert, but I was stumped by the subject and issuer hash tags, since I am not aware of what hashing algorithm they are using. (See below for an example CA entry.)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I admit, I must be missing something obvious, can you guide me in the error of my ways?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;John&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;lt;entry name="DigiCertCA"&amp;gt;&lt;BR /&gt;&amp;lt;subject-hash&amp;gt;58754cf2&amp;lt;/subject-hash&amp;gt;&lt;BR /&gt;&amp;lt;issuer-hash&amp;gt;81b9768f&amp;lt;/issuer-hash&amp;gt;&lt;BR /&gt;&amp;lt;not-valid-before&amp;gt;Oct 22 12:00:00 2013 GMT&amp;lt;/not-valid-before&amp;gt;&lt;BR /&gt;&amp;lt;issuer&amp;gt;/C=US/O=DigiCert Inc/OU=&lt;A href="http://www.digicert.com/CN=DigiCert" target="_blank"&gt;www.digicert.com/CN=DigiCert&lt;/A&gt; High Assurance EV Root CA&amp;lt;/issuer&amp;gt;&lt;BR /&gt;&amp;lt;not-valid-after&amp;gt;Oct 22 12:00:00 2028 GMT&amp;lt;/not-valid-after&amp;gt;&lt;BR /&gt;&amp;lt;common-name&amp;gt;DigiCert SHA2 High Assurance Server CA&amp;lt;/common-name&amp;gt;&lt;BR /&gt;&amp;lt;algorithm&amp;gt;RSA&amp;lt;/algorithm&amp;gt;&lt;BR /&gt;&amp;lt;expiry-epoch&amp;gt;1855828800&amp;lt;/expiry-epoch&amp;gt;&lt;BR /&gt;&amp;lt;ca&amp;gt;yes&amp;lt;/ca&amp;gt;&lt;BR /&gt;&amp;lt;subject&amp;gt;/C=US/O=DigiCert Inc/OU=&lt;A href="http://www.digicert.com/CN=DigiCert" target="_blank"&gt;www.digicert.com/CN=DigiCert&lt;/A&gt; SHA2 High Assurance Server CA&amp;lt;/subject&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;lt;public-key&amp;gt;-----BEGIN CERTIFICATE-----&lt;BR /&gt;MIIEsTCCA5mgAwIBAgIQBOHnpNxc8vNtwCtCuF0VnzANBgkqhkiG9w0BAQsFADBs&lt;BR /&gt;MQswCQYDVQQGEwJVUzEVMBMGA1UEChMMRGlnaUNlcnQgSW5jMRkwFwYDVQQLExB3&lt;BR /&gt;d3cuZGlnaWNlcnQuY29tMSswKQYDVQQDEyJEaWdpQ2VydCBIaWdoIEFzc3VyYW5j&lt;BR /&gt;ZSBFViBSb290IENBMB4XDTEzMTAyMjEyMDAwMFoXDTI4MTAyMjEyMDAwMFowcDEL&lt;BR /&gt;MAkGA1UEBhMCVVMxFTATBgNVBAoTDERpZ2lDZXJ0IEluYzEZMBcGA1UECxMQd3d3&lt;BR /&gt;LmRpZ2ljZXJ0LmNvbTEvMC0GA1UEAxMmRGlnaUNlcnQgU0hBMiBIaWdoIEFzc3Vy&lt;BR /&gt;YW5jZSBTZXJ2ZXIgQ0EwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQC2&lt;BR /&gt;4C/CJAbIbQRf1+8KZAayfSImZRauQkCbztyfn3YHPsMwVYcZuU+UDlqUH1VWtMIC&lt;BR /&gt;Kq/QmO4LQNfE0DtyyBSe75CxEamu0si4QzrZCwvV1ZX1QK/IHe1NnF9Xt4ZQaJn1&lt;BR /&gt;itrSxwUfqJfJ3KSxgoQtxq2lnMcZgqaFD15EWCo3j/018QsIJzJa9buLnqS9UdAn&lt;BR /&gt;4t07QjOjBSjEuyjMmqwrIw14xnvmXnG3Sj4I+4G3FhahnSMSTeXXkgisdaScus0X&lt;BR /&gt;sh5ENWV/UyU50RwKmmMbGZJ0aAo3wsJSSMs5WqK24V3B3aAguCGikyZvFEohQcft&lt;BR /&gt;bZvySC/zA/WiaJJTL17jAgMBAAGjggFJMIIBRTASBgNVHRMBAf8ECDAGAQH/AgEA&lt;BR /&gt;MA4GA1UdDwEB/wQEAwIBhjAdBgNVHSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIw&lt;BR /&gt;NAYIKwYBBQUHAQEEKDAmMCQGCCsGAQUFBzABhhhodHRwOi8vb2NzcC5kaWdpY2Vy&lt;BR /&gt;dC5jb20wSwYDVR0fBEQwQjBAoD6gPIY6aHR0cDovL2NybDQuZGlnaWNlcnQuY29t&lt;BR /&gt;L0RpZ2lDZXJ0SGlnaEFzc3VyYW5jZUVWUm9vdENBLmNybDA9BgNVHSAENjA0MDIG&lt;BR /&gt;BFUdIAAwKjAoBggrBgEFBQcCARYcaHR0cHM6Ly93d3cuZGlnaWNlcnQuY29tL0NQ&lt;BR /&gt;UzAdBgNVHQ4EFgQUUWj/kK8CB3U8zNllZGKiErhZcjswHwYDVR0jBBgwFoAUsT7D&lt;BR /&gt;aQP4v0cB1JgmGggC72NkK8MwDQYJKoZIhvcNAQELBQADggEBABiKlYkD5m3fXPwd&lt;BR /&gt;aOpKj4PWUS+Na0QWnqxj9dJubISZi6qBcYRb7TROsLd5kinMLYBq8I4g4Xmk/gNH&lt;BR /&gt;E+r1hspZcX30BJZr01lYPf7TMSVcGDiEo+afgv2MW5gxTs14nhr9hctJqvIni5ly&lt;BR /&gt;/D6q1UEL2tU2ob8cbkdJf17ZSHwD2f2LSaCYJkJA69aSEaRkCldUxPUd1gJea6zu&lt;BR /&gt;xICaEnL6VpPX/78whQYwvwt/Tv9XBZ0k7YXDK/umdaisLRbvfXknsuvCnQsH6qqF&lt;BR /&gt;0wGjIChBWUMo0oHjqvbsezt3tkBigAVBRQHvFwY+3sAzm2fTYS5yh+Rp/BIAV0Ae&lt;BR /&gt;cPUeybQ=&lt;BR /&gt;-----END CERTIFICATE-----&lt;BR /&gt;&amp;lt;/public-key&amp;gt;&lt;BR /&gt;&amp;lt;/entry&amp;gt;&lt;/P&gt;</description>
      <pubDate>Tue, 31 Mar 2020 12:07:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/quot-only-self-signed-ca-cert-can-have-identical-sub-and-issuer/m-p/319553#M81939</guid>
      <dc:creator>JohnWade</dc:creator>
      <dc:date>2020-03-31T12:07:38Z</dc:date>
    </item>
    <item>
      <title>Re: "Only self signed CA cert can have identical sub and issuer fields" when uploading a c</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/quot-only-self-signed-ca-cert-can-have-identical-sub-and-issuer/m-p/319912#M81964</link>
      <description>&lt;P&gt;Is that the actual certificate ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It's a root CA so it's going to have the CA flag already set.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Nehmaan_0-1585740439151.png" style="width: 1429px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/24826i144D6F30ECE16FD1/image-dimensions/1429x50/is-moderation-mode/true?v=v2" width="1429" height="50" role="button" title="Nehmaan_0-1585740439151.png" alt="Nehmaan_0-1585740439151.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Export candidate-config:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Nehmaan_0-1585740779723.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/24828iCA22A5915E605C4B/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Nehmaan_0-1585740779723.png" alt="Nehmaan_0-1585740779723.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Apr 2020 11:33:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/quot-only-self-signed-ca-cert-can-have-identical-sub-and-issuer/m-p/319912#M81964</guid>
      <dc:creator>Nehmaan</dc:creator>
      <dc:date>2020-04-01T11:33:11Z</dc:date>
    </item>
    <item>
      <title>Re: "Only self signed CA cert can have identical sub and issuer fields" when uploading a c</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/quot-only-self-signed-ca-cert-can-have-identical-sub-and-issuer/m-p/319965#M81974</link>
      <description>&lt;P&gt;No, sorry if this was not clear.&amp;nbsp; &amp;nbsp;As I noted, this is just an example certificate from an existing CA taken from the XML config export.&amp;nbsp; &amp;nbsp;Since I can't import the certificate I need to add through the GUI, it is not in the export to tweak.&amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I included the example section to illustrate the fields you would need to have to manually create a certificate entry and import the config.&amp;nbsp; &amp;nbsp;I think I could put correct values in for most of them but am stumped by what hashing algorithm PaloAlto is using to generate the&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;lt;subject-hash&amp;gt;58754cf2&amp;lt;/subject-hash&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;lt;issuer-hash&amp;gt;81b9768f&amp;lt;/issuer-hash&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;But maybe I don't need to go down this path.&amp;nbsp; &amp;nbsp; Do you know of another way?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Apr 2020 12:45:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/quot-only-self-signed-ca-cert-can-have-identical-sub-and-issuer/m-p/319965#M81974</guid>
      <dc:creator>JohnWade</dc:creator>
      <dc:date>2020-04-01T12:45:16Z</dc:date>
    </item>
    <item>
      <title>Re: "Only self signed CA cert can have identical sub and issuer fields" when uploading a c</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/quot-only-self-signed-ca-cert-can-have-identical-sub-and-issuer/m-p/319979#M81978</link>
      <description>&lt;P&gt;Nothing to do with Palo, Here you go mate.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Nehmaan_0-1585746581829.png" style="width: 571px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/24829i89D742D175F0AE24/image-dimensions/571x322/is-moderation-mode/true?v=v2" width="571" height="322" role="button" title="Nehmaan_0-1585746581829.png" alt="Nehmaan_0-1585746581829.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Nehmaan_1-1585746613492.png" style="width: 570px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/24830iF06C50A2622A5FAB/image-dimensions/570x324/is-moderation-mode/true?v=v2" width="570" height="324" role="button" title="Nehmaan_1-1585746613492.png" alt="Nehmaan_1-1585746613492.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Apr 2020 13:10:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/quot-only-self-signed-ca-cert-can-have-identical-sub-and-issuer/m-p/319979#M81978</guid>
      <dc:creator>Nehmaan</dc:creator>
      <dc:date>2020-04-01T13:10:39Z</dc:date>
    </item>
    <item>
      <title>Re: "Only self signed CA cert can have identical sub and issuer fields" when uploading a c</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/quot-only-self-signed-ca-cert-can-have-identical-sub-and-issuer/m-p/319987#M81980</link>
      <description>&lt;P&gt;Easy enough, will give it a try.&amp;nbsp; Should have Googled it or gone to openssl rather than relying on Window's lame SSL cert tools.&amp;nbsp; Thanks a million&lt;/P&gt;</description>
      <pubDate>Wed, 01 Apr 2020 13:23:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/quot-only-self-signed-ca-cert-can-have-identical-sub-and-issuer/m-p/319987#M81980</guid>
      <dc:creator>JohnWade</dc:creator>
      <dc:date>2020-04-01T13:23:05Z</dc:date>
    </item>
  </channel>
</rss>

