To update certificates for protected internal servers
without incurring downtime, renew or obtain a new server
certificate before it expires or otherwise becomes
invalid. Then, import the certificate and private key
onto your
NGFW or
Strata Cloud Manager,
add it to an SSL Inbound Inspection policy rule before
installing the same certificate onto your web server.
Updating your policy rule with a new certificate while
another is active on your web server prepares the
NGFW to decrypt traffic to the server
regardless of the certificate in use.
Configure SSL Inbound
Inspection describes this process
further.
(Panorama ™) Support for multiple
certificates in SSL Inbound Inspection policy rules is
unavailable in PAN-OS® versions earlier than
PAN-OS 10.2. If you push an SSL Inbound Inspection
policy rule with multiple certificates from a Panorama
management server running PAN-OS 10.2 to a NGFW running an earlier version, the
policy rule on the managed NGFW inherits
only the first certificate from the alphabetically
sorted list of certificates.