Enhanced Security Measures in Place:   To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.

Device Certificate - Where to find OTP?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Device Certificate - Where to find OTP?

L4 Transporter

Under Device -> Setup -> Management -> Device Certificate, I am unable to fetch the device certificate.

 

A message box says get your one-time-password from the Customer Support Portal and enter it below.  I tried my 2-factor OTP that I use to login to the support portal, but that doesn't work.  How do I generate the OTP to get the device certificate?

 

I get the error: Failed to fetch device certificate.OTP is not valid

1 accepted solution

Accepted Solutions

L1 Bithead

There is an option to generate OTPs for registered devices in the Customer Support Portal.

Assets -> Device Certificates

View solution in original post

23 REPLIES 23

L1 Bithead

Same here after Panorama upgrade 9.1.1 -> 9.1.2.

Mine occurred after downloading renewed yearly subscriptions, or perhaps just the first time I noticed it.  I am on 9.0.8.

Running 9.1.2. Anyone know where to get the OTP? 

Not yet. I have a case running with our support partner about this.

L1 Bithead

There is an option to generate OTPs for registered devices in the Customer Support Portal.

Assets -> Device Certificates

Thanks. duh.. I should have seen that.

Thanks. 

Indeed, should've seen it...

 

Anyhow, my issue is fixed. 

Thank you!

Thanks, i did this and the new cert is good for 3 months.

Why is this necessary? I've never had the issue before v9.1.2.

Am I going to have to do this every 3 months from now on?

 

The option for provide a Device Certificate appears in a new section on the Device > Setup > Management page.

 

This option is part of an enhancement to the telemetry system and will be documented in the next major release of the software. As of today (2020 June 17), you need to be part of the 9.2 beta program to find this documented in the "New Features Guide". Since the feature does appear in the already released 9.1.2, I want to explain what it is here. 

 

By default, all telemetry data is collected and stored locally on your device for a limited period of time. Going forward, this data can not be shared with Palo Alto Networks unless your organization has a Cortex Data Lake license or a device certificate is configured for your firewall. 

 

So, why suddenly is there a Device Certificate option in PAN-OS 9.1.2? Ans: To support connections back to Palo Alto Networks to transfer telemetry data to the Data Lake.

 

Is a Device Certificate required? Will the operation of my firewall change if I do not supply one? Ans: The Device Certificate is required only to send telemetry data and if you are not already running Panorama and sending logs to the Cortex Data Lake. 

 

Telemetry options are configured on the Device > Setup > Telemetry page.

 

Hope this helps!

-dgn.

Thanks for the headsup.

@dgnewell 

 

Thank you the explanation.

 

Is there any ramifications when we enter OTP into the configuration page (eg, will we have to reboot the FW / will there be any downtime, etc)?

 

 

I didn't have any issues when I updated this.

After you enter the OTP, the task may take a minute or two to complete. You can/should monitor it in the Task Manager (click Tasks in the bottom right of the web interface). Download and installation of the certificate does not even require a commit. You should see no interruption of services or data flow. 

  • 1 accepted solution
  • 47550 Views
  • 23 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!