Change forward decrypt trust cert to a new one.

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Palo Alto Networks Approved
Palo Alto Networks Approved
Community Expert Verified
Community Expert Verified

Change forward decrypt trust cert to a new one.

L1 Bithead

I have forward ssl decrypt running and I want to change the cert I use. Can only have one forward trust cert at a time. If I deselect forward trust box I get commit error because my ssl decrypt policies don't have a forward trust cert. I can't select forward trust on the new cert until the old cert has forward trust deselected.

So now what do I do? Thanks.

2 ACCEPTED SOLUTIONS

Accepted Solutions

L5 Sessionator

Do you have private key for it?

Following two screenshots are sample that shows what happens if you did not import private key ( looks same as your result):

 

Image 001.png

Image 002.png

 

View solution in original post

L1 Bithead

No priv. key. We are making a new cert from our CA and including keys so we can d/l the cert and key. We just have to figure the flavor of cert (usage etc). We made the current one so we should be able to make a new one. Thanks for the tip on needing the priv key to qual for Forward trust.

View solution in original post

4 REPLIES 4

L5 Sessionator

You don't need to "deselect and commit".

Just change cert and commit will work (at least worked on my lab / pan-os 10.1.6-h6)

Image 001.png

Thanks for response. I am not able to select Forward Trust Cert option.

djon_0-1674597524676.png

The new cert is the Issuing CA Trusted Root chained from the Root CA if this makes ant sense.

L5 Sessionator

Do you have private key for it?

Following two screenshots are sample that shows what happens if you did not import private key ( looks same as your result):

 

Image 001.png

Image 002.png

 

L1 Bithead

No priv. key. We are making a new cert from our CA and including keys so we can d/l the cert and key. We just have to figure the flavor of cert (usage etc). We made the current one so we should be able to make a new one. Thanks for the tip on needing the priv key to qual for Forward trust.

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!