I found the solution, i see 6 registry key are created in HKLM/SOFTWARE\Palo Alto Networks\TS Agent\Conf :
And TSAgentSSL, that the key used to add the password certificate.
I get the value for the key TSAgentSSL with Process Monitor application.
This registry key is deleted when the service boot. that's why i doesn't see this key before.
I add the creation of this registry key in the script and the service is booting now
... View more