When renewing a certificate that was generated by PANOS the SANs are lost
9925
Created On 02/26/20 22:08 PM - Last Modified 07/10/20 18:27 PM
Symptom
- SANs field disappear from the field of a renewed cert on the PANOS device although the original cert had the SANs field populated
Environment
- PAN-OS
- Certificate with SAN
Cause
The root cause is the system limitation due to openssl not supporting SAN when renewing certificate.
Resolution
To renew a cert, generated on the firewall, which has the SAN field you need to:
1- Generate a new similar cert.