To update the certificate for a protected internal server
without incurring downtime, follow these steps:
- Renew or obtain a new server certificate before the
current one expires or otherwise becomes
invalid.
- Import the new certificate and private key onto your
NGFW.
Add the new certificate to your SSL Inbound
Inspection decryption policy rule.
This must be done while a different certificate
is active on the web server, so that a valid
certificate in the policy rule always matches the
certificate presented by the server.
- Install the new certificate on your web server, and
then verify that it was properly installed.
Installation of the new certificate doesn't impact
existing connections. The
NGFW verifies
that the certificate in the Server Hello message matches
the certificate in your decryption policy rule. If there
isn't a match, the session ends, and the corresponding
decryption log
entry reports the session-end reason as a certificate
mismatch between the firewall and server. To view the
server certificates used in all inbound inspection
sessions, select
Log Successful SSL
Handshake under Log Settings ().
(Panorama ™) Support for multiple
certificates in SSL Inbound Inspection policy rules
isn't available on PAN-OS versions earlier than PAN-OS
10.2. If you push an SSL Inbound Inspection policy rule
with multiple certificates from a Panorama management
server running PAN-OS 11.1 to an NGFW
running older software, the policy rule on the managed
NGFW inherits only the first
certificate from the alphabetically sorted list of
certificates.