- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
08-01-2023 09:27 AM
@Adrian_Jensen wrote:
I do not have Panorama, and as such I always generated CSRs on the local firewall, but it is my understanding you can also do it from Panorama (I suspect its Panorama instructing the local firewall to generate the cert and then downloading the CSR).
From what I have seen, Panorama generates the private key and pushes it to the firewall as part of the template. And likewise, it will push the signed cert to the firewall. Doesn't matter if you push private key / CSR to the firewall before importing the signed cert or after.
The certs/keys are like any other template settings...just that they happen to be a few hundred characters of randomness instead of other typical settings that are short legible strings.