So, turns out that Thawte and a few others really do require a full csr for renewal. My mistake was creating the cert on the Palo Alto itself. Long story short, don't create an external cert that you plan to renew on the Palo Alto itself. I did find the original csr and did use it to create a new cert. Imported it over the old with the exact same name, but the commit failed due to key mismatch. = Don't create external certificates on the Palo Alto = I have installed openssl on a vm in order to create the cert from now on. I also documented the crap out of it since I will only do this every two years. Again, Don't create external certificates on the Palo Alto. In case you missed it, this was ridiculously over complicated. I finally found something to complain about with my Palo Alto. This would also explain why there is no documentation on this process at all.
... View more