08-25-2019 11:45 PM
I got an issue to update a cert on PA pair.
The issue is very similar to what it describes under
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CldECAS
I import the new cert to both PA FW units and change config to use the new cert. However it comes with config out-of-sync issue and somehow the new cert on passive unit is removed after committing config.
any fix for the issue?