Panorama reset Authentication Profile (Certificate Profile based Authentication) via CLI

Reply
L0 Member

Panorama reset Authentication Profile (Certificate Profile based Authentication) via CLI

Hi,

 

I have configured (on a test Panorama VM - luckly not on the production one) a SSL Certificate Based authentication following the steps provided on the Panorama Administrator's Guide; somehow It didn't quite worked out and I'm currently locked out.


I do have admin access to the Panorama VM via CLI -> is there any chance to reset the GUI authentication profile to username and password (its default) ? thanks

Tags (2)
L3 Networker

Re: Panorama reset Authentication Profile (Certificate Profile based Authentication) via CLI

If you have access to CLI, create a new authentication-profile using the set authentication-profile command.

Then, assign the authentication profile to the user you want to login with using set mgt-config users *username* authenticaton-profile command


*Please like or mark as solution if the answer is helpful!*
L0 Member

Re: Panorama reset Authentication Profile (Certificate Profile based Authentication) via CLI

Hi,

 

thank you for the feedback but this is not really what I'm after.

 

I would like to enable

 

https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/firewall-administration/manage-firewall-ad...

 

However at the very beginning of the Web Page I can read:

 

"Configuring certificate-based authentication for any administrator disables the username/password logins for all administrators on the firewall; administrators thereafter require the certificate to log in."

 

I would like to know if there is any possibility to reset the "Certificate-Based Administrator Authentication to the Web Interface" via cli should something go wrong ...

 

Is this technically possible / supported ?

 

Thank you fro your feedback.

 

 

 

L3 Networker

Re: Panorama reset Authentication Profile (Certificate Profile based Authentication) via CLI

Have you tried just deleting the certificate-profile you created with "delete panorama certificate-profile" command?


*Please like or mark as solution if the answer is helpful!*
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!