Automated certificate renewal for Palo Alto Networks PAN-OS
GlobalProtect portals and gateways, and the management interface, depend on certificates that someone has to import and commit. The PAN-OS package imports the keypair over the XML API and commits.
package palo-alto-target 2.0.0
importKeypairwhen configuredimportKeypairVsyswhen configuredcommitwaitForCommitwhen configured
At a glance
- Package
palo-alto-target 2.0.0- Compatibility
PAN-OS / Panorama >=9.0 <12.0- Runs from
- Any Windows or Linux agent with network access to it
- Mechanism
- REST API
- Authentication
- API key
- Capabilities
- Import certificate and keyActivate configuration
- Deployment steps
- importKeypair* → importKeypairVsys* → commit → waitForCommit*
- Rollback
- None
- Key usage
- No requirement
* conditional step
What it does
An agent on your network imports the certificate and key as a keypair under the configured name - into a specific virtual system if you set one - and then commits the configuration, waiting for the commit to finish.
SSL/TLS service profiles that reference the certificate name pick up the renewed certificate after the commit.
How it runs
- 01
importKeypair / importKeypairVsys
The keypair is imported, into the configured vsys if set.
- 02
commit
A commit is started.
- 03
waitForCommit
The package waits for the commit job to finish.
What you configure
- Management host and port (firewall or Panorama)
- XML API key (stored encrypted)
- Certificate name
- Optional virtual system
Prerequisites
- An agent with network access to the management interface
- An API key for an admin allowed to import certificates and commit
Limitations
- The commit applies all pending changes on the device, not only the certificate.
Doing it by hand
The documentation has a step-by-step guide for replacing this certificate manually - useful for a first install, or to see exactly what the package automates.
Related features
Solutions
More in Firewalls
Documentation
Frequently asked questions
Palo Alto Networks PAN-OS
Does it commit automatically?
Yes. The import is followed by a commit, and the package waits for it to complete. Pending changes by other admins are committed with it.
Is Panorama supported?
The package declares PAN-OS and Panorama 9.0 up to (not including) 12.0.
Automate Palo Alto Networks PAN-OS
Enroll an agent, attach the package, and the next renewal installs itself.
Community plan, no card required. Open registration - your account is ready in a few minutes.