How to Renew or Replace an Expired Certificate

How to Renew or Replace an Expired Certificate

104528
Created On 08/09/22 20:08 PM - Last Modified 08/23/23 18:50 PM


Objective


Renewing or replacing an expired certificate.

Environment


  • PAN-OS
  • Certificates/PKI


Procedure


  1. Renew or replace the certificate based on its type:
    1. If the expired certificate is under Device > Certificates then:
  1. If the certificate is signed by the firewall acting as a CA, then use:
  1. If the certificate is signed by an external/third-party CA, then use:
  1. If the certificate is a CA Certificate, then use:
Tip: to view these certificates, use the CLI command below:
> request certificate show
  1. If the expired certificate is the Device Certificate, navigate to Device > Setup > Management > Device Certificate and perform the below steps:
> show device-certificate status
Note: The Device Certificate is used to securely connect to and leverage Palo Alto Networks cloud services for features such as Device Telemetry, IoT Security , and Strata Cloud Manager (AIOps for NGFW) if you choose to use them (more details here)
  1. If the expired certificate is the Logging Service Certificate, navigate to Device > Setup > Management > Logging Service (Cortex Data Lake) and perform the below steps:
> request logging-service-forwarding status


Additional Information


Additional Information:
Renew a Certificate
Obtain a Certificate from an External CA

Install a Device Certificate
How to Install a Device Certificate
Impact and Meaning of System Logs showing "No Valid Device Certificate Found"

Start Sending Logs to Cortex Data Lake 
Verifying Cortex Data Lake Connectivity On A Palo Alto Firewall
Troubleshooting Firewall Connectivity Issues With Logging Service
How To Troubleshoot Connection Failure To Cortex Data Lake (CDL)

Tip: One way to find out which certificate(s) are currently in use (and by which configured software features) is by searching the Global Find  (top-right search box in PAN-OS Web UI) using the name of certificate. The result of the search will list either the SSL/TLS Service Profile or the Certificate Profile where this certificate is used. You can then use the name of those to continue your search. For certificates used for decryption you will see under Device > Certificates > Device certificates that the usage is showing Forward Trust CertificateForward Untrust Certificate.



Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000wlGRCAY&lang=en_US%E2%80%A9&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language