Home
EN
Location
Documentation Home
Palo Alto Networks
Support
Live Community
Knowledge Base
>
Clear
Strata Copilot
Generate a Private Key and Block It
Updated on
Jul 22, 2025
Focus
Download PDF
English
日本語 (Japanese)
中文 (Chinese Simplified)
繁體中文 (Chinese Traditional)
Español (Spanish)
Français (French)
한국어 (Korean)
Updated on
Jul 22, 2025
Focus
Home
PAN-OS
Decryption
Block Private Key Export
Generate a Private Key and Block It
Download PDF
English
日本語 (Japanese)
中文 (Chinese Simplified)
繁體中文 (Chinese Traditional)
Español (Spanish)
Français (French)
한국어 (Korean)
Generate a Private Key and Block It
Table of Contents
Filter
End-of-Life (EoL)
Previous
Block Private Key Export
Next
Import a Private Key and Block It
Generate a Private Key and Block It
Secure private keys that you generate on PAN-OS devices by blocking key export.
Block the export of a private key to prevent its misuse after generating a certificate.
Select
Device
Certificate Management
Certificates
Device Certificates
.
If there is more than one virtual system, select a
Location
or
Shared
for the certificate.
Generate
the certificate.
Select
Block Private Key Export
to prevent anyone from exporting the certificate.
See
Generate a Certificate
for information about the other certificate fields.
Click
Generate
to generate the new certificate.
You can also generate a certificate and block its private key from export using the operational CLI command:
admin@pa-220> request certificate generate block-private-keys yes
The preceding CLI command can also include the certificate and other parameters that are not shown.
Previous
Block Private Key Export
Next
Import a Private Key and Block It