- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
08-03-2023 12:31 AM
08-03-2023 01:25 AM
Hi there,
A SSL certificated signed by well known CA (certificate authority) allows you to offer SSL encrypted services to people/ devices outside of your enterprise and for them to trust the validity and source of that connection. That is because your public key has been signed by the CA and the public keys of these CAs are distributed to operating systems, which in turn allows this chain to be trusted.
A self-signed SSL certificate comes from an 'untrusted' source and has not been signed by a trusted CA. You can create your own CA within your enterprise and use it to sign all your internal certificates, this is a valid approach. You should only really start using publicly signed certificates once you are offering services to devices which cannot easily download and install the public key from your own CA.
cheers,
Seb.
08-03-2023 01:38 AM
Thank you.
I will recommend my customer again. My customer need to know the Best Practice for used ssl certificate on PaloAlto.
Jita.
08-03-2023 01:44 AM
It depends on the services/ features your customer wants to use and whether they will be accessed by people outside of your enterprise.
Let us know these and we can work out the type of cert you'd use for each.
cheers,
Seb.
08-03-2023 01:57 AM
@seb_rupik Thank you.
We have outsource or vendor access GlobalProtech to our internal network. We need to know the best practice for used certificate VPN globalprotech for outsource or vendor.
For existing, the globalprotech used self-signed certificate that generate from PaloAlto NGFW for all user access global protech. We not sure it's enough for secure protechtion.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!