Home
EN
Location
Documentation Home
Palo Alto Networks
Support
Live Community
Knowledge Base
>
Clear
Generate a Private Key and Block It
Updated on
Tue Jul 22 10:21:19 PDT 2025
Focus
Download PDF
English
日本語 (Japanese)
中文 (Chinese Simplified)
繁體中文 (Chinese Traditional)
Español (Spanish)
Français (French)
한국어 (Korean)
Updated on
Tue Jul 22 10:21:19 PDT 2025
Focus
Home
PAN-OS
Decryption
Block Private Key Export
Generate a Private Key and Block It
Download PDF
English
日本語 (Japanese)
中文 (Chinese Simplified)
繁體中文 (Chinese Traditional)
Español (Spanish)
Français (French)
한국어 (Korean)
Generate a Private Key and Block It
Table of Contents
Filter
End-of-Life (EoL)
Previous
Block Private Key Export
Next
Import a Private Key and Block It
Generate a Private Key and Block It
Secure private keys that you generate on PAN-OS devices by blocking key export.
Block the export of a private key to prevent its misuse after generating a certificate.
Select
Device
Certificate Management
Certificates
Device Certificates
.
If there is more than one virtual system, select a
Location
or
Shared
for the certificate.
Generate
the certificate.
Select
Block Private Key Export
to prevent anyone from exporting the certificate.
See
Generate a Certificate
for information about the other certificate fields.
Click
Generate
to generate the new certificate.
You can also generate a certificate and block its private key from export using the operational CLI command:
admin@pa-220> request certificate generate block-private-keys yes
The preceding CLI command can also include the certificate and other parameters that are not shown.
Previous
Block Private Key Export
Next
Import a Private Key and Block It