You can export certificates and keys directly from the firewall or Panorama for
various applications.
Palo Alto Networks recommends that you use your enterprise public key
infrastructure (PKI) to distribute a certificate and private key in your
organization. However, if necessary, you can also export a certificate and private
key from the firewall or Panorama. You can use an exported certificate and private
key in the following cases: