SSL Certificates import

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

SSL Certificates import

L3 Networker

Hi All,

 

I need to import some SSL certificates for a Global Protect instance. Customer has already supplied me with their wildcard certificates which I have imported but I cannot select them when creating an SSL/TLS Service Profile. Can I set up this way or should I generate the CSR from the firewall and get the certificates created for me?

 

Regards

 

Adrian

1 accepted solution

Accepted Solutions

Hi @a.jones,

 

When creating SSL/TLS profile, firewall will not allow you to select ceritificate that doesn't have private key imported - it wouldn't show up in the dropdown list.

 

So I am guessing that your customer have provide you only the public key - the certificate, but didn't send you the private key for it.

You can confirm that by  checking the uploaded certificate via the GUI. Go to Device -> Ceritificate Management -> Certificates and see if the certificate have a check for key

 

image.png

 

If that is correct you have two options:

- Request again from user to send you PKCS 12 (.p12) which is combination of both private and public key

- Generate a CSR and send it to the customer to sign it.

 

As you mentioned that your customer is using wildcard certificate I believe that your prefferable option will be the first one. Because creating CSR will meand that customer will need to re-issue their wildcard ceritifcate.

View solution in original post

2 REPLIES 2

Hi @a.jones,

 

When creating SSL/TLS profile, firewall will not allow you to select ceritificate that doesn't have private key imported - it wouldn't show up in the dropdown list.

 

So I am guessing that your customer have provide you only the public key - the certificate, but didn't send you the private key for it.

You can confirm that by  checking the uploaded certificate via the GUI. Go to Device -> Ceritificate Management -> Certificates and see if the certificate have a check for key

 

image.png

 

If that is correct you have two options:

- Request again from user to send you PKCS 12 (.p12) which is combination of both private and public key

- Generate a CSR and send it to the customer to sign it.

 

As you mentioned that your customer is using wildcard certificate I believe that your prefferable option will be the first one. Because creating CSR will meand that customer will need to re-issue their wildcard ceritifcate.

Thanks. As I posted this originally I was chasing the customer for a private key. It has taken two weeks to get but the solution now works. Thanks for the info.

  • 1 accepted solution
  • 3180 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!