I need to delete a certificate from a PA-3050. The certificate is currently EXPIRED. When I try to delete it it says this message
1- Failed to delete Certificate - MYCOMPANYWildcard 2014-2017-FOR_DELETION.
° MYCOMPANY Wildcard 2014-2017-FOR_DELETION cannot be deleted because of references from:
° ssl-tls-service-profile -> MYCOMPANYWildcard 2014-2017-ssl-tls-service-profile -> certificate
In Device-Certificate Management-SSL/TLS Service Profile doesn't appear it. i download a copy of the current running config and it appear,
<entry name="MYCOMPANYWildcard 2014-2017-ssl-tls-service-profile">
but I don't know where could it be. Do anybody knows where could it be?
I also try to revoke it but appear this message "Certificate is not locally issued."
If you can see the certificate inside of Device > Certificate Management > Certificates
But you cannot delete it.. question.. if you can click on the certificate to get more information.. what is checked?
Also, inside of the CLI, you should be able to list out:
> show shared ssl-decrypt
it should show you all of your certificates who have some form or fashion of being associated with ssl-decrypt.
You can run this command from the CLI to get it removed:
> delete shared ssl-decrypt trusted-root-CA 123Test (where 123Test was the name of the cert in question)
There are the questions for your answer.
1. if you can click on the certificate to get more information.. what is checked?. There is nothing checked.
2. acuntia@FW2(active)# show shared ssl-decrypt
forward-untrust-certificate "Forward untrust";
3. I try to delete, option "shared" now appears but I have this output (see attachment"
In instances like this I would simply put a lock on the configuration, export the candidate-config.xml on the device and manually remove the certificate from the XML file. You can then import and load the configuration.
Also, if not stated before, any cert that you are trying to delete cannot be "in use" in the config, or you will not be able to delete it.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!