How to identify and re-onboard Dedicated Log Collectors that are using legacy certificates prior to 11.1 upgrade
3147
Created On 06/05/25 14:58 PM - Last Modified 07/11/25 19:54 PM
Objective
To identify Dedicated Log Collectors that are using legacy certificates for Panorama communication and re-onboard them.
This is a pre-requisite for upgrading Panorama and Log Collectors to PAN-OS 11.1 and above.
- Identify Dedicated log collectors that were onboarded to Panorama on 10.0 or earlier and are currently using legacy certificates for Panorama communication.
- Re-onboard affected Dedicated Log Collectors using an Auth Key to migrate to current certificates.
- Verify re-onboarding is successful.
Environment
- Panorama
- 11.0 or lower
- Planning upgrade to 11.1 or higher
- Log Collector
- 11.0 or lower
- Onboarded to Panorama on 10.0 or lower
Procedure
- Identify the Log Collectors using legacy certificates for securing Panorama communication
- On Panorama CLI, issue the command:
> show log-collector all - Under each Log Collector entry, check the "Certificate subject Name" for one of three possible formats:
- Serial number of LC
- Format: Decimal number
XXXXXXXXXXXX - Example output:
012345678901 2 log-collector1 yes In Sync 10.2.10-h9 10.1.1.1 - unknown Certificate subject Name: 012345678910Result: Legacy certificate in use. Must re-onboard.
- Format: Decimal number
- UUID
- Format: Hexadecimal number
XXXXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXXXX Example output:012345678901 2 log-collector1 yes In Sync 10.2.10-h9 10.1.1.1 - unknown Certificate subject Name: 01234567-89ab-cdef-0123-456789abcdefResult: New certificate in use. No action required.
- Format: Hexadecimal number
- Blank
- Example output:
012345678901 2 log-collector1 yes In Sync 10.2.10-h9 10.1.1.1 - unknown Certificate subject Name:Result: This is the local log collector. No action required.
- Example output:
- Serial number of LC
- On Panorama CLI, issue the command:
- Re-onboard Log Collectors that have been identified as using legacy certificate
- On Panorama generate a new Auth Key
- Navigate to: Panorama -> Device Registration Auth Key
- Click Add
- Enter a name
- Set the "Lifetime" to a value greater than the default 1 minute. eg. 1 day
- Set the "Count" to the number of Log Collectors to re-onboard
- Set the "Device Type" to Log Collector
- Enter the the serial numbers of the Log Collectors to re-onboard
- Click OK
- Click Copy Auth Key
- On each Log Collector to re-onboarded
- Set the new Auth Key
> request authkey set <authkey> - Restart the Management Server
> debug software restart process management-server
- Set the new Auth Key
- On Panorama generate a new Auth Key
- Verify that Log Collectors have re-onboarded successfully
- For each log collector that has been re-onboarded, on Panorama issue the command:
> show log-collector <serial_number_of_log_collector> - Check the "Certificate subject Name" is now in UUID format
- Format: Hexadecimal number
XXXXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXXXX Example output:012345678901 2 log-collector1 yes In Sync 10.2.10-h9 10.1.1.1 - unknown Certificate subject Name: 01234567-89ab-cdef-0123-456789abcdef
- Format: Hexadecimal number
- For each log collector that has been re-onboarded, on Panorama issue the command:
Additional Information
This procedure is a pre-requisite for upgrading Panorama and Log Collectors to 11.1 as per the Upgrade/Downgrade Considerations document.