<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Is there a secure way to generate XML API tokens? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/is-there-a-secure-way-to-generate-xml-api-tokens/m-p/309292#M80169</link>
    <description>&lt;P&gt;Hello &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/132223"&gt;@StefanLoeve&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How about applying a SSL certificate on the management interface of the firewall? That given, the credentials are no longer flying in plaintext over the wire.&lt;/P&gt;</description>
    <pubDate>Tue, 04 Feb 2020 05:58:19 GMT</pubDate>
    <dc:creator>JoergSchuetter</dc:creator>
    <dc:date>2020-02-04T05:58:19Z</dc:date>
    <item>
      <title>Is there a secure way to generate XML API tokens?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-there-a-secure-way-to-generate-xml-api-tokens/m-p/309259#M80166</link>
      <description>&lt;P&gt;I've been trawling Google for a while now trying to find an alternate way to generate the XML API token. However there only seems to be one method to do so.&lt;/P&gt;&lt;P&gt;Maybe I'm a little paranoid, but it seems really insecure to send your admin username and password in plaintext to the firewall to generate an API token. In a world where network security is paramount for a modern business, it seems like a glaring oversight to force users to only be able to generate an API token in this manner. It would be great if there was another method to generate the token in a way that doesn't require you to do so.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Am I alone in feeling this way? Has anyone else found a way around this? Your thoughtful responses are appreciated.&lt;/P&gt;</description>
      <pubDate>Mon, 03 Feb 2020 22:40:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-there-a-secure-way-to-generate-xml-api-tokens/m-p/309259#M80166</guid>
      <dc:creator>StefanLoeve</dc:creator>
      <dc:date>2020-02-03T22:40:47Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a secure way to generate XML API tokens?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-there-a-secure-way-to-generate-xml-api-tokens/m-p/309292#M80169</link>
      <description>&lt;P&gt;Hello &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/132223"&gt;@StefanLoeve&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How about applying a SSL certificate on the management interface of the firewall? That given, the credentials are no longer flying in plaintext over the wire.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Feb 2020 05:58:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-there-a-secure-way-to-generate-xml-api-tokens/m-p/309292#M80169</guid>
      <dc:creator>JoergSchuetter</dc:creator>
      <dc:date>2020-02-04T05:58:19Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a secure way to generate XML API tokens?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-there-a-secure-way-to-generate-xml-api-tokens/m-p/309436#M80199</link>
      <description>&lt;P&gt;Hello Jeorg.&lt;/P&gt;&lt;P&gt;I have already applied an SSL certificate to the webUI. Thanks for pointing me in that direction. I hadn't properly understood that the hostname is the only part that isn't encrypted when connecting using HTTPS. Thanks for the quick response!&lt;/P&gt;</description>
      <pubDate>Tue, 04 Feb 2020 17:41:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-there-a-secure-way-to-generate-xml-api-tokens/m-p/309436#M80199</guid>
      <dc:creator>StefanLoeve</dc:creator>
      <dc:date>2020-02-04T17:41:22Z</dc:date>
    </item>
  </channel>
</rss>

