<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Failed to delete Certificate due to references - but I don't want to delete those references in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/failed-to-delete-certificate-due-to-references-but-i-don-t-want/m-p/412184#M92827</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;my current GlobalProtect portal/gateway certificate is expiring soon so I had our 3rd party CA create a new one with the same name.&amp;nbsp; In Panorama under templates/device/certificates, I uploaded the new cert with a temporary name (ex. expiring cert name is foobar.net so I uploaded the new cert as new_foobar.net).&amp;nbsp; Now I want to delete the expiring foobar.net and rename new_foobar.net to foobar.net.&amp;nbsp; If I don't name it the same, I'll have to find everywhere it is referenced and change it multiple times.&amp;nbsp; The problem is that when I go to delete the expiring cert, I get the familiar "foobar.net cannot be deleted because of references from: ..."&lt;/P&gt;
&lt;P&gt;Anyone know a way to get around this?&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 09 Jun 2021 19:02:09 GMT</pubDate>
    <dc:creator>Joni_Larned</dc:creator>
    <dc:date>2021-06-09T19:02:09Z</dc:date>
    <item>
      <title>Failed to delete Certificate due to references - but I don't want to delete those references</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/failed-to-delete-certificate-due-to-references-but-i-don-t-want/m-p/412184#M92827</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;my current GlobalProtect portal/gateway certificate is expiring soon so I had our 3rd party CA create a new one with the same name.&amp;nbsp; In Panorama under templates/device/certificates, I uploaded the new cert with a temporary name (ex. expiring cert name is foobar.net so I uploaded the new cert as new_foobar.net).&amp;nbsp; Now I want to delete the expiring foobar.net and rename new_foobar.net to foobar.net.&amp;nbsp; If I don't name it the same, I'll have to find everywhere it is referenced and change it multiple times.&amp;nbsp; The problem is that when I go to delete the expiring cert, I get the familiar "foobar.net cannot be deleted because of references from: ..."&lt;/P&gt;
&lt;P&gt;Anyone know a way to get around this?&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jun 2021 19:02:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/failed-to-delete-certificate-due-to-references-but-i-don-t-want/m-p/412184#M92827</guid>
      <dc:creator>Joni_Larned</dc:creator>
      <dc:date>2021-06-09T19:02:09Z</dc:date>
    </item>
    <item>
      <title>Re: Failed to delete Certificate due to references - but I don't want to delete those references</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/failed-to-delete-certificate-due-to-references-but-i-don-t-want/m-p/412754#M92873</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/182422"&gt;@Joni_Larned&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is the whole purpose of "SSL/TLS Service Profile".&lt;/P&gt;&lt;P&gt;-&amp;nbsp; You select a certificate in the service profile and use this profile everywher you need.&lt;/P&gt;&lt;P&gt;- When you need to renew/change the certificate you change it only in the service profile, which apply to all locations where this profile is being used.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In addition - you cannot refrence certificate anywhere except ssl/tls service profile. So you don't have to worrie that you need to change the certificate anywhere else.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So what you need to do is:&lt;/P&gt;&lt;P&gt;- Find the ssl/tls service profile which is using the certificate that needs to be replaced&lt;/P&gt;&lt;P&gt;- Edit it and select from the dropdown your new certificate&lt;/P&gt;&lt;P&gt;- Commit and push config&lt;/P&gt;&lt;P&gt;- You should be able to old ceritifcate now&lt;/P&gt;&lt;P&gt;- (optional) now you can renew your new cert (removing "new_") name. This should automaticaly reflect in the service profile, but you can go and doublecheck if profile is using the update name. Commit and push to have it on the FW.&lt;/P&gt;</description>
      <pubDate>Sat, 12 Jun 2021 20:14:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/failed-to-delete-certificate-due-to-references-but-i-don-t-want/m-p/412754#M92873</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2021-06-12T20:14:31Z</dc:date>
    </item>
  </channel>
</rss>

