Enhanced Security Measures in Place:   To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.

Certification expiration alert

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Certification expiration alert

L2 Linker

Is there a way to generate alerts for certificates which are about to expire?

I mean, for certificates installed and used for example for GlobalProtect, SSL decrypt and etc...

1 accepted solution

Accepted Solutions

Cyber Elite
Cyber Elite

Hello @g-crisostomo

 

there is a KB: https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000POWJCA4&lang=en_US%E2%80%A... with instructions how to enable certificate expiration check.

 

Unfortunately, I have a mixture of feelings about this feature. While I have not seen anybody complaining about this not being working properly, at least in my case it did not trigger any alert. After several month long TAC ticket, TAC engineer confirmed they could eventually reproduce it, but not planning to address this issue. It was flagged instead as an enhancement request instead of a bug.

 

Kind Regards

Pavel

Help the community: Like helpful comments and mark solutions.

View solution in original post

3 REPLIES 3

Cyber Elite
Cyber Elite

Hello @g-crisostomo

 

there is a KB: https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000POWJCA4&lang=en_US%E2%80%A... with instructions how to enable certificate expiration check.

 

Unfortunately, I have a mixture of feelings about this feature. While I have not seen anybody complaining about this not being working properly, at least in my case it did not trigger any alert. After several month long TAC ticket, TAC engineer confirmed they could eventually reproduce it, but not planning to address this issue. It was flagged instead as an enhancement request instead of a bug.

 

Kind Regards

Pavel

Help the community: Like helpful comments and mark solutions.

L2 Linker

Yeah, I checked and there's no way to the verify the expiration of certificates imported on firewall.

Thanks for the help.

The "Certificate expiration check" is specifically to check the expiration of the device certificate. It will not generate a warning message for any other certificate except the device certificate for the firewall or Panorama. 

 

  • 1 accepted solution
  • 4855 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!