- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
08-09-2019 01:58 AM
Hi All,
I need to import some SSL certificates for a Global Protect instance. Customer has already supplied me with their wildcard certificates which I have imported but I cannot select them when creating an SSL/TLS Service Profile. Can I set up this way or should I generate the CSR from the firewall and get the certificates created for me?
Regards
Adrian
08-12-2019 02:05 AM - edited 08-12-2019 02:12 AM
Hi @a.jones,
When creating SSL/TLS profile, firewall will not allow you to select ceritificate that doesn't have private key imported - it wouldn't show up in the dropdown list.
So I am guessing that your customer have provide you only the public key - the certificate, but didn't send you the private key for it.
You can confirm that by checking the uploaded certificate via the GUI. Go to Device -> Ceritificate Management -> Certificates and see if the certificate have a check for key
If that is correct you have two options:
- Request again from user to send you PKCS 12 (.p12) which is combination of both private and public key
- Generate a CSR and send it to the customer to sign it.
As you mentioned that your customer is using wildcard certificate I believe that your prefferable option will be the first one. Because creating CSR will meand that customer will need to re-issue their wildcard ceritifcate.
08-12-2019 02:05 AM - edited 08-12-2019 02:12 AM
Hi @a.jones,
When creating SSL/TLS profile, firewall will not allow you to select ceritificate that doesn't have private key imported - it wouldn't show up in the dropdown list.
So I am guessing that your customer have provide you only the public key - the certificate, but didn't send you the private key for it.
You can confirm that by checking the uploaded certificate via the GUI. Go to Device -> Ceritificate Management -> Certificates and see if the certificate have a check for key
If that is correct you have two options:
- Request again from user to send you PKCS 12 (.p12) which is combination of both private and public key
- Generate a CSR and send it to the customer to sign it.
As you mentioned that your customer is using wildcard certificate I believe that your prefferable option will be the first one. Because creating CSR will meand that customer will need to re-issue their wildcard ceritifcate.
08-20-2019 02:13 AM
Thanks. As I posted this originally I was chasing the customer for a private key. It has taken two weeks to get but the solution now works. Thanks for the info.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!