Need to known what about difference between a self-signed certificate and purchased certificate.

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Need to known what about difference between a self-signed certificate and purchased certificate.

L1 Bithead
I need to know what about the difference between a self-signed certificate that generate from PaloAlto NGFW and external purchased certificate (import to PaloAlto NGFW).  
 
Please help explain about the difference.
 
 
#SSL_Certificate
Jita.O
4 REPLIES 4

L4 Transporter

Hi there,

A SSL certificated signed by well known CA (certificate authority) allows you to offer SSL encrypted services to people/ devices outside of your enterprise and for them to trust the validity and source of that connection. That is because your public key has been signed by the CA and the public keys of these CAs are distributed to operating systems, which in turn allows this chain to be trusted.

 

A self-signed SSL certificate comes from an 'untrusted' source and has not been signed by a trusted CA. You can create your own CA within your enterprise and use it to sign all your internal certificates, this is a valid approach. You should only really start using publicly signed certificates once you are offering services to devices which cannot easily download and install the public key from your own CA.

 

cheers,

Seb.

L1 Bithead

@seb_rupik  

Thank you.

I will recommend my customer again. My customer need to know the Best Practice for used ssl certificate on PaloAlto.

 

 

Jita.

Jita.O

L4 Transporter

It depends on the services/ features your customer wants to use and whether they will be accessed by people outside of your enterprise.

Let us know these and we can work out the type of cert you'd use for each.

 

cheers,

Seb.

L1 Bithead

@seb_rupik  Thank you.

We have outsource or vendor access GlobalProtech to our internal network. We need to know the best practice for used certificate VPN globalprotech for outsource or vendor.

For existing, the globalprotech used self-signed certificate that generate from PaloAlto NGFW for all user access global protech. We not sure it's enough for secure protechtion. 

Jita.O
  • 1545 Views
  • 4 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!