0% found this document useful (0 votes)
8 views2 pages

Change A Client Certificate

The document provides a guide for replacing a client certificate in Panorama, including steps to obtain or generate a device certificate and change the certificate in the certificate profile. It outlines the use of self-signed certificates or those from trusted CAs, and mentions the SCEP profile for automatic certificate deployment. The guide emphasizes committing changes after updating the certificate profile.

Uploaded by

bibist
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
8 views2 pages

Change A Client Certificate

The document provides a guide for replacing a client certificate in Panorama, including steps to obtain or generate a device certificate and change the certificate in the certificate profile. It outlines the use of self-signed certificates or those from trusted CAs, and mentions the SCEP profile for automatic certificate deployment. The guide emphasizes committing changes after updating the certificate profile.

Uploaded by

bibist
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
You are on page 1/ 2

(/content/techdocs/en_US.

html)

Updated on Thu Mar 13 20:26:10 UTC 2025

Home (/) | Panorama (/content/techdocs/en_US/panorama.html)


| Panorama Administrator's Guide (/content/techdocs/en_US/panorama/10-1/panorama-admin.html)
| Set Up Panorama (/content/techdocs/en_US/panorama/10-1/panorama-admin/set-up-panorama.html)
| Set Up Authentication Using Custom Certificates (/content/techdocs/en_US/panorama/10-1/panorama-admin/set-up-panorama/set-up-
authentication-using-custom-certificates.html)
| Change Certificates (/content/techdocs/en_US/panorama/10-1/panorama-admin/set-up-panorama/set-up-authentication-using-custom-
certificates/change-certificates.html)
| Change a Client Certificate (/content/techdocs/en_US/panorama/10-1/panorama-admin/set-up-panorama/set-up-authentication-using-
custom-certificates/change-certificates/change-a-client-certificate.html)

DOWNLOAD PDF (/CONTENT/DAM/TECHDOCS/EN_US/PDF/PANORAMA/10-1/PANORAMA-ADMIN/PANORAMA-


ADMIN.PDF)

Panorama Administrator's Guide


(/content/techdocs/en_US/panorama/10-
1/panorama-admin.html)
Change a Client Certificate

Table of Contents

Complete the following task to replace a client certificate.

STEP 1 -
Obtain or generate the device certificate.

You can deploy certificates (https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/certificate-


management/certificate-deployment) on Panorama or a server Log Collector by generating a self-signed
certificate on Panorama or obtaining a certificate from your enterprise CA or a trusted third-party CA.

Set the common name to $UDID or subject to CN=$UDID (in the SCEP profile) if authorizing client devices
based on serial number.

You can generate a self-signed certificate on Panorama or obtain a certificate from your enterprise CA or a
trusted third-party CA.

If you are using SCEP for the device certificate, configure a SCEP profile
(https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/large-scale-vpn-lsvpn/enable-ssl-
between-globalprotect-lsvpn-components). SCEP allows you to automatically deploy certificates to
managed devices. When a new client devices with a SCEP profile attempts to authenticate with Panorama,
the certificate is sent by the SCEP server to the device.

STEP 2 -
Change the certificate in the certificate profile.

This site uses cookies essential to its operation, for analytics, and for personalized content and ads. By
continuing to browse this site, you acknowledge the use of cookies. Privacy statement ❯ Cookie Settings
A Select Device > Certificate Management > Certificate Profile and select the certificate profile.
(https://www.paloaltonetworks.com/legal-notices/privacy)
B Under CA Certificates, Add the new certificate to assign to the certificate profile.

C Click OK.

D Commit your changes.

Was this information helpful?

Yes No

Next
(/content/techdocs/en_US/panorama/10- (/content/techdocs/en_US/panorama/10-
Previous
Change a
1/panorama-admin/set-up-panorama/set-up- 1/panorama-admin/set-up-panorama/set-
Change a Root or
authentication-using-custom- up-authentication-using-custom-
Server Intermediate
certificates/change-certificates/change-a- certificates/change-certificates/change-a-
Certificate CA
server-certificate.html) root-or-intermediate-ca-certificate.html)
Certificate

Technical Documentation Co

Release Notes (/content/techdocs/en_US/release-notes.html) Abo


Search (/content/techdocs/en_US/search.html) Care
Blog (https://www.paloaltonetworks.com/blog/category/technical- Cus
documentation/) LIVE
Compatibility Matrix (/content/techdocs/en_US/compatibility- Kno
matrix.html)
OSS Listings (/content/techdocs/en_US/oss-listings.html)
Sitemap (/content/techdocs/en_US/sitemap.html)

(https://www.facebook.com/PaloAltoNetworks) (https://w
(https://www.youtube.com/channel/UCPRouchFt58TZnjoI65aelA)

(/content/techdocs/en_US.html) © 2025 Palo Alto Ne

This site uses cookies essential to its operation, for analytics, and for personalized content and ads. By
continuing to browse this site, you acknowledge the use of cookies. Privacy statement ❯
(https://www.paloaltonetworks.com/legal-notices/privacy)

You might also like

pFad - Phonifier reborn

Pfad - The Proxy pFad of © 2024 Garber Painting. All rights reserved.

Note: This service is not intended for secure transactions such as banking, social media, email, or purchasing. Use at your own risk. We assume no liability whatsoever for broken pages.


Alternative Proxies:

Alternative Proxy

pFad Proxy

pFad v3 Proxy

pFad v4 Proxy