<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Secure web-GUI access for managment in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/secure-web-gui-access-for-managment/m-p/365067#M88532</link>
    <description>&lt;P&gt;Dears,&lt;/P&gt;&lt;P&gt;When i log in my firewall it is showing the connection not secure.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Jafar_Hussain_0-1606198282984.png" style="width: 625px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/28783i3D79470E1308DCAE/image-dimensions/625x25/is-moderation-mode/true?v=v2" width="625" height="25" role="button" title="Jafar_Hussain_0-1606198282984.png" alt="Jafar_Hussain_0-1606198282984.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For secure connection login, i have gone through these documents and try to configure a secure connection for web GUI access.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClFGCA0" target="_blank"&gt;How To Configure A Certificate For Secure Web-GUI Access - Knowledge Base - Palo Alto Networks&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Procedure 1 I followed:-&lt;/P&gt;&lt;P&gt;- Created a self-sign certificate with a common name management IP address.&lt;/P&gt;&lt;P&gt;- Created an SSL/TLS profile and attached the self-sign certificate in SSL/TLS profile&lt;/P&gt;&lt;P&gt;- Then Device&amp;gt;Setup&amp;gt;&amp;gt;management&amp;gt;general setting &amp;gt; Attached the same SSL/TLS profile and commit.&lt;/P&gt;&lt;P&gt;- Export the self-sign certificate in import in client machine trusted root certificate store.&lt;/P&gt;&lt;P&gt;- Tried to login into the firewall in a different browser.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Procedure 2 i followed:-&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Created a CSR request and the certificate sign by internal CA.&lt;/P&gt;&lt;P&gt;- Import the certificate in the firewall.&lt;/P&gt;&lt;P&gt;- Created an SSL/TLS profile and attached the newly imported certificate in SSL/TLS profile&lt;/P&gt;&lt;P&gt;- Then Device&amp;gt;Setup&amp;gt;&amp;gt;management&amp;gt;general setting &amp;gt; Attached the same SSL/TLS profile and commit.&lt;/P&gt;&lt;P&gt;- Export the certificate in import in client machine trusted root certificate store.&lt;/P&gt;&lt;P&gt;- Tried to login into the firewall in a different browser.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tried two both above procedures but still, I am facing the connection, not a secure error.&lt;/P&gt;&lt;P&gt;Can anyone help me with this.&lt;/P&gt;</description>
    <pubDate>Tue, 24 Nov 2020 06:24:03 GMT</pubDate>
    <dc:creator>Jafar_Hussain</dc:creator>
    <dc:date>2020-11-24T06:24:03Z</dc:date>
    <item>
      <title>Secure web-GUI access for managment</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/secure-web-gui-access-for-managment/m-p/365067#M88532</link>
      <description>&lt;P&gt;Dears,&lt;/P&gt;&lt;P&gt;When i log in my firewall it is showing the connection not secure.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Jafar_Hussain_0-1606198282984.png" style="width: 625px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/28783i3D79470E1308DCAE/image-dimensions/625x25/is-moderation-mode/true?v=v2" width="625" height="25" role="button" title="Jafar_Hussain_0-1606198282984.png" alt="Jafar_Hussain_0-1606198282984.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For secure connection login, i have gone through these documents and try to configure a secure connection for web GUI access.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClFGCA0" target="_blank"&gt;How To Configure A Certificate For Secure Web-GUI Access - Knowledge Base - Palo Alto Networks&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Procedure 1 I followed:-&lt;/P&gt;&lt;P&gt;- Created a self-sign certificate with a common name management IP address.&lt;/P&gt;&lt;P&gt;- Created an SSL/TLS profile and attached the self-sign certificate in SSL/TLS profile&lt;/P&gt;&lt;P&gt;- Then Device&amp;gt;Setup&amp;gt;&amp;gt;management&amp;gt;general setting &amp;gt; Attached the same SSL/TLS profile and commit.&lt;/P&gt;&lt;P&gt;- Export the self-sign certificate in import in client machine trusted root certificate store.&lt;/P&gt;&lt;P&gt;- Tried to login into the firewall in a different browser.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Procedure 2 i followed:-&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Created a CSR request and the certificate sign by internal CA.&lt;/P&gt;&lt;P&gt;- Import the certificate in the firewall.&lt;/P&gt;&lt;P&gt;- Created an SSL/TLS profile and attached the newly imported certificate in SSL/TLS profile&lt;/P&gt;&lt;P&gt;- Then Device&amp;gt;Setup&amp;gt;&amp;gt;management&amp;gt;general setting &amp;gt; Attached the same SSL/TLS profile and commit.&lt;/P&gt;&lt;P&gt;- Export the certificate in import in client machine trusted root certificate store.&lt;/P&gt;&lt;P&gt;- Tried to login into the firewall in a different browser.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tried two both above procedures but still, I am facing the connection, not a secure error.&lt;/P&gt;&lt;P&gt;Can anyone help me with this.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Nov 2020 06:24:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/secure-web-gui-access-for-managment/m-p/365067#M88532</guid>
      <dc:creator>Jafar_Hussain</dc:creator>
      <dc:date>2020-11-24T06:24:03Z</dc:date>
    </item>
    <item>
      <title>Re: Secure web-GUI access for managment</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/secure-web-gui-access-for-managment/m-p/365081#M88533</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/124013"&gt;@Jafar_Hussain&lt;/a&gt;&amp;nbsp; Your screenshot shows you are accessing it by IP, instead you should be accessing it by the common name you have set while creating cert.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Nov 2020 06:44:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/secure-web-gui-access-for-managment/m-p/365081#M88533</guid>
      <dc:creator>raji_toor</dc:creator>
      <dc:date>2020-11-24T06:44:49Z</dc:date>
    </item>
    <item>
      <title>Re: Secure web-GUI access for managment</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/secure-web-gui-access-for-managment/m-p/365082#M88534</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/56221"&gt;@raji_toor&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As i mentioned i have given the management IP address in the certificate common name.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Nov 2020 06:47:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/secure-web-gui-access-for-managment/m-p/365082#M88534</guid>
      <dc:creator>Jafar_Hussain</dc:creator>
      <dc:date>2020-11-24T06:47:13Z</dc:date>
    </item>
    <item>
      <title>Re: Secure web-GUI access for managment</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/secure-web-gui-access-for-managment/m-p/365305#M88551</link>
      <description>&lt;P&gt;If i am not wrong it should be a dns name and not IP in there although it doesn't stop you from entering IP&lt;/P&gt;</description>
      <pubDate>Tue, 24 Nov 2020 17:17:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/secure-web-gui-access-for-managment/m-p/365305#M88551</guid>
      <dc:creator>raji_toor</dc:creator>
      <dc:date>2020-11-24T17:17:05Z</dc:date>
    </item>
    <item>
      <title>Re: Secure web-GUI access for managment</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/secure-web-gui-access-for-managment/m-p/365421#M88556</link>
      <description>&lt;P&gt;For procedure 1, if you use a firewall self-signed cert for the web management, you're workstation won't trust that cert unless you import the firewall CA certificate on to your workstation.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For procedure 2, you don't need to export/import the device certificate. If your workstation trusts your internal CA, then your workstation will trust any certificates issued by that internal CA wherever they are installed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What's the message if you click on 'Not secure'? It will usually point you in the right direction for troubleshooting. What does the subject and subject alternative show in the certificate details?&lt;/P&gt;</description>
      <pubDate>Wed, 25 Nov 2020 00:00:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/secure-web-gui-access-for-managment/m-p/365421#M88556</guid>
      <dc:creator>rmfalconer</dc:creator>
      <dc:date>2020-11-25T00:00:04Z</dc:date>
    </item>
    <item>
      <title>Re: Secure web-GUI access for managment</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/secure-web-gui-access-for-managment/m-p/365488#M88572</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/55733"&gt;@rmfalconer&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For procedure 1, if you use a firewall self-signed cert for the web management, you're workstation won't trust that cert unless you import the firewall CA certificate on to your workstation. -&amp;nbsp; &lt;STRONG&gt;installed the certificate on the workstation but did not work.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For procedure 2, you don't need to export/import the device certificate. If your workstation trusts your internal CA, then your workstation will trust any certificates issued by that internal CA wherever they are installed.-&amp;nbsp; &lt;STRONG&gt;OK got it.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;when I use a self-sign certificate and try to login in to the firewall. the below error is showing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Jafar_Hussain_0-1606298038801.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/28798i1B7ADDC0F62FE070/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Jafar_Hussain_0-1606298038801.png" alt="Jafar_Hussain_0-1606298038801.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;but when i check the certificate it is showing OK.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Jafar_Hussain_1-1606298100401.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/28799i964501119FB9F3CE/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Jafar_Hussain_1-1606298100401.png" alt="Jafar_Hussain_1-1606298100401.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Nov 2020 09:55:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/secure-web-gui-access-for-managment/m-p/365488#M88572</guid>
      <dc:creator>Jafar_Hussain</dc:creator>
      <dc:date>2020-11-25T09:55:42Z</dc:date>
    </item>
    <item>
      <title>Re: Secure web-GUI access for managment</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/secure-web-gui-access-for-managment/m-p/366363#M88693</link>
      <description>&lt;P&gt;Did you create a certificate authority on the PA and then use that to issue the device certificate? The root certificate from the PA would need to be imported into your local machine's certificate store, not the device certificate. For the device certificate to be trusted by your PC, the root that issued it needs to be trusted.&lt;/P&gt;&lt;P&gt;For actually generating the certificate, you'll probably need to use an actual name as the CN, not an IP address. Most authorities won't issue with an IP address as the CN. If you want to include the IP as a valid entry, create it as a SAN entry on the cert using the IP field. You should also include the CN in the SAN entry as well.&lt;/P&gt;&lt;P&gt;Try this:&lt;/P&gt;&lt;P&gt;Create a root authority on the PA:&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/certificate-management/obtain-certificates/create-a-self-signed-root-ca-certificate.html" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/certificate-management/obtain-certificates/create-a-self-signed-root-ca-certificate.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Export this root certificate and import to the trusted root store on your computer.&lt;/P&gt;&lt;P&gt;Generate a device certificate on the PA signed by the root you just created:&lt;/P&gt;&lt;P&gt;&amp;nbsp;Common name: firewallname.company.com&lt;/P&gt;&lt;P&gt;&amp;nbsp;Attribute Hostname: firewallname.company.com&lt;/P&gt;&lt;P&gt;&amp;nbsp;Attribute Hostname: firewallname&lt;/P&gt;&lt;P&gt;&amp;nbsp;Attribute IP: 172.16.3.30&lt;/P&gt;&lt;P&gt;Then assign this cert to your SSL/TLS profile.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Nov 2020 20:17:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/secure-web-gui-access-for-managment/m-p/366363#M88693</guid>
      <dc:creator>rmfalconer</dc:creator>
      <dc:date>2020-11-30T20:17:37Z</dc:date>
    </item>
  </channel>
</rss>

