Import a Certificate and Private Key (2024)

Import a Certificate and Private Key

Updated on

Wed Aug 21 20:47:37 UTC 2024

Focus

Download PDF

Updated on

Wed Aug 21 20:47:37 UTC 2024

Focus

  1. Home
  2. PAN-OS
  3. Certificate Management
  4. Obtain Certificates
  5. Import a Certificate and Private Key

Download PDF

Table of Contents

End-of-Life (EoL)

Previous Generate a Certificate
Next Obtain a Certificate from an External CA

If your enterprise has its own public keyinfrastructure (PKI), you can import a certificate and private keyinto the firewall from your enterprise certificate authority (CA). EnterpriseCA certificates (unlike most certificates purchased from a trusted, third-partyCA) can automatically issue CA certificates for applications suchas SSL/TLS decryption or large-scale VPN.

Ona Palo Alto Networks firewall or Panorama, you can import self-signed certificatesonly if they are CA certificates.

Instead of importing a self-signedroot CA certificate into all the client systems, it is a best practiceto import a certificate from the enterprise CA because the clientswill already have a trust relationship with the enterprise CA, whichsimplifies the deployment.

If the certificate you will importis part of a certificate chain, it is a best practice to importthe entire chain.

  1. From the enterprise CA, export the certificateand private key that the firewall will use for authentication.

    When exporting a private key, you must enter a passphraseto encrypt the key for transport. Ensure the management system canaccess the certificate and key files. When importing the key ontothe firewall, you must enter the same passphrase to decrypt it.

  2. Select

    Device

    CertificateManagement

    Certificates

    DeviceCertificates

    .

  3. If the firewall has more than one virtual system (vsys),select a

    Location

    (vsys or

    Shared

    )for the certificate.

  4. Click

    Import

    and enter a

    CertificateName

    . The name is case-sensitive and can have up to63 characters on the firewall or up to 31 characters on Panorama.It must be unique and use only letters, numbers, hyphens, and underscores.

  5. To make the certificate available to all virtual systems,select the

    Shared

    check box. This check boxappears only if the firewall supports multiple virtual systems.

  6. Enter the path and name of the

    CertificateFile

    received from the CA, or

    Browse

    tofind the file.

  7. Select a

    File Format

    :

    • Encrypted Private Key and Certificate(PKCS12)

      —This is the default and most common format,in which the key and certificate are in a single container (

      CertificateFile

      ). If a hardware security module (HSM) will storethe private key for this certificate, select the

      Privatekey resides on Hardware Security Module

      check box.

    • Base64 Encoded Certificate (PEM)

      —Youmust import the key separately from the certificate. If a hardwaresecurity module (HSM) stores the private key for this certificate,select the

      Private key resides on Hardware Security Module

      check boxand skip the next step. Otherwise, select the

      ImportPrivate Key

      check box, enter the

      Key File

      or

      Browse

      toit, then continue to the next step.

      (

      Panoramamanaged firewalls

      ) You are required to

      Import PrivateKey

      if you enabled

      Block Private Key Export

      whenthe certificate was generated to successfullypush configuration changes from the Panorama management server tomanaged firewalls.

  8. Enter and re-enter (confirm) the

    Passphrase

    usedto encrypt the private key.

  9. Click

    OK

    . The Device Certificatespage displays the imported certificate.

"); adBlockNotification.append($( "Thanks for visiting https://docs.paloaltonetworks.com. To improve your experience when accessing content across our site, please add the domain to the allow list on your ad blocker application." )); let adBlockNotificationClose = $("x"); adBlockNotification.prepend(adBlockNotificationClose) $('body').append(adBlockNotification); setTimeout(function (e) { adBlockNotification.addClass('open'); }, 10); adBlockNotificationClose.on('click', function (e) { adBlockNotification.removeClass('open'); }) } }, 5000)

Previous Generate a Certificate
Next Obtain a Certificate from an External CA

Recommended For You

{{ if(( raw.pantechdoctype != "techdocsAuthoredContentPage" && raw.objecttype != "Knowledge" && raw.pancommonsourcename != "TD pan.dev Docs")) { }} {{ if (raw.panbooktype) { }} {{ if (raw.panbooktype.indexOf('PANW Yellow Theme') != -1){ }}

{{ } else if (raw.panbooktype.indexOf('PANW Green Theme') != -1){ }}

{{ } else if (raw.panbooktype.indexOf('PANW Blue Theme') != -1){ }}

{{ } else { }}

{{ } }} {{ } else { }}

{{ } }} {{ } else { }} {{ if (raw.pantechdoctype == "pdf"){ }}

{{ } else if (raw.objecttype == "Knowledge") { }}

{{ } else if (raw.pancommonsourcename == "TD pan.dev Docs") { }}

{{ } else if (raw.pancommonsourcename == "LIVEcommunity Public") { }}

{{ } else { }}

{{ } }} {{ } }}

{{ if (raw.pancommonsourcename == "LIVEcommunity Public") { }}

{{ if (raw.pantechdoctype == "pdf"){ }}

{{ } }}

{{ } else { }}

{{ if (raw.pantechdoctype == "pdf"){ }}

{{ } }}

{{ } }}

{{ if (raw.pancommonsourcename != "TD pan.dev Docs"){ }} {{ if (raw.pandevdocsosversion){ }} {{ } else { }} {{ if ((_.size(raw.panosversion)>0) && !(_.isNull(raw.panconversationid )) && (!(_.isEmpty(raw.panconversationid ))) && !(_.isNull(raw.otherversions ))) { }} (See other versions) {{ } }} {{ } }} {{ } }}

{{ } }}{{ if (raw.pantechdoctype == "bookDetailPage"){ }}

{{ } }}{{ if (raw.pantechdoctype == "bookLandingPage"){ }}

{{ } }}{{ if (raw.pantechdoctype == "productLanding"){ }}

{{ } }}{{ if (raw.pantechdoctype == "techdocsAuthoredContentPage"){ }}

{{ } }}{{ if (raw.pantechdoctype == "pdf"){ }}

{{ } }}

© 2024 Palo Alto Networks, Inc. All rights reserved.

Import a Certificate and Private Key (2024)
Top Articles
What’s a Penny Social? Get More From this Fundraising Event
Five tips for writing mystery stories for kids | Australian Writers' Centre
Northern Counties Soccer Association Nj
Skyward Sinton
Where are the Best Boxing Gyms in the UK? - JD Sports
Hotels Near 625 Smith Avenue Nashville Tn 37203
Forozdz
Breaded Mushrooms
Stadium Seats Near Me
Nyuonsite
Kostenlose Games: Die besten Free to play Spiele 2024 - Update mit einem legendären Shooter
104 Presidential Ct Lafayette La 70503
Vichatter Gifs
What Is A Good Estimate For 380 Of 60
Wnem Radar
Hartford Healthcare Employee Tools
The fabulous trio of the Miller sisters
Guilford County | NCpedia
7543460065
Fool’s Paradise movie review (2023) | Roger Ebert
Ostateillustrated Com Message Boards
Diamond Piers Menards
Walmart stores in 6 states no longer provide single-use bags at checkout: Which states are next?
Average Salary in Philippines in 2024 - Timeular
Free Online Games on CrazyGames | Play Now!
Accident On May River Road Today
Zack Fairhurst Snapchat
Craigslist List Albuquerque: Your Ultimate Guide to Buying, Selling, and Finding Everything - First Republic Craigslist
The Blind Showtimes Near Amc Merchants Crossing 16
Rufus Benton "Bent" Moulds Jr. Obituary 2024 - Webb & Stephens Funeral Homes
Jc Green Obits
Minnick Funeral Home West Point Nebraska
Two Babies One Fox Full Comic Pdf
Horn Rank
Malluvilla In Malayalam Movies Download
Farm Equipment Innovations
100 Million Naira In Dollars
Bi State Schedule
Ridge Culver Wegmans Pharmacy
Average weekly earnings in Great Britain
Flixtor Nu Not Working
What Is Xfinity and How Is It Different from Comcast?
Bus Dublin : guide complet, tarifs et infos pratiques en 2024 !
Breckie Hill Fapello
Diana Lolalytics
Daily Journal Obituary Kankakee
Exploring The Whimsical World Of JellybeansBrains Only
Rage Of Harrogath Bugged
South Bend Tribune Online
2017 Ford F550 Rear Axle Nut Torque Spec
CPM Homework Help
Qvc Com Blogs
Latest Posts
Article information

Author: Lidia Grady

Last Updated:

Views: 6339

Rating: 4.4 / 5 (65 voted)

Reviews: 88% of readers found this page helpful

Author information

Name: Lidia Grady

Birthday: 1992-01-22

Address: Suite 493 356 Dale Fall, New Wanda, RI 52485

Phone: +29914464387516

Job: Customer Engineer

Hobby: Cryptography, Writing, Dowsing, Stand-up comedy, Calligraphy, Web surfing, Ghost hunting

Introduction: My name is Lidia Grady, I am a thankful, fine, glamorous, lucky, lively, pleasant, shiny person who loves writing and wants to share my knowledge and understanding with you.