When renewing a certificate that was generated by PANOS the SANs are lost

When renewing a certificate that was generated by PANOS the SANs are lost

7004
Created On 02/26/20 22:08 PM - Last Modified 07/10/20 18:27 PM


Symptom


  • SANs field disappear from the field of a renewed cert on the PANOS device although the original cert had the SANs field populated

 


Environment


  • PAN-OS
  • Certificate with SAN


Cause


The root cause is the system limitation due to openssl not supporting SAN when renewing certificate.

Resolution


To renew a cert, generated on the firewall, which has the SAN field you need to:
1- Generate a new similar cert.


Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000POqOCAW&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language