- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
07-20-2026 05:22 AM
Hi everyone,
With the industry moving toward shorter validity periods for publicly issued SSL/TLS certificates, I'm trying to plan ahead for certificate management on our Palo Alto firewalls.
We have several firewalls that are managed through Panorama, and some of them will also be using SAML for authentication. Since public certificates will need to be renewed more frequently, I'm looking for the most efficient way to handle the certificate replacement process across multiple devices.
I've come across a few discussions describing different methods, but many of them are older or use different deployment scenarios. Before implementing anything, I'd like to hear how others are approaching this today.
A few questions I have:
What is the current best practice for updating certificates on Panorama-managed firewalls?
Are you automating certificate deployment and renewal? If so, what tools or workflows are you using?
For SAML integrations, are there any considerations or common pitfalls when replacing certificates regularly?
Has anyone successfully integrated ACME or another automated certificate management solution with PAN-OS?
I'd appreciate hearing about real-world experiences and any recommendations that have helped reduce the operational overhead.
Thanks in advance!
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!

