User Tools

Site Tools


windows:create_certificate_with_pki

Create Certificate with Microsoft PKI

  1. Import the Root cert of the MS CA into the Palo Alto Networks.
  2. Go to https://server_ip/certsrv (where server_ip is the IP or DNS name of the Windows Server that is running the MS Certificate Authority)
  3. Click the link Download a CA Certificate, certificate chain or CRI
  4. Select the format Base64
  5. Click the link Download CA certificate
  6. On the Palo Alto Networks firewall, go to Device→Certificate→Import
  7. Select File
  8. Set Certificate name to something meaningful (e.g. my_domain.local)
  9. Click Okay
  10. Select Certificate from the list and tick 'Trusted Root CA'.
  11. Generate a certificate signing request (CSR) that is to be signed by External authority. Add all the extra info as needed.
  12. Export the CSR using the Export button in the Palo GUI
  13. Click Request certificate
  14. Click Advanced Certificate request
  15. Set Certificate template to Subordinate Certificate Authority
  16. Paste in the text from the CSR files and click Submit
  17. Click Base64 encoded.
  18. Download the Certificate
  19. Download the certificate chain
  20. On the Palo GUI, go to Device→Certificate and click Import.
  21. Select the Certificate you just downloaded from server_ip.
  22. Make sure you set the value of Certificate Name to be identical to that of the CSR entry.
  23. Now you can generate a SSL_Decrypt certificate or any other 'trusted' certificate on the Palo using your newly signed subordinate CA certificate.
  24. Don't forget to set your Decryption policies under the Policy tab and the Decryption profile under the Objects tab. Also, don't forget to create a self-signed untrust certificate.
windows/create_certificate_with_pki.txt · Last modified: by 127.0.0.1