SCM GP User Certificate Renewal Process

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

SCM GP User Certificate Renewal Process

L1 Bithead
The below are the steps to renew GP certificate for Prisma Access on Strata Cloud Manager
 
*Note in this example we are using Azure as the IDP
 
  1. Make sure to delete the old certificate on the Azure SAML IdP side
  2. Then export the new SAML metadata XML file (which has only the new certificate) from Azure IdP
  3. In Strata Cloud Manager(SCM), navigate to Manage > Configurations > NGFW & Prisma Access > Identity Services > Authentication > Server Profiles > SAML, open the existing SAML profile which you use and click on "Import"  under Identity Provider Certificate, to import the new metadata XML file to the SCM console. Now save the SAML profile.
  4. After that, navigate to Objects > Certificate Management to verify and confirm that the Azure SAML IdP certificate is automatically renewed.
  5. Now do an 'all-admin' push to the Mobile Users template to ensure the update is propagated to the Prisma Access backend nodes
(Note: All-admin push is needed, as it will show the changes done by 'System' since the new SAML certificate is extracted from the recently imported XML file)
0 REPLIES 0
  • 211 Views
  • 0 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!