Change A Client Certificate
Change A Client Certificate
html)
Table of Contents
STEP 1 -
Obtain or generate the device certificate.
Set the common name to $UDID or subject to CN=$UDID (in the SCEP profile) if authorizing client devices
based on serial number.
You can generate a self-signed certificate on Panorama or obtain a certificate from your enterprise CA or a
trusted third-party CA.
If you are using SCEP for the device certificate, configure a SCEP profile
(https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/large-scale-vpn-lsvpn/enable-ssl-
between-globalprotect-lsvpn-components). SCEP allows you to automatically deploy certificates to
managed devices. When a new client devices with a SCEP profile attempts to authenticate with Panorama,
the certificate is sent by the SCEP server to the device.
STEP 2 -
Change the certificate in the certificate profile.
This site uses cookies essential to its operation, for analytics, and for personalized content and ads. By
continuing to browse this site, you acknowledge the use of cookies. Privacy statement ❯ Cookie Settings
A Select Device > Certificate Management > Certificate Profile and select the certificate profile.
(https://www.paloaltonetworks.com/legal-notices/privacy)
B Under CA Certificates, Add the new certificate to assign to the certificate profile.
C Click OK.
Yes No
Next
(/content/techdocs/en_US/panorama/10- (/content/techdocs/en_US/panorama/10-
Previous
Change a
1/panorama-admin/set-up-panorama/set-up- 1/panorama-admin/set-up-panorama/set-
Change a Root or
authentication-using-custom- up-authentication-using-custom-
Server Intermediate
certificates/change-certificates/change-a- certificates/change-certificates/change-a-
Certificate CA
server-certificate.html) root-or-intermediate-ca-certificate.html)
Certificate
Technical Documentation Co
(https://www.facebook.com/PaloAltoNetworks) (https://w
(https://www.youtube.com/channel/UCPRouchFt58TZnjoI65aelA)
This site uses cookies essential to its operation, for analytics, and for personalized content and ads. By
continuing to browse this site, you acknowledge the use of cookies. Privacy statement ❯
(https://www.paloaltonetworks.com/legal-notices/privacy)