Failed to delete Certificate due to references - but I don't want to delete those references

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Failed to delete Certificate due to references - but I don't want to delete those references

L0 Member

Hello,

my current GlobalProtect portal/gateway certificate is expiring soon so I had our 3rd party CA create a new one with the same name.  In Panorama under templates/device/certificates, I uploaded the new cert with a temporary name (ex. expiring cert name is foobar.net so I uploaded the new cert as new_foobar.net).  Now I want to delete the expiring foobar.net and rename new_foobar.net to foobar.net.  If I don't name it the same, I'll have to find everywhere it is referenced and change it multiple times.  The problem is that when I go to delete the expiring cert, I get the familiar "foobar.net cannot be deleted because of references from: ..."

Anyone know a way to get around this?

Thanks,

 

1 accepted solution

Accepted Solutions

Hi @Joni_Larned ,

 

This is the whole purpose of "SSL/TLS Service Profile".

-  You select a certificate in the service profile and use this profile everywher you need.

- When you need to renew/change the certificate you change it only in the service profile, which apply to all locations where this profile is being used.

 

In addition - you cannot refrence certificate anywhere except ssl/tls service profile. So you don't have to worrie that you need to change the certificate anywhere else.

 

So what you need to do is:

- Find the ssl/tls service profile which is using the certificate that needs to be replaced

- Edit it and select from the dropdown your new certificate

- Commit and push config

- You should be able to old ceritifcate now

- (optional) now you can renew your new cert (removing "new_") name. This should automaticaly reflect in the service profile, but you can go and doublecheck if profile is using the update name. Commit and push to have it on the FW.

View solution in original post

1 REPLY 1

Hi @Joni_Larned ,

 

This is the whole purpose of "SSL/TLS Service Profile".

-  You select a certificate in the service profile and use this profile everywher you need.

- When you need to renew/change the certificate you change it only in the service profile, which apply to all locations where this profile is being used.

 

In addition - you cannot refrence certificate anywhere except ssl/tls service profile. So you don't have to worrie that you need to change the certificate anywhere else.

 

So what you need to do is:

- Find the ssl/tls service profile which is using the certificate that needs to be replaced

- Edit it and select from the dropdown your new certificate

- Commit and push config

- You should be able to old ceritifcate now

- (optional) now you can renew your new cert (removing "new_") name. This should automaticaly reflect in the service profile, but you can go and doublecheck if profile is using the update name. Commit and push to have it on the FW.

  • 1 accepted solution
  • 3458 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!