<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Warnings: External Dynamic List &amp;lt;list&amp;gt; is configured with no certificate profile. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/warnings-external-dynamic-list-lt-list-gt-is-configured-with-no/m-p/242043#M96500</link>
    <description>&lt;P&gt;Same issue here.&amp;nbsp; This is another example of the limitations between device-groups and templates. This really needs to be addressed.&lt;/P&gt;</description>
    <pubDate>Tue, 04 Dec 2018 14:44:27 GMT</pubDate>
    <dc:creator>DrJonBane</dc:creator>
    <dc:date>2018-12-04T14:44:27Z</dc:date>
    <item>
      <title>Warnings: External Dynamic List &lt;list&gt; is configured with no certificate profile.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/warnings-external-dynamic-list-lt-list-gt-is-configured-with-no/m-p/170340#M96495</link>
      <description>&lt;P&gt;Warnings:&lt;/P&gt;
&lt;P&gt;External Dynamic List &amp;lt;list&amp;gt; is configured with no certificate profile.&lt;/P&gt;
&lt;P&gt;Please select a certificate profile for performing server certificate validation.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Customer went from 7.1.x to now 8.0.x and is using a MineMeld link in the External Dynami List(EDL).&amp;nbsp; This link is to a https site.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We followed this link:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/MineMeld-Articles/How-to-Generate-New-MineMeld-HTTPS-Cert/ta-p/101331" target="_blank"&gt;https://live.paloaltonetworks.com/t5/MineMeld-Articles/How-to-Generate-New-MineMeld-HTTPS-Cert/ta-p/101331&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After doing this, the warning was still there.&lt;/P&gt;
&lt;P&gt;We had also done this:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/policy/disable-authentication-for-an-external-dynamic-list" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/policy/disable-authentication-for-an-external-dynamic-list&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So when we went to choose a certificate profle, there was not an option to choose one.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="minemeldcertprof.JPG" style="width: 601px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/10663i6996B8FB343A19B5/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="minemeldcertprof.JPG" alt="minemeldcertprof.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Because of this, we force the certificate profile via the CLI:&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;# set shared external-list Minemeld-Office-365-IP type ip certificate-profile &amp;lt;cert profile&amp;gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;This resolved this issue.&amp;nbsp; Then MineMeld went to update the list and &lt;SPAN&gt;there was an Auth error and the list emptied.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;Error:&lt;BR /&gt;&lt;SPAN&gt;description contains 'EDL server certificate authentication failed. The associated external dynamic list has been removed, which might impact your policy. EDL Name: Minemeld-Office-365-IP, EDL Source URL: &lt;A href="https://10.x.xxx.xx/feeds/office365_IPv4s" target="_blank"&gt;https://10.x.xxx.xx/feeds/office365_IPv4s&lt;/A&gt;, CN: norminemeld, Reason: SSL peer certificate or SSH remote key was not OK'&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;The customer then went back to Panorama and removed the cert profile.&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;We have also looked at this post:&lt;BR /&gt;&lt;A href="https://live.paloaltonetworks.com/t5/General-Topics/Panorama-8-0-EDL-amp-Certificate-Profile/m-p/148098/highlight/true#M49516" target="_blank"&gt;https://live.paloaltonetworks.com/t5/General-Topics/Panorama-8-0-EDL-amp-Certificate-Profile/m-p/148098/highlight/true#M49516&lt;/A&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;Namely the second to the last comment by: PerTenggren&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;After&amp;nbsp;further investigation it seems&amp;nbsp;that EDL created as "shared" can't list any certificate profile, but it works if assigning the EDL to a specific device group.&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;Customer said that: &lt;SPAN&gt; All of our policies that reference the Minemeld external dynamic list are Shared (global) in nature and cannot see a local EDL.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Customer is wanting to not see this warning message after commits.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Aug 2017 16:12:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/warnings-external-dynamic-list-lt-list-gt-is-configured-with-no/m-p/170340#M96495</guid>
      <dc:creator>DaBone</dc:creator>
      <dc:date>2017-08-07T16:12:26Z</dc:date>
    </item>
    <item>
      <title>Re: Warnings: External Dynamic List &lt;list&gt; is configured with no certificate profile.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/warnings-external-dynamic-list-lt-list-gt-is-configured-with-no/m-p/170575#M96496</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/46097"&gt;@DaBone&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;this looks a problem with the configuration of PAN-OS and Panorama, have you opened a ticket to Palo Alto Networks TAC ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;luigi&lt;/P&gt;</description>
      <pubDate>Tue, 08 Aug 2017 17:57:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/warnings-external-dynamic-list-lt-list-gt-is-configured-with-no/m-p/170575#M96496</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2017-08-08T17:57:09Z</dc:date>
    </item>
    <item>
      <title>Re: Warnings: External Dynamic List &lt;list&gt; is configured with no certificate profile.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/warnings-external-dynamic-list-lt-list-gt-is-configured-with-no/m-p/170592#M96497</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/46097"&gt;@DaBone&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Are you trying to push Certificates and profiles from Panorama to the FW's? If you have Device Group parent with policies defined and child DG's with firewalls, you will need to put a fake serial number in the parent DG and the same fake serial number in the template that you have the certificates in.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Make sure you have enough device licenses in Panorama to add this fake serial number. When you commit the changes to Panorama and then push the DG and Template changes to the firewall, you should see the certificate and profile in your firewalls to make your EDL's.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;LG.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Aug 2017 19:30:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/warnings-external-dynamic-list-lt-list-gt-is-configured-with-no/m-p/170592#M96497</guid>
      <dc:creator>lgiancaterini</dc:creator>
      <dc:date>2017-08-08T19:30:01Z</dc:date>
    </item>
    <item>
      <title>Re: Warnings: External Dynamic List &lt;list&gt; is configured with no certificate profile.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/warnings-external-dynamic-list-lt-list-gt-is-configured-with-no/m-p/195994#M96498</link>
      <description>&lt;P&gt;Has any one been able to verify if the workaround suggested by LG resolves the issue?&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jan 2018 20:09:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/warnings-external-dynamic-list-lt-list-gt-is-configured-with-no/m-p/195994#M96498</guid>
      <dc:creator>Mike.ship</dc:creator>
      <dc:date>2018-01-19T20:09:14Z</dc:date>
    </item>
    <item>
      <title>Re: Warnings: External Dynamic List &lt;list&gt; is configured with no certificate profile.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/warnings-external-dynamic-list-lt-list-gt-is-configured-with-no/m-p/231383#M96499</link>
      <description>&lt;P&gt;We also setup EDLs in the "shared" device-group and we're unable to attach a cert-profile to those EDLs. However, if we clone that EDL into a device-group leaf we get to chose a cert-profile.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It's not really an option for us to clone an EDL into each device-group. We also had to build individual security rules this way. So we keep the shared EDL for now, without any cert-profile attached.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;(we're running v8.1.3 of Panorama)&lt;/P&gt;</description>
      <pubDate>Wed, 19 Sep 2018 06:24:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/warnings-external-dynamic-list-lt-list-gt-is-configured-with-no/m-p/231383#M96499</guid>
      <dc:creator>oschuler</dc:creator>
      <dc:date>2018-09-19T06:24:20Z</dc:date>
    </item>
    <item>
      <title>Re: Warnings: External Dynamic List &lt;list&gt; is configured with no certificate profile.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/warnings-external-dynamic-list-lt-list-gt-is-configured-with-no/m-p/242043#M96500</link>
      <description>&lt;P&gt;Same issue here.&amp;nbsp; This is another example of the limitations between device-groups and templates. This really needs to be addressed.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Dec 2018 14:44:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/warnings-external-dynamic-list-lt-list-gt-is-configured-with-no/m-p/242043#M96500</guid>
      <dc:creator>DrJonBane</dc:creator>
      <dc:date>2018-12-04T14:44:27Z</dc:date>
    </item>
    <item>
      <title>Re: Warnings: External Dynamic List &lt;list&gt; is configured with no certificate profile.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/warnings-external-dynamic-list-lt-list-gt-is-configured-with-no/m-p/248424#M96501</link>
      <description>&lt;P&gt;Any news regarding this issue?&lt;/P&gt;</description>
      <pubDate>Fri, 01 Feb 2019 10:46:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/warnings-external-dynamic-list-lt-list-gt-is-configured-with-no/m-p/248424#M96501</guid>
      <dc:creator>erikda</dc:creator>
      <dc:date>2019-02-01T10:46:32Z</dc:date>
    </item>
    <item>
      <title>Re: Warnings: External Dynamic List &lt;list&gt; is configured with no certificate profile.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/warnings-external-dynamic-list-lt-list-gt-is-configured-with-no/m-p/249155#M96502</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/61005"&gt;@erikda&lt;/a&gt;,&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/46097"&gt;@DaBone&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;do you have a case open with TAC about this? I would like to bring the discussion to our Product Management&lt;/P&gt;</description>
      <pubDate>Thu, 07 Feb 2019 08:09:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/warnings-external-dynamic-list-lt-list-gt-is-configured-with-no/m-p/249155#M96502</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2019-02-07T08:09:42Z</dc:date>
    </item>
    <item>
      <title>Re: Warnings: External Dynamic List &lt;list&gt; is configured with no certificate profile.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/warnings-external-dynamic-list-lt-list-gt-is-configured-with-no/m-p/249260#M96503</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11678"&gt;@lmori&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My case&lt;SPAN&gt;&amp;nbsp;01048381.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Feb 2019 16:08:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/warnings-external-dynamic-list-lt-list-gt-is-configured-with-no/m-p/249260#M96503</guid>
      <dc:creator>fwmike</dc:creator>
      <dc:date>2019-02-07T16:08:37Z</dc:date>
    </item>
    <item>
      <title>Re: Warnings: External Dynamic List &lt;list&gt; is configured with no certificate profile.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/warnings-external-dynamic-list-lt-list-gt-is-configured-with-no/m-p/250230#M96504</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11678"&gt;@lmori&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;Sorry I forgot about this post.&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;00717965 case, it is now resolved.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Feb 2019 16:32:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/warnings-external-dynamic-list-lt-list-gt-is-configured-with-no/m-p/250230#M96504</guid>
      <dc:creator>DaBone</dc:creator>
      <dc:date>2019-02-15T16:32:29Z</dc:date>
    </item>
    <item>
      <title>Re: Warnings: External Dynamic List &lt;list&gt; is configured with no certificate profile.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/warnings-external-dynamic-list-lt-list-gt-is-configured-with-no/m-p/250390#M96505</link>
      <description>&lt;P&gt;What was the fix? Is it something you had to change or is it included in a later release?&lt;/P&gt;</description>
      <pubDate>Mon, 18 Feb 2019 18:31:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/warnings-external-dynamic-list-lt-list-gt-is-configured-with-no/m-p/250390#M96505</guid>
      <dc:creator>mteachout</dc:creator>
      <dc:date>2019-02-18T18:31:56Z</dc:date>
    </item>
    <item>
      <title>Re: Warnings: External Dynamic List &lt;list&gt; is configured with no certificate profile.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/warnings-external-dynamic-list-lt-list-gt-is-configured-with-no/m-p/251630#M96506</link>
      <description>&lt;P&gt;I also faced same issue. TAC has advised to try this.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As far as EDL warning is concerned, cert profile need to be configured to verify server certificate using CA that signed CA cert. &lt;BR /&gt;&lt;BR /&gt;There are two ways to resolve warning&lt;BR /&gt;&lt;BR /&gt;1) use http instead of https to connect to webserver in EDL config&lt;BR /&gt;2) Or, configure cert profile using root CA that signed web server cert, Global sign in this case and use it in cert profile under EDL.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Feb 2019 02:29:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/warnings-external-dynamic-list-lt-list-gt-is-configured-with-no/m-p/251630#M96506</guid>
      <dc:creator>FarzanaMustafa</dc:creator>
      <dc:date>2019-02-28T02:29:38Z</dc:date>
    </item>
    <item>
      <title>Re: Warnings: External Dynamic List &lt;list&gt; is configured with no certificate profile.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/warnings-external-dynamic-list-lt-list-gt-is-configured-with-no/m-p/294739#M96507</link>
      <description>&lt;P&gt;The real issue with the use of certificate profiles on external dynamic lists is that the firewall administrator has no control over the actions of 3rd party external dynamic list providers.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;The list provider might force you to use HTTPS.&lt;/LI&gt;
&lt;LI&gt;The list provider is free to choose whichever SSL Certificate provider they want.&lt;/LI&gt;
&lt;LI&gt;If the certificate profile becomes invalid due to SSL certificate provider change, the list empties out, and you have no notification of this.&lt;/LI&gt;
&lt;LI&gt;So, how exactly does this provide security if it suddenly fails open?&lt;/LI&gt;
&lt;LI&gt;The GUI's "None (Disable Cert profile)" is a misnomer since it doesn't disable it to the point of no longer warning on policy commit.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;A proper fix would be that "None (Disable Cert profile)" does what it says it will do which is to not use it and by disabled means it won't warn about it either.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Oct 2019 15:52:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/warnings-external-dynamic-list-lt-list-gt-is-configured-with-no/m-p/294739#M96507</guid>
      <dc:creator>andrew571</dc:creator>
      <dc:date>2019-10-28T15:52:15Z</dc:date>
    </item>
    <item>
      <title>Re: Warnings: External Dynamic List &lt;list&gt; is configured with no certificate profile.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/warnings-external-dynamic-list-lt-list-gt-is-configured-with-no/m-p/476573#M103593</link>
      <description>&lt;P&gt;Unfortunately I still cannot attach a cert-profile to my "shared" EDLs under PAN-OS 9.1. Is this fixed with version 10 or 10.1?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Mar 2022 09:08:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/warnings-external-dynamic-list-lt-list-gt-is-configured-with-no/m-p/476573#M103593</guid>
      <dc:creator>Tobi</dc:creator>
      <dc:date>2022-03-29T09:08:49Z</dc:date>
    </item>
    <item>
      <title>Re: Warnings: External Dynamic List &lt;list&gt; is configured with no certificate profile.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/warnings-external-dynamic-list-lt-list-gt-is-configured-with-no/m-p/482315#M104270</link>
      <description>&lt;P&gt;You can try following:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. Push Certificate Profile via template to all firewalls.&lt;BR /&gt;2. Create the required EDL with the certificate profile on any device group&lt;BR /&gt;3. Commit and Push&lt;BR /&gt;&lt;STRONG&gt;4. Clone the EDL from the device group as a shared EDL.&lt;/STRONG&gt;&lt;BR /&gt;5. You can then select the Certificate Profile in the Shared EDL.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Apr 2022 14:11:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/warnings-external-dynamic-list-lt-list-gt-is-configured-with-no/m-p/482315#M104270</guid>
      <dc:creator>andrey11</dc:creator>
      <dc:date>2022-04-25T14:11:09Z</dc:date>
    </item>
    <item>
      <title>Re: Warnings: External Dynamic List &lt;list&gt; is configured with no certificate profile.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/warnings-external-dynamic-list-lt-list-gt-is-configured-with-no/m-p/521171#M108015</link>
      <description>&lt;P&gt;WOW!&lt;/P&gt;
&lt;P&gt;I even open a case that went to up the chain to the dev team and was told that with 10.2.3 it was going to be fixed!&lt;/P&gt;
&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/79449"&gt;@andrey11&lt;/a&gt;&amp;nbsp;AMAZING instructions!&lt;/P&gt;
&lt;P&gt;THANK YOU!!!&lt;/P&gt;
&lt;P&gt;5*'s!&lt;/P&gt;
&lt;P&gt;This process working, proves the platform can do it, but the pointers/database/code need to be looked at for the GUI.&lt;/P&gt;
&lt;P&gt;Palo Alto Needs to hire you! (:&lt;/P&gt;
&lt;P&gt;thanks again!&lt;/P&gt;</description>
      <pubDate>Mon, 14 Nov 2022 16:24:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/warnings-external-dynamic-list-lt-list-gt-is-configured-with-no/m-p/521171#M108015</guid>
      <dc:creator>miguelMA</dc:creator>
      <dc:date>2022-11-14T16:24:35Z</dc:date>
    </item>
    <item>
      <title>Re: Warnings: External Dynamic List &lt;list&gt; is configured with no certificate profile.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/warnings-external-dynamic-list-lt-list-gt-is-configured-with-no/m-p/534875#M110046</link>
      <description>&lt;P&gt;Alternatively, you can just type in the certificate profile without moving the edl around device groups..... for some reason.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For example we use some of the Palo Alto maintained edls (&lt;A href="https://docs.paloaltonetworks.com/resources/edl-hosting-service" target="_blank" rel="noopener"&gt;EDL Hosting Service (paloaltonetworks.com)&lt;/A&gt;) and we named the certificate profile, "PaloAlto-EDL-Cert-Profile", I can manually type that in the shared edl even though its not an option in the drop down menu. I dont know how this works but Palo cant make it appear in the drop down menu&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Mar 2023 16:32:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/warnings-external-dynamic-list-lt-list-gt-is-configured-with-no/m-p/534875#M110046</guid>
      <dc:creator>Claw4609</dc:creator>
      <dc:date>2023-03-17T16:32:56Z</dc:date>
    </item>
    <item>
      <title>Re: Warnings: External Dynamic List &lt;list&gt; is configured with no certificate profile.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/warnings-external-dynamic-list-lt-list-gt-is-configured-with-no/m-p/551630#M112301</link>
      <description>&lt;P&gt;Follow up:&lt;/P&gt;
&lt;P&gt;Still not fixed in the newer vesions, running the latest 11.x code and still not fixed.&lt;/P&gt;
&lt;P&gt;In addition, stacking manualy into 1 txt file all the certifficate chain no longer works.&lt;/P&gt;
&lt;P&gt;this is what i did to make it work.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. go to firefox (chrome doesn't give you the options below) and pull up&amp;nbsp; the https URL where the list is published.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;in firefox, pull up the certificate and download the pem file for each of the certs in the chain (pem)&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="miguelMA_0-1690566356298.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/52341iA9904CFE3B51ABDD/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="miguelMA_0-1690566356298.png" alt="miguelMA_0-1690566356298.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;2. Then got to panorama and IMPORT in the share each certificate.&lt;/P&gt;
&lt;P&gt;committ push&lt;/P&gt;
&lt;P&gt;3. Then go to the individual device template and build a local certificate profile that uses/references the individually shared certificates&lt;/P&gt;
&lt;P&gt;commit push&lt;/P&gt;
&lt;P&gt;4. then go to the created certifiate profile and clone it to SHARE.&lt;/P&gt;
&lt;P&gt;committ push&lt;/P&gt;
&lt;P&gt;5. delete the individual local profile.&lt;/P&gt;
&lt;P&gt;6. build the new external dynamic list object usign the same URL as step 1.&lt;/P&gt;
&lt;P&gt;7. the new certifiate profile will now be available to use in the new shared external dyanmic list dropdown.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This used to work by using a single certificate that was manually stacked and saved as one certificate but it seeems that is no longer the case.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps someone outthere and keeps some of the pain away (:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jul 2023 17:55:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/warnings-external-dynamic-list-lt-list-gt-is-configured-with-no/m-p/551630#M112301</guid>
      <dc:creator>miguelMA</dc:creator>
      <dc:date>2023-07-28T17:55:51Z</dc:date>
    </item>
  </channel>
</rss>

