Best Practice for Managing Short-Lived Public Certificates on Panorama-Managed Firewalls?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Best Practice for Managing Short-Lived Public Certificates on Panorama-Managed Firewalls?

L0 Member

Hi everyone,

With the industry moving toward shorter validity periods for publicly issued SSL/TLS certificates, I'm trying to plan ahead for certificate management on our Palo Alto firewalls.

We have several firewalls that are managed through Panorama, and some of them will also be using SAML for authentication. Since public certificates will need to be renewed more frequently, I'm looking for the most efficient way to handle the certificate replacement process across multiple devices.

I've come across a few discussions describing different methods, but many of them are older or use different deployment scenarios. Before implementing anything, I'd like to hear how others are approaching this today.

A few questions I have:

  1. What is the current best practice for updating certificates on Panorama-managed firewalls?

  2. Are you automating certificate deployment and renewal? If so, what tools or workflows are you using?

  3. For SAML integrations, are there any considerations or common pitfalls when replacing certificates regularly?

  4. Has anyone successfully integrated ACME or another automated certificate management solution with PAN-OS?

I'd appreciate hearing about real-world experiences and any recommendations that have helped reduce the operational overhead.

Thanks in advance!

0 REPLIES 0
  • 25 Views
  • 0 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!