To verify if you have already set up a master key, run the >show system masterkey-properties command.
For example:
> show system masterkey-properties
Master key expires at: unspecified
Reminders will begin at: unspecified
Master key on hsm: no
The output above indicates that no master key was created.
To create a new master key, run the following command:
> request master-key new-master-key <new_key_value> lifetime <lifetime_value>
-
- The new master key should be a 64-bit encoded public key
- The lifetime value is in hours (1-17520)
For example:
> request master-key new-master-key paloalto12345678 lifetime 1
Master key changed successfully. All key material has been re-encrpyted with
new master key and committed via jobid 12
Note: Once the master key is created, the Palo Alto Networks firewall will auto-commit. Prior to creating a new master key, make sure there is no changes pending to commit. Otherwise, the firewall will display the following error message:
Server error : There are uncommitted changes. Please commit all pending changes and try
again.
Running the show system masterkey-properties will now show information on the new master key:
> show system master key-properties
Master key expires at: 2015/01/22 16:44:43
Reminders will begin at: 2015/01/15 16:44:43
Master key on hsm: no