- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
Enhanced Security Measures in Place: To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.
06-09-2021 12:02 PM
Hello,
my current GlobalProtect portal/gateway certificate is expiring soon so I had our 3rd party CA create a new one with the same name. In Panorama under templates/device/certificates, I uploaded the new cert with a temporary name (ex. expiring cert name is foobar.net so I uploaded the new cert as new_foobar.net). Now I want to delete the expiring foobar.net and rename new_foobar.net to foobar.net. If I don't name it the same, I'll have to find everywhere it is referenced and change it multiple times. The problem is that when I go to delete the expiring cert, I get the familiar "foobar.net cannot be deleted because of references from: ..."
Anyone know a way to get around this?
Thanks,
06-12-2021 01:14 PM
Hi @Joni_Larned ,
This is the whole purpose of "SSL/TLS Service Profile".
- You select a certificate in the service profile and use this profile everywher you need.
- When you need to renew/change the certificate you change it only in the service profile, which apply to all locations where this profile is being used.
In addition - you cannot refrence certificate anywhere except ssl/tls service profile. So you don't have to worrie that you need to change the certificate anywhere else.
So what you need to do is:
- Find the ssl/tls service profile which is using the certificate that needs to be replaced
- Edit it and select from the dropdown your new certificate
- Commit and push config
- You should be able to old ceritifcate now
- (optional) now you can renew your new cert (removing "new_") name. This should automaticaly reflect in the service profile, but you can go and doublecheck if profile is using the update name. Commit and push to have it on the FW.
06-12-2021 01:14 PM
Hi @Joni_Larned ,
This is the whole purpose of "SSL/TLS Service Profile".
- You select a certificate in the service profile and use this profile everywher you need.
- When you need to renew/change the certificate you change it only in the service profile, which apply to all locations where this profile is being used.
In addition - you cannot refrence certificate anywhere except ssl/tls service profile. So you don't have to worrie that you need to change the certificate anywhere else.
So what you need to do is:
- Find the ssl/tls service profile which is using the certificate that needs to be replaced
- Edit it and select from the dropdown your new certificate
- Commit and push config
- You should be able to old ceritifcate now
- (optional) now you can renew your new cert (removing "new_") name. This should automaticaly reflect in the service profile, but you can go and doublecheck if profile is using the update name. Commit and push to have it on the FW.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!