<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PANOS 8.0.0 EDL requires certificate in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/panos-8-0-0-edl-requires-certificate/m-p/140984#M96790</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/10823"&gt;@luks&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;the default MineMeld certificate is self-signed and won't work with PAN-OS 8.0. You should:&lt;/P&gt;
&lt;P&gt;- create a new certificate signed by a CA&lt;/P&gt;
&lt;P&gt;- copy the full certificate chain in /etc/nginx/minemeld.cer and the private key in /etc/nginx/minemeld.pem&lt;/P&gt;
&lt;P&gt;- reload nginx config (sudo service nginx reload)&lt;/P&gt;
&lt;P&gt;- use the CA public certificate in PAN-OS 8.0 Certificate Profile&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you don't have an internal CA,&amp;nbsp;a quick fix is the script here:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://gist.github.com/jtschichold/f0977e5c1ec09b3ec7d66bf80687d9da" target="_blank"&gt;https://gist.github.com/jtschichold/f0977e5c1ec09b3ec7d66bf80687d9da&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There are instructions in the comment at the end of the script on how to use it. The script automatically generates a new CA, creates and signs a certificate for MineMeld Webui, moves the files in their places, and destroys the CA private key to eliminate the risk of the CA becoming compromised. At the end of the script you can take the generated CA.crt file and use it inside the PAN-OS 8.0 Certificate Profile.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 03 Feb 2017 18:38:44 GMT</pubDate>
    <dc:creator>lmori</dc:creator>
    <dc:date>2017-02-03T18:38:44Z</dc:date>
    <item>
      <title>PANOS 8.0.0 EDL requires certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panos-8-0-0-edl-requires-certificate/m-p/140976#M96789</link>
      <description>&lt;P&gt;Hey guys,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just set up Minemeld, upgraded to PANOS 8.0.0, running into an issue with seeting up the EDL, the source (&lt;A href="https://minemeld.local/feeds/inboundfeedhc" target="_blank"&gt;https://minemeld.local/feeds/inboundfeedhc&lt;/A&gt;) being HTTPS, PANOS now requires a certificate profile for the communication to work - what shpuld be configured there, and what -if anything- on the minemeld server?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Great tool by the way!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;Luk&lt;/P&gt;</description>
      <pubDate>Fri, 03 Feb 2017 18:27:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panos-8-0-0-edl-requires-certificate/m-p/140976#M96789</guid>
      <dc:creator>luks</dc:creator>
      <dc:date>2017-02-03T18:27:37Z</dc:date>
    </item>
    <item>
      <title>Re: PANOS 8.0.0 EDL requires certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panos-8-0-0-edl-requires-certificate/m-p/140984#M96790</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/10823"&gt;@luks&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;the default MineMeld certificate is self-signed and won't work with PAN-OS 8.0. You should:&lt;/P&gt;
&lt;P&gt;- create a new certificate signed by a CA&lt;/P&gt;
&lt;P&gt;- copy the full certificate chain in /etc/nginx/minemeld.cer and the private key in /etc/nginx/minemeld.pem&lt;/P&gt;
&lt;P&gt;- reload nginx config (sudo service nginx reload)&lt;/P&gt;
&lt;P&gt;- use the CA public certificate in PAN-OS 8.0 Certificate Profile&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you don't have an internal CA,&amp;nbsp;a quick fix is the script here:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://gist.github.com/jtschichold/f0977e5c1ec09b3ec7d66bf80687d9da" target="_blank"&gt;https://gist.github.com/jtschichold/f0977e5c1ec09b3ec7d66bf80687d9da&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There are instructions in the comment at the end of the script on how to use it. The script automatically generates a new CA, creates and signs a certificate for MineMeld Webui, moves the files in their places, and destroys the CA private key to eliminate the risk of the CA becoming compromised. At the end of the script you can take the generated CA.crt file and use it inside the PAN-OS 8.0 Certificate Profile.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Feb 2017 18:38:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panos-8-0-0-edl-requires-certificate/m-p/140984#M96790</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2017-02-03T18:38:44Z</dc:date>
    </item>
    <item>
      <title>Re: PANOS 8.0.0 EDL requires certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panos-8-0-0-edl-requires-certificate/m-p/141020#M96791</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for the quick reply!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Ok i got that done, got the PEM key and then followed these instructions to split the key (&lt;A href="https://live.paloaltonetworks.com/t5/MineMeld-Articles/How-to-Generate-New-MineMeld-HTTPS-Cert/ta-p/101331" target="_blank"&gt;https://live.paloaltonetworks.com/t5/MineMeld-Articles/How-to-Generate-New-MineMeld-HTTPS-Cert/ta-p/101331&lt;/A&gt;) .&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;so I end up with these files&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;-rw-r--r--&amp;nbsp; 1 luks luks 2791 Feb&amp;nbsp; 3 19:52 cert_minemeld.pem&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;-rw-r--r--&amp;nbsp; 1 root root 1025 Feb&amp;nbsp; 3 20:19 minemeld.cer&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;-rw-r--r--&amp;nbsp; 1 root root 1766 Feb&amp;nbsp; 3 20:19 minemeld1.cer&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Doing the following works, but &lt;STRONG&gt;I still get the URL Access&lt;/STRONG&gt; error on my Palo Alto firewall (PS/ etc/nginx/minemeld/ directory doesn't exist so I just used /etc/nginx). I am using the right certificate in the profile on the ELD.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;[minemeld ~]$ sudo cp minemeld.cer /etc/nginx/minemeld.cer&lt;BR /&gt;[minemeld ~]$ sudo openssl rsa -in minemeld1.cer -out /etc/ngnix/minemeld/minemeld.pem&lt;BR /&gt;[minemeld ~]$ sudo service nginx restart&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;I think I'm doing something wrong on the NGINX part?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks again for the help,&lt;/P&gt;
&lt;P&gt;Luk&lt;/P&gt;</description>
      <pubDate>Fri, 03 Feb 2017 19:34:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panos-8-0-0-edl-requires-certificate/m-p/141020#M96791</guid>
      <dc:creator>luks</dc:creator>
      <dc:date>2017-02-03T19:34:32Z</dc:date>
    </item>
    <item>
      <title>Re: PANOS 8.0.0 EDL requires certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panos-8-0-0-edl-requires-certificate/m-p/141030#M96792</link>
      <description>&lt;P&gt;I found it, it was a routing issue (service route configuration needed to be changed)&lt;/P&gt;
&lt;P&gt;DUH!&lt;/P&gt;
&lt;P&gt;it's working now, thanks agan!&lt;/P&gt;
&lt;P&gt;Luk&lt;/P&gt;</description>
      <pubDate>Fri, 03 Feb 2017 19:56:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panos-8-0-0-edl-requires-certificate/m-p/141030#M96792</guid>
      <dc:creator>luks</dc:creator>
      <dc:date>2017-02-03T19:56:26Z</dc:date>
    </item>
    <item>
      <title>Re: PANOS 8.0.0 EDL requires certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panos-8-0-0-edl-requires-certificate/m-p/142146#M96793</link>
      <description>&lt;P&gt;I am having diffilculties with the Certificate Profile. In the System logs I see an error regarding the EDL Server authentication being failed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;"Reason: unable to get local issuer certificat"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I already created a CertProfile with the CA Cert of the MineMeld Server. Configured my EDL with the appropriate Cert Profile. Am I a missing something ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Roland&lt;/P&gt;</description>
      <pubDate>Thu, 09 Feb 2017 15:57:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panos-8-0-0-edl-requires-certificate/m-p/142146#M96793</guid>
      <dc:creator>gafrol</dc:creator>
      <dc:date>2017-02-09T15:57:30Z</dc:date>
    </item>
    <item>
      <title>Re: PANOS 8.0.0 EDL requires certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panos-8-0-0-edl-requires-certificate/m-p/142299#M96794</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/5885"&gt;@gafrol&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;have you already generated a new certificate for MineMeld ? The default certificate on MineMeld is self-signed and it can't be used in a Certificate Profile.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;An easy way to generate a new certificate is:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;ssh into the MineMeld instance&lt;/LI&gt;
&lt;LI&gt;type the following commands&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;$ wget https://gist.githubusercontent.com/jtschichold/f0977e5c1ec09b3ec7d66bf80687d9da/raw/7ec994a3a731637ffa335365adddddbfd92004f2/generate-certificate.sh
$ chmod a+x generate-certificate.sh
$ sudo ./generate-certificate.sh &amp;lt;minemeld ip address&amp;gt;&lt;/PRE&gt;
&lt;UL&gt;
&lt;LI&gt;at the end of the operation above the MineMeld WebUI has a new certificate and you can grab the CA certificate from the browser or from the file CA.crt in the directory where you typed the commands&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;If you want to check the details of the script check this gist here:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://gist.github.com/jtschichold/f0977e5c1ec09b3ec7d66bf80687d9da" target="_self"&gt;https://gist.github.com/jtschichold/f0977e5c1ec09b3ec7d66bf80687d9da&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Feb 2017 09:56:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panos-8-0-0-edl-requires-certificate/m-p/142299#M96794</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2017-02-15T09:56:59Z</dc:date>
    </item>
    <item>
      <title>Re: PANOS 8.0.0 EDL requires certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panos-8-0-0-edl-requires-certificate/m-p/142871#M96795</link>
      <description>&lt;P&gt;We are using an official certificate for our MineMeld install. Just had to add the intermediate SSL cert to the Cert Profile. Now it is working.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks&lt;/P&gt;
&lt;P&gt;Roland&lt;/P&gt;</description>
      <pubDate>Tue, 14 Feb 2017 10:09:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panos-8-0-0-edl-requires-certificate/m-p/142871#M96795</guid>
      <dc:creator>gafrol</dc:creator>
      <dc:date>2017-02-14T10:09:33Z</dc:date>
    </item>
    <item>
      <title>Re: PANOS 8.0.0 EDL requires certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panos-8-0-0-edl-requires-certificate/m-p/143126#M96796</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/5885"&gt;@gafrol&lt;/a&gt;, using a valid certificate is a far better solution !&lt;/P&gt;</description>
      <pubDate>Wed, 15 Feb 2017 09:57:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panos-8-0-0-edl-requires-certificate/m-p/143126#M96796</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2017-02-15T09:57:45Z</dc:date>
    </item>
    <item>
      <title>Re: PANOS 8.0.0 EDL requires certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panos-8-0-0-edl-requires-certificate/m-p/143130#M96797</link>
      <description>&lt;P&gt;Absolutely, we provide MineMeld as a Service (running in our Datacenter) to our PAN FW customers. So a commercial certificate is a must. It is working like a charm now .&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Rgds&lt;/P&gt;
&lt;P&gt;Roland&lt;/P&gt;</description>
      <pubDate>Wed, 15 Feb 2017 10:07:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panos-8-0-0-edl-requires-certificate/m-p/143130#M96797</guid>
      <dc:creator>gafrol</dc:creator>
      <dc:date>2017-02-15T10:07:12Z</dc:date>
    </item>
    <item>
      <title>Re: PANOS 8.0.0 EDL requires certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panos-8-0-0-edl-requires-certificate/m-p/181461#M96798</link>
      <description>&lt;P&gt;I have followed your outlined procedure...but still i get this output:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;admin@PA-VM&amp;gt; request system external-list show type domain name sdfsdfsdf&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;vsys1/sdfsdfsdf:&lt;BR /&gt; Next update at : Thu Oct 12 02:00:39 2017&lt;BR /&gt; Source : &lt;A href="https://192.168.122.231/feeds/Domain-Output" target="_blank"&gt;https://192.168.122.231/feeds/Domain-Output&lt;/A&gt;&lt;BR /&gt; Referenced : Yes&lt;BR /&gt; Valid : Yes&lt;BR /&gt; Auth-Valid : Yes&lt;BR /&gt; Total invalid entries : 1&lt;BR /&gt; Valid domains:&lt;BR /&gt; Failed binding local connection end&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;All certificates are imported and nginx restarted....even CA certificate trusted in Firefox browser gives a cert error....&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please can anyone tell whats the issue?&lt;/P&gt;</description>
      <pubDate>Thu, 12 Oct 2017 08:58:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panos-8-0-0-edl-requires-certificate/m-p/181461#M96798</guid>
      <dc:creator>ausafali88</dc:creator>
      <dc:date>2017-10-12T08:58:36Z</dc:date>
    </item>
    <item>
      <title>Re: PANOS 8.0.0 EDL requires certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panos-8-0-0-edl-requires-certificate/m-p/229284#M96799</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11678"&gt;@lmori&lt;/a&gt;&amp;nbsp;what the apoarch for certificate profile in Pan-8.0 if you are using Minemeld hosted by the Autofocus. the problem in my case is the miners are working but the FW is not able to access those Dynamic list. is there any tech doc to regenerate&amp;nbsp; certificate on the Minemeld hosted on Autofocus.&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Sep 2018 19:52:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panos-8-0-0-edl-requires-certificate/m-p/229284#M96799</guid>
      <dc:creator>Sanssj</dc:creator>
      <dc:date>2018-09-03T19:52:56Z</dc:date>
    </item>
    <item>
      <title>Re: PANOS 8.0.0 EDL requires certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panos-8-0-0-edl-requires-certificate/m-p/229374#M96800</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/91991"&gt;@Sanssj&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;is the article &lt;A href="https://live.paloaltonetworks.com/t5/MineMeld-Articles/Connecting-PAN-OS-to-MineMeld-using-External-Dynamic-Lists/ta-p/190414" target="_self"&gt;https://live.paloaltonetworks.com/t5/MineMeld-Articles/Connecting-PAN-OS-to-MineMeld-using-External-Dynamic-Lists/ta-p/190414&lt;/A&gt; the documentation you're looking for?&lt;/P&gt;</description>
      <pubDate>Tue, 04 Sep 2018 10:29:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panos-8-0-0-edl-requires-certificate/m-p/229374#M96800</guid>
      <dc:creator>xhoms</dc:creator>
      <dc:date>2018-09-04T10:29:24Z</dc:date>
    </item>
    <item>
      <title>Re: PANOS 8.0.0 EDL requires certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panos-8-0-0-edl-requires-certificate/m-p/268488#M96801</link>
      <description>&lt;P&gt;I have done everything in this &lt;FONT size="3"&gt;feed and&lt;/FONT&gt; "&lt;FONT size="3"&gt;&lt;SPAN class="lia-link-navigation lia-link-disabled"&gt;How to Generate New MineMeld HTTPS Cert".&amp;nbsp; This is what I get:&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="3"&gt;&lt;SPAN class="lia-link-navigation lia-link-disabled"&gt;'EDL server certificate authentication failed. The associated external dynamic list has been removed, which might impact your policy. EDL Name: XXXXXXXXX, EDL Source URL: &lt;A href="https://XXXXXXXXXXX.com/feeds/inboundfeedhc" target="_blank"&gt;https://XXXXXXXXXXX.com/feeds/inboundfeedhc&lt;/A&gt;, CN: XXXXXXXXXX, Reason: SSL peer certificate or SSH remote key was not OK'&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="3"&gt;&lt;SPAN class="lia-link-navigation lia-link-disabled"&gt;I created a self-signed CA.&amp;nbsp; Created a certificate from that CA and imported it into my Minemeld server.&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jun 2019 20:55:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panos-8-0-0-edl-requires-certificate/m-p/268488#M96801</guid>
      <dc:creator>Todd_Benshoof</dc:creator>
      <dc:date>2019-06-10T20:55:52Z</dc:date>
    </item>
  </channel>
</rss>

