Lets Encrypt

L0 Member

Our customer is implementing the Lets Encrypt ( in the whole his infrastructure. 

This way, every certificates SSL expired in 90 days.

The Palo Alto use certificate SSL to VPN, Captive Portal, and others services.

Is there an automatic procedure of how to change these certificates? 

Has the Palo Alto API support for this kind of implementation?

If it is not possible via API, is there another way to do it? 

By script, for example.

Does any other customer already implement the Lets Encrypt with PA? 

Do you have any recommendation or best practices for use Lets Encrypt with Palo Alto?

The goal to avoid the manual process.


