- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
01-23-2023 04:18 PM
I have forward ssl decrypt running and I want to change the cert I use. Can only have one forward trust cert at a time. If I deselect forward trust box I get commit error because my ssl decrypt policies don't have a forward trust cert. I can't select forward trust on the new cert until the old cert has forward trust deselected.
So now what do I do? Thanks.
01-24-2023 04:38 PM
Do you have private key for it?
Following two screenshots are sample that shows what happens if you did not import private key ( looks same as your result):
01-24-2023 06:08 PM
No priv. key. We are making a new cert from our CA and including keys so we can d/l the cert and key. We just have to figure the flavor of cert (usage etc). We made the current one so we should be able to make a new one. Thanks for the tip on needing the priv key to qual for Forward trust.
01-23-2023 04:42 PM
You don't need to "deselect and commit".
Just change cert and commit will work (at least worked on my lab / pan-os 10.1.6-h6)
01-24-2023 02:12 PM
Thanks for response. I am not able to select Forward Trust Cert option.
The new cert is the Issuing CA Trusted Root chained from the Root CA if this makes ant sense.
01-24-2023 04:38 PM
Do you have private key for it?
Following two screenshots are sample that shows what happens if you did not import private key ( looks same as your result):
01-24-2023 06:08 PM
No priv. key. We are making a new cert from our CA and including keys so we can d/l the cert and key. We just have to figure the flavor of cert (usage etc). We made the current one so we should be able to make a new one. Thanks for the tip on needing the priv key to qual for Forward trust.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!