I ran into the same issue. Seems to be a design issue depending on your device group hierarchy. In my case my firewalls are in a DG under an organizational DG. For example shared > datacenter firewalls > data center A. The issue is that I am managing security policy in the " datacenter firewalls" DG, which doesn't have any devices assigned to it - this is the issue. But I'm not able to create an EDL in the "datacenter firewalls" DG and reference a cert file from the template. I hope Palo dev fixes this.
... View more