Skip to content

Palo Alto Panorama

This feature is in Preview

This feature is currently available as a Preview and is not yet generally available (GA). Functionality and behavior may change before GA.

  1. In the Certificate Manager - SaaS toolbar, click Machines.
  2. On the right, click the More Options menu button for the machine that you want to provision a certificate to, and select Provision.
  3. From the Search a certificate by name, expiration, or fingerprint field, begin typing the certificate name you want to provision. Click the certificate when it appears in the list.

    Verify that you've selected the correct certificate by reviewing the Subject DN, Validity, and Fingerprint.

  4. In the Certificate Name field, enter the name for this certificate as you want it to appear on your Palo Alto Panorama.

    What if the name is already in use on the Palo Alto Panorama?

    When provisioning a certificate to the Palo Alto Panorama, Certificate Manager - SaaS checks whether the name you enter in this field is already in use.

    • If the name isn't in use, Certificate Manager - SaaS will use it.
  5. (Optional) In the Template field, select the template to use when creating the certificate. The certificate will be pushed to devices that are using this template.

  6. (Optional) In the Installation Endpoint field, enter a TLS Service Profile to associate with the certificate. The certificate will be pushed to all devices using this profile, if it is shared.

  7. If you don't want the certificate to be pushed when you save, toggle the Push certificate on save slider to Off.

  8. Click Save.

    Want to schedule your provisions?

    Schedule your provisions daily, weekly, or monthly. Learn more

After saving, the certificate is pushed to the Palo Alto Panorama tenant that you specified. The tenant's virtual service is updated to use that certificate, and an installation is created on the Installations tab.