- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
Content translations are temporarily unavailable due to site maintenance. We apologize for any inconvenience. Visit our blog to learn more.
07-13-2020 07:25 PM
Hi Team,
We are using self signed certificate for user authentication signed by self-signed CA cert on Palo Alto for our global protect.
does my understanding below is correct regarding certificate expiration/renewal.
1. if CA cert expired while user cert still valid, user does not need to install renewed CA cert.
we can renew the CA cert on palo alto and user will be able to connect to global protect again.
2. If we renew user certificate (i.e user cert is still valid and we renew for 1 year), user will need to install new renewed certificate.
Thanks
07-14-2020 01:26 PM
Hey @L1_ENG I hope all is well!
1. If the CA certificate used to sign any intermediate or leaf certificate expires, then each subordinate child ticket will be invalidated also. This is true regardless of the certificate being self-signed form the firewall itself or imported from an internal PKI.
2. If the CA certificate is generated on the firewall, and is renewed on the firewall prior to expiring, then it doesn't require being redeployed to the endpoints, as it will automatically be updated.
I hope this helps with your questions!
-Stay safe and have a great day!
07-14-2020 01:26 PM
Hey @L1_ENG I hope all is well!
1. If the CA certificate used to sign any intermediate or leaf certificate expires, then each subordinate child ticket will be invalidated also. This is true regardless of the certificate being self-signed form the firewall itself or imported from an internal PKI.
2. If the CA certificate is generated on the firewall, and is renewed on the firewall prior to expiring, then it doesn't require being redeployed to the endpoints, as it will automatically be updated.
I hope this helps with your questions!
-Stay safe and have a great day!
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!