aethercert
Firewalls

Automated certificate renewal for Palo Alto Networks PAN-OS

GlobalProtect portals and gateways, and the management interface, depend on certificates that someone has to import and commit. The PAN-OS package imports the keypair over the XML API and commits.

The deployment steps defined in this package's manifest.

At a glance

Package
palo-alto-target 2.0.0
Compatibility
PAN-OS / Panorama >=9.0 <12.0
Runs from
Any Windows or Linux agent with network access to it
Mechanism
REST API
Authentication
API key
Capabilities
Import certificate and keyActivate configuration
Deployment steps
importKeypair* → importKeypairVsys* → commit → waitForCommit*
Rollback
None
Key usage
No requirement

* conditional step

What it does

An agent on your network imports the certificate and key as a keypair under the configured name - into a specific virtual system if you set one - and then commits the configuration, waiting for the commit to finish.

SSL/TLS service profiles that reference the certificate name pick up the renewed certificate after the commit.

How it runs

  1. 01

    importKeypair / importKeypairVsys

    The keypair is imported, into the configured vsys if set.

  2. 02

    commit

    A commit is started.

  3. 03

    waitForCommit

    The package waits for the commit job to finish.

What you configure

  • Management host and port (firewall or Panorama)
  • XML API key (stored encrypted)
  • Certificate name
  • Optional virtual system

Prerequisites

  • An agent with network access to the management interface
  • An API key for an admin allowed to import certificates and commit

Limitations

  • The commit applies all pending changes on the device, not only the certificate.

Doing it by hand

The documentation has a step-by-step guide for replacing this certificate manually - useful for a first install, or to see exactly what the package automates.

Manual replacement guide

Frequently asked questions

Palo Alto Networks PAN-OS

Does it commit automatically?

Yes. The import is followed by a commit, and the package waits for it to complete. Pending changes by other admins are committed with it.

Is Panorama supported?

The package declares PAN-OS and Panorama 9.0 up to (not including) 12.0.

Automate Palo Alto Networks PAN-OS

Enroll an agent, attach the package, and the next renewal installs itself.

Community plan, no card required. Open registration - your account is ready in a few minutes.