<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Certificate ca status from the CLI in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/certificate-ca-status-from-the-cli/m-p/357275#M87757</link>
    <description>&lt;P&gt;I have successfully loaded my device certificate and a CA certificate from the CLI - took some seraching for format of the certificate strings, but they're in there now.&amp;nbsp;&lt;/P&gt;&lt;P&gt;One problem.&amp;nbsp;&lt;/P&gt;&lt;P&gt;In a firewall I have previously set up I show (in set format) the certificate stanza:&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;set shared certificate wanroot subject-hash ffffffff&lt;BR /&gt;set shared certificate wanroot issuer-hash ffffffff&lt;BR /&gt;set shared certificate wanroot not-valid-before "May 23 02:36:33 2020 GMT"&lt;BR /&gt;set shared certificate wanroot issuer /CN=wanroot&lt;BR /&gt;set shared certificate wanroot not-valid-after "May 18 02:36:33 2040 GMT"&lt;BR /&gt;set shared certificate wanroot common-name wanroot&lt;BR /&gt;set shared certificate wanroot expiry-epoch 2220921393&lt;BR /&gt;set shared certificate wanroot ca yes&lt;BR /&gt;set shared certificate wanroot subject /CN=wanroot&lt;BR /&gt;set shared certificate wanroot public-key "-----BEGIN CERTIFICATE-----[blahblahblah]-----END CERTIFICATE-----"&lt;BR /&gt;set shared certificate wanroot algorithm EC&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I get an error entering the line "set shared certificate wanroot ca yes" - Invalid syntax.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What is the correct way to declare a certificate a CA certificate from the CLI?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;--Matthew&lt;/P&gt;</description>
    <pubDate>Tue, 20 Oct 2020 04:27:07 GMT</pubDate>
    <dc:creator>MatthewSabin</dc:creator>
    <dc:date>2020-10-20T04:27:07Z</dc:date>
    <item>
      <title>Certificate ca status from the CLI</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/certificate-ca-status-from-the-cli/m-p/357275#M87757</link>
      <description>&lt;P&gt;I have successfully loaded my device certificate and a CA certificate from the CLI - took some seraching for format of the certificate strings, but they're in there now.&amp;nbsp;&lt;/P&gt;&lt;P&gt;One problem.&amp;nbsp;&lt;/P&gt;&lt;P&gt;In a firewall I have previously set up I show (in set format) the certificate stanza:&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;set shared certificate wanroot subject-hash ffffffff&lt;BR /&gt;set shared certificate wanroot issuer-hash ffffffff&lt;BR /&gt;set shared certificate wanroot not-valid-before "May 23 02:36:33 2020 GMT"&lt;BR /&gt;set shared certificate wanroot issuer /CN=wanroot&lt;BR /&gt;set shared certificate wanroot not-valid-after "May 18 02:36:33 2040 GMT"&lt;BR /&gt;set shared certificate wanroot common-name wanroot&lt;BR /&gt;set shared certificate wanroot expiry-epoch 2220921393&lt;BR /&gt;set shared certificate wanroot ca yes&lt;BR /&gt;set shared certificate wanroot subject /CN=wanroot&lt;BR /&gt;set shared certificate wanroot public-key "-----BEGIN CERTIFICATE-----[blahblahblah]-----END CERTIFICATE-----"&lt;BR /&gt;set shared certificate wanroot algorithm EC&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I get an error entering the line "set shared certificate wanroot ca yes" - Invalid syntax.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What is the correct way to declare a certificate a CA certificate from the CLI?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;--Matthew&lt;/P&gt;</description>
      <pubDate>Tue, 20 Oct 2020 04:27:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/certificate-ca-status-from-the-cli/m-p/357275#M87757</guid>
      <dc:creator>MatthewSabin</dc:creator>
      <dc:date>2020-10-20T04:27:07Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate ca status from the CLI</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/certificate-ca-status-from-the-cli/m-p/358027#M87836</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/58201"&gt;@MatthewSabin&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I was testing these commands in my lab but the following isn't a valid CLI syntax anymore (maybe it used to be in a previous PAN-OS) :&lt;/P&gt;
&lt;P&gt;set shared certificate &amp;lt;name&amp;gt; ca yes&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The one command that comes close is using certificate-profile but I'm guessing that's not what you're looking for ? :&lt;/P&gt;
&lt;P&gt;set shared certificate-profile &amp;lt;name&amp;gt; CA &lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I wasn't able to find anything else through CLI&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Maybe someone else has an idea ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;
&lt;DIV id="ConnectiveDocSignExtentionInstalled" data-extension-version="1.0.4"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Thu, 22 Oct 2020 08:02:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/certificate-ca-status-from-the-cli/m-p/358027#M87836</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2020-10-22T08:02:34Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate ca status from the CLI</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/certificate-ca-status-from-the-cli/m-p/360529#M88107</link>
      <description>&lt;P&gt;Thanks for the tip, but it turns out that my problem wasn't about syntax but method.&lt;/P&gt;&lt;P&gt;Pasting all of the parts of a certificate into the configuration and comitting doesn't actually "install" a certificate, or so I've learned.&lt;/P&gt;&lt;P&gt;Rather than pasting it in, TAC informs me that I must exit configuration mode and import the certificate as below:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;scp import certificate source-ip &amp;lt;scp server IP&amp;gt; remote-port &amp;lt;scp server port&amp;gt; from &amp;lt;user&amp;gt;@&amp;lt;scp server&amp;gt;:&amp;lt;path&amp;gt;&amp;lt;filename&amp;gt; format &amp;lt;pem|pkcs12&amp;gt; [passphrase &amp;lt;pass phrase&amp;gt;] certificate-name &amp;lt;name&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;Whe the certificate is imported, that invalid syntax line magically materializes in the show output.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Nov 2020 20:15:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/certificate-ca-status-from-the-cli/m-p/360529#M88107</guid>
      <dc:creator>MatthewSabin</dc:creator>
      <dc:date>2020-11-03T20:15:07Z</dc:date>
    </item>
  </channel>
</rss>

