Cert Delete and Created new devicecert

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Cert Delete and Created new devicecert

L4 Transporter

Anyone run into this?

We discovered around 0400 AM (outside business hours so no admins online) the following logs generated. They appear system generated as if the device is regenerating a cert. Problem is, it doesn't match the dates on the device certificate that is normally generated under the device tab and PAN has zero documentation to tell us if this is normal behavior.

logs-cert.jpg

 

1 accepted solution

Accepted Solutions

L4 Transporter

We contacted TAC to get clarity on this issue and here is the answer received:

This is a new feature in 10.1.

The firewall certificate is valid for 3 Months.


2 Weeks prior to expiration, the firewall will:
     -Create a new CSR and send this to panorama for signing
     -Panorama will sign this CSR and return, signed cert, device CA cert, SNI to use for this new certificate
     -Switches the connection to new Cert on the next connect

View solution in original post

3 REPLIES 3

Cyber Elite
Cyber Elite

Hello, this is normal to see a device cert get regenerated. It will do this every 90 days more or less.

 

SteveCantwell_0-1662676926758.png

 

Help the community: Like helpful comments and mark solutions

L4 Transporter

We contacted TAC to get clarity on this issue and here is the answer received:

This is a new feature in 10.1.

The firewall certificate is valid for 3 Months.


2 Weeks prior to expiration, the firewall will:
     -Create a new CSR and send this to panorama for signing
     -Panorama will sign this CSR and return, signed cert, device CA cert, SNI to use for this new certificate
     -Switches the connection to new Cert on the next connect

L2 Linker

We're noticing similar issue on Panorama where there is no certificate creation however getting the high severity alert on the cert delete.

 

is there anyway to stop this high severity cert delete alert?

 

  • 1 accepted solution
  • 2658 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!