- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
Enhanced Security Measures in Place: To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.
01-19-2023 10:27 AM
Is there a way to generate alerts for certificates which are about to expire?
I mean, for certificates installed and used for example for GlobalProtect, SSL decrypt and etc...
01-19-2023 12:57 PM
Hello @g-crisostomo
there is a KB: https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000POWJCA4&lang=en_US%E2%80%A... with instructions how to enable certificate expiration check.
Unfortunately, I have a mixture of feelings about this feature. While I have not seen anybody complaining about this not being working properly, at least in my case it did not trigger any alert. After several month long TAC ticket, TAC engineer confirmed they could eventually reproduce it, but not planning to address this issue. It was flagged instead as an enhancement request instead of a bug.
Kind Regards
Pavel
01-19-2023 12:57 PM
Hello @g-crisostomo
there is a KB: https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000POWJCA4&lang=en_US%E2%80%A... with instructions how to enable certificate expiration check.
Unfortunately, I have a mixture of feelings about this feature. While I have not seen anybody complaining about this not being working properly, at least in my case it did not trigger any alert. After several month long TAC ticket, TAC engineer confirmed they could eventually reproduce it, but not planning to address this issue. It was flagged instead as an enhancement request instead of a bug.
Kind Regards
Pavel
02-23-2023 05:55 AM
Yeah, I checked and there's no way to the verify the expiration of certificates imported on firewall.
Thanks for the help.
08-23-2024 01:54 PM
The "Certificate expiration check" is specifically to check the expiration of the device certificate. It will not generate a warning message for any other certificate except the device certificate for the firewall or Panorama.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!