- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
on 03-09-2022 09:16 AM - edited on 07-11-2022 11:31 PM by jennaqualls
The certificates and the chain used for GlobalProtect App Log Collection and ADEM are expiring as of June 3, 2022. Please be sure to update the certificates for GlobalProtect App Log Collection and ADEM after April 20, 2022 and before June 3, 2022, when the certificate expires. Read the steps below to renew the certificate used for GlobalProtect App Log Collection and ADEM now. 
Steps to renew the certificate used for GlobalProtect App Log Collection and ADEM:
If you are using Cloud Managed Prisma Access performing the following steps:
Note: Customers are advised to renew the certificate only after April 20 2022 and before June 3 2022 when the certificate expires. If certificate renewal is performed before April 20 2022 then you will still get the old certificate which is due to expire on June 3 2022.
You say "If you are using Panorama to manage Prisma Access and NGFW"
So it makes me think it applies to me because I manage my NGFW's with Panorama however I do not use Prisma Access. You should state in BOLD if you are not using Prisma Access this does not apply to your organization.
Please correct me if I am wrong.
Hello,
Similar situation to Jasonwald's question above... We do not use Panorama or Prisma with our firewalls, so does this not apply to us at all? We do use GlobalProtect, but I'm not seeing any certs related to that in the system.
Thank you!
Is this related to only those that are pointing their global protect clients to Prima ADEM service? https://www.paloaltonetworks.com/sase/adem
Exactly - what about clients that have deployed Global Protect on physical or VM FW's but are not using Panorama or Prisma.
Lurking here to get confirmation this is not an issue for physical firewalls....
GlobalProtect
Hello everyone,
The GlobalProtect App Log Collection feature is available for both NGFW GP Subscription and Prisma Access Customers.
NGFW GP Subscription based customer require Panorama with the Cloud Plug-in and a CDL License to use this feature. More details are available in the tech docs at: https://docs.paloaltonetworks.com/globalprotect/5-2/globalprotect-app-new-features/new-features-rele...
If your customer does not use the GP App Log Collection feature or ADEM, this article will not be applicable to them.
Hello,
After clicking "Renew Certificate for GlobalProtect App Log Collection and Autonomous DEM" I get a message saying that the cert was successfully renewed. However, after I click OK, I can see that the ADEM cert is still slated to expire on 6/4/2022.
I was having this issue as well.
Today, I modified all my portal configs, removing this cert, then exported the cert with private key, just incase.
Next, I deleted the cert. After deleting I performed a commit-push, after push completed, I clicked the option "Renew Certificate...." from the Cloud Services plugin. This time, it generated a new cert with an expiration of:
May 31 15:15:10 2023 GMT
Now I am reconfiguring my portal agent configs to push that cert.
Hope this heps!