top of page

General discussion

Public·1 member

Certificate-Based Administrator Authentication to the Web Interface

Hi,

Im trying to create cert based administrator access but the doc from Palo Alto refers to selfsigned CA, can i use a cert from third party provider. if there is any useful link or material on how this could be done would be helpful. Should i repeat the process for all administrators, can i use authentication profile which has Firewall Admins.

https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/firewall-administration/manage-firewall-administrators/configure-administrative-accounts-and-authentication/configure-certificate-based-administrator-authentication-to-the-web-interface

26 Views
Reaper
Reaper
Apr 26, 2021

to set up this type of authentication to an external CA, you need to import the intermediate and root CA for the external CA, then create a certificate profile

In the Certificate profile you should add the CA cert that will be signing the client certificates, and also provide the OCSP/CRL information. Then go ahead just like the doc. (client certificates should have the admin username as CN)



  • Whatsapp
  • Amazon
  • X
  • LinkedIn

Contact
PANgurus BV
VAT: BE0769507136
INFO@PANGURUS.COM
+32 (486) 986 753

©2020 by PANgurus.

bottom of page