Export "SSL VPN/SSL INBOUND Inspection Certificate" in PAN-OS 3.0.6

Showing results for 
Show  only  | Search instead for 
Did you mean: 

Export "SSL VPN/SSL INBOUND Inspection Certificate" in PAN-OS 3.0.6

L0 Member


I can't find in PAN-OS 3.0.6 solution to export CERTIFICATE.

I tried WEB-admin and CLI but without solution :

scp export
> application                  Use scp to export application packet capture
> application-block-page       Use scp to export application block comfort page
> captive-portal-text          Use scp to export captive portal text
> configuration                Use scp to export configuration
> core-file                    Use scp to export core-file
> crl                          Use scp to export crl.tgz
> debug-pcap                   Use scp to export packet capture generated for purpose of debugging daemons
> file-block-page              Use scp to export file block comfort page
> filter                       Use scp to export filter
> log                          Use scp to export log in csv format
> log-file                     Use scp to export log-file
> logdb                        Use scp to export logdb
> packet-log                   Use scp to export packet-log
> pdf-reports                  Use scp to export PDF reports
> spyware-block-page           Use scp to export spyware block comfort page
> ssl-cert-status-page         Use scp to export SSL cert status page
> ssl-decryption-certificate   Use scp to export ssl-decryption-certificate
> ssl-optout-text              Use scp to export ssl optout text
> stats-dump                   Use scp to export logdb in csv format
> tech-support                 Use scp to export tech support info
> url-block-page               Use scp to export url block comfort page
> url-coach-text               Use scp to export url coach text
> virus-block-page             Use scp to export virus block comfort page
> web-interface-certificate    Use scp to export web-interface-certificate

Thx a lot four your reply.


L4 Transporter


currently there is not option to do this on 3.0.x or 3.1.x.

You can of course submit an enhancement request with your sales contact.



L4 Transporter

Why do you want to export the inbound inspection certificate? By definition, this certificate had to be held by the admin and imported previously as it needs to be the same certificate that is on the destination web server.



I want to export the certificate beacause the certificate was generated through web interface.

And now I want to upgrade paloalto firmware on PA-500. This PA and our NFR-PA was bought at the same time, but no luck, our PA did not support Upgrade to 3.1.0 (cf. RMA), so I don want to crach my client PA.

So I want to prepare a spare of the PA-500, SO I have to export certificate.


Inbound inspection certificates cannot be generated via the web interface. They are always imported. Other certificates that are generated by the device are able to be exported via the commands above.


Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!