is it possible to add a CA in PA device?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

is it possible to add a CA in PA device?

L3 Networker

Hello there.

I have a question related to CA for SSL client.

Customer has a certificate which issued by Trusted Root CA, but this trusted root CA is not contained in an ssl client's browser.

And then, the customer certificate was issued by this CA.

So, customer wants to distribute a CA of customer for all SSL VPN clients to avoid ssl certification error. (it was not created by a PA device.)

I tried to import to the CA at certificates in Device tab, but it  was impossible.

Is it possible to do it through PA device?

Please let me know someone who know about it.

Thanks,

Eugene.

4 REPLIES 4

L6 Presenter

There is a trusted CA list within the device but I cant find in the manuals on how to list its content nor how to add your own CA's to this list - perhaps somebody else in here who knows?

Regarding importing of stuff, if the web-gui fails you can use scp or tftp like so:

scp import certificate from user1@10.0.3.4:/tmp/certificatefile

tftp import ssl-certificate from user1@10.0.3.4:/tmp/certificatefile

Through the Webui -> Device -> Certificates .. that shows all of the certs there.

You can take public CA certs and import them with their Key files.

OR you can create local generated CA's,. or the actual SSL certs..

It honestly really depends on what you are trying to accomplish.

LIVEcommunity team member
Stay Secure,
Joe
Don't forget to Like items if a post is helpful to you!

I hope you mean the public key when you spoke about public CA certs because I seriously doubt they will or should release their private key 😉

Regarding that cert list I have completely missed that, in which version did that show up (and whats the CLI commands to list and modify it)?

Device -> Certificate Management -> Certificates -> Default Trusted Certificate Authorities (tab)

As of 4.1, we do not list the trusted certs that are used by PAN. The tab "Device -> Certificate Management -> Certificates -> Default Trusted Certificate Authorities" is an new feature added in 5.0.

To generate a cert through CLI:

request certificate generate <options>

To modify the cert:

set shared certificate <options>

  • 2718 Views
  • 4 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!