Configure a Master Key
Focus
Focus
Next-Generation Firewall

Configure a Master Key

Table of Contents

Configure a Master Key

Learn how to configure a unique master key to secure all private keys and passwords in a particular configuration.
Where Can I Use This?What Do I Need?
  • NGFW
One of these licenses for Strata Cloud Manager managed NGFWs:
  • Strata Cloud Manager Essentials
  • Strata Cloud Manager Pro
Role requirements:
  • Superuser role (to update the master key)
  • Admin role or higher (to synchronize and view)
A master key encrypts all private keys and passwords in a configuration to secure them (such as the private key used for SSL Forward Proxy decryption). Every Next-Generation Firewall (NGFW), Panorama appliance, log collector, and WF-500 appliance has a default master key.
Master key requirements vary by deployment:
  • In a high availability (HA) configuration, both NGFWs or Panorama appliances must use the same master key since keys are not synchronized across HA peers. Otherwise, HA synchronization will not work properly.
  • If you're using Panorama to manage your NGFWs, you can either configure the same master key on Panorama and the managed NGFWs or configure a unique master key for each managed NGFW. The most secure option is to configure a unique master key for Panorama and each managed NGFW. This limits the security impact of a compromised master key. See Manage the Master Key from Panorama if your NGFWs are managed by a Panorama appliance.
    Unique master keys are supported only for Panorama and managed NGFWs. Log collectors and WF-500 appliances must share the same master key as Panorama.
Store master keys in a safe location such as a hardware security module (HSM). Lost master keys cannot be recovered. The only way to restore the default master key is to reset the NGFW to factory default settings.
Change the default master key as soon as possible to ensure that you use a unique master key for encryption.
(PAN-OS 12.2.2 and later releases) PAN-OS 12.2.2 enforces replacement of the default master key with a custom master key within a specific grace period. Configure a custom master key before the 60-day default grace period expires. See Default Master Key Replacement below for full details.
Default Master Key Replacement
(PAN-OS 12.2.2 and later releases)
The default master key is publicly known and poses a critical security risk. Starting with PAN-OS 12.2.2, the system enforces replacement of the default master key with a custom master key within a configurable grace period.
When the system detects the default master key, a 60-day grace period begins automatically. If you need additional time, you can extend the grace period to a maximum of 120 days, but you must configure this extension before the current grace period expires. This 120-day limit is absolute and measured from the original trigger event — an upgrade, factory reset, or first power-on. The extension does not add a new window from the date you configure it. The system always calculates the final deadline from the date of the original trigger event, regardless of when you configure the extension. You cannot extend the grace period beyond 120 days under any circumstances.
After the grace period expires, the system blocks all standard configuration commits, commit-all jobs, and HA synchronization until you configure a custom master key. Auto-commits and dynamic updates, including content and antivirus deployments, continue to operate normally during this blocked state.
Palo Alto Networks strongly recommends configuring a custom master key immediately after upgrading to PAN-OS 12.2.2. Do not wait for the default grace period of 60 days to approach expiry.
The countdown begins when any of the following trigger events are detected:
  • You upgrade a device to PAN-OS 12.2.2 or a later version.
  • You restore a device running PAN-OS 12.2.2 or a later version to factory default settings.
  • You power on a new factory-default device running PAN-OS 12.2.2 or a later version for the first time.
If a grace period timer is already running, upgrading or downgrading between PAN-OS 12.2.2 and later versions does not restart the timer. If the grace period has already expired and you downgrade to another PAN-OS 12.2.2 or later release, the timer does not restart and commits fail immediately on the downgraded version.
If your firewalls are managed by Strata Cloud Manager, you can configure a per-tenant custom master key and synchronize it to all managed firewalls centrally, without configuring the key on each device individually. Strata Cloud Manager also automatically deploys the custom master key to newly onboarded firewalls during the bootstrap process, ensuring they never operate with the default key beyond first connect. See the Strata Cloud Manager tab below for details.

Configure the Master Key Panorama and PAN-OS

Ensure there are no pending configuration changes before starting this procedure. Commit any pending changes prior to configuring the master key.
  1. (HA only) Disable configuration synchronization.
    This step is required before deploying a new master key to any NGFW HA pair.
    Before deploying a new master key to any NGFW in an HA pair, disable Config Sync.
    If Panorama is in a passive HA configuration, a failover to make Panorama active is required before proceeding. Configure the master key only on the active Panorama peer.
    1. Select DeviceHigh AvailabilityGeneral and edit the Setup.
    2. Disable (clear) Enable Config Sync and then click OK.
    3. Commit your configuration changes.
  2. Select DeviceMaster Key and Diagnostics and edit the Master Key section.
    In the Master Key dialog, select the Master Key checkbox to activate the master key configuration fields. The fields are greyed out until the checkbox is selected.
  3. Enter the Current Master Key if one exists.
  4. Define a new New Master Key, and then Confirm New Master Key. The key must contain exactly 16 characters.
    Record and store your master key in a secure, access-controlled location. You will need this key to perform future key rotations, restore configurations, or recover from HA failover scenarios. If the master key is lost, the device cannot be recovered without a full factory reset, resulting in complete loss of your running configuration.
    For devices participating in a high availability (HA) configuration, you must configure the same master key on both HA peers. HA synchronization fails if the master keys do not match.
  5. To specify the master key Lifetime, enter the number of Days or Hours after which the key expires.
    Configure a new master key before the current key expires. If the master key expires, the NGFW or Panorama automatically reboots in Maintenance mode causing a network traffic outage. Then, you must reset the NGFW to factory default settings.
    Set the Lifetime to two years or less, depending on how many encryptions the device performs. The more encryptions a device performs, the shorter the Lifetime you should set. The critical consideration is to not run out of unique encryptions before you change the master key. Each master key can provide up to 232 unique encryptions based on the master key value and the Initialization Vector (IV) value. After 232 unique encryptions, encryptions repeat (are no longer unique), which is a security risk.
    Set a Time for Reminder value (see next step) for the master key and when the reminder notification occurs, change the master key.
  6. Enter a Time for Reminder that specifies the number of Days and Hours before the master key expires when the NGFW generates an expiration alarm. The NGFW automatically opens the System Alarms dialog to display the alarm.
    Set the reminder so that it gives you plenty of time to configure a new master key before it expires in a scheduled maintenance window. When the Time for Reminder expires and the NGFW or Panorama sends a notification log, change the master key, don’t wait for the Lifetime to expire. For grouped devices, track every device (for example, NGFWs that Panorama manages and NGFW HA pairs) and when the reminder value expires for any device in the group, change the master key.
    To ensure the expiration alarm displays, select DeviceLog Settings, edit the Alarm Settings, and Enable Alarms.
  7. Enable Auto Renew Master Key to configure the NGFW to automatically renew the master key. To configure Auto Renew With Same Master Key, specify the number of Days or Hours to renew the same master key. The key extension enables the NGFW to remain operational and continue securing your network; it is not a replacement for configuring a new key if the existing master key lifetime expires soon.
    Automatically renewing the master key has benefits and risks. The benefit is that extending the master key Lifetime protects against failure to change the master key before its lifetime expires. The risk is that encryptions will repeat and cause a security risk if the number of encryptions the device performs with the master key exceeds the number of unique encryptions the master key can generate (232 unique encryptions).
    If the master key expires (you don't automatically renew or replace it in a timely manner), the device reboots into maintenance mode, causing a network traffic outage. The only recovery method is to factory reset the device.
    If you enable Auto Renew Master Key, set it so that the total time (lifetime plus the auto renew time) does not cause the device to run out of unique encryptions. For example, if you believe the device will consume the master key’s number of unique encryptions in two and a half years, you could set the Lifetime for two years, set the Time for Reminder to 60 days, and set the Auto Renew Master Key for 60-90 days to provide the extra time to configure a new master key before the Lifetime expires. However, the best practice is still to change the master key before the lifetime expires to ensure that no device repeats encryptions.
    Consider the number of days until your next available maintenance window when configuring the master key to automatically renew after the lifetime of the key expires.
  8. (12.2.2 and later releases) Configure the Default Master Key Grace Period in the Master Key dialog.
    1. In the Master Key dialog, locate the Default Master Key Grace Period field at the bottom of the dialog.
      • This field is only active and editable while the device is still using the default master key. Once a custom master key is configured on the device, this field is hidden — it is not applicable and the option to configure it is removed from the dialog.
      • Enter a value between 60 and 120 days. If you do not configure a value, the grace period defaults to 60 days.
      • 120-day limit is cumulative from the original trigger event (upgrade, factory reset, or first power-on) — it is not an additional extension. For example, if 60 days have already elapsed since upgrade, you cannot gain a further 120 days. The maximum total time available is 120 days from the original start of the timer.
      • The dialog displays a warning indicator showing the number of days remaining to configure a new master key — for example, 96 Days Remaining to Configure New Master Key.
      During the grace period, each configuration commit generates an on-screen warning prompting you to configure a custom master key. In addition, a critical severity system log is generated on every commit. Monitor these warnings and act before the grace period expires — once it does, commits fail and HA sync is suspended until a custom master key is configured.
      If this firewall is managed by Panorama, the grace period can also be configured centrally. See Manage the Master Key from Panorama.
    2. Click OK.
  9. (Optional) For added security, select whether to use an HSM to encrypt the master key. For details, see Encrypt and Refresh Master Keys Using an HSM.
  10. Click OK and select CommitCommit to PanoramaCommit All Changes.
  11. (HA only) Re-enable configuration synchronization.
    1. Select DeviceHigh AvailabilityGeneral and edit the Setup.
    2. Enable Config Sync, and then click OK.
    3. Select CommitCommit to PanoramaCommit All Changes.

Configure the Master Key Strata Cloud Manager

Strata Cloud Manager provides two methods to configure and manage master keys on your cloud-managed firewalls:
  • Sync to SCM Master Key (recommended)—Configure a per-tenant master key in Strata Cloud Manager and synchronize it to all managed firewalls. Strata Cloud Manager stores the key, tracks versions, handles rotations without requiring the previous key, and automatically deploys the key to newly bootstrapped firewalls.
  • Deploy Master Key (legacy)—Deploy a master key directly to individual firewalls. Keys deployed through this method are not stored or tracked by Strata Cloud Manager, and you must provide the current key for subsequent rotations.
Master key configuration status never blocks device onboarding. If you have not configured a master key for the tenant, the Device Management page displays a warning banner. Devices onboard successfully with the default key, and you can configure and synchronize a custom key at any time.
Role requirements: Updating the Strata Cloud Manager master key (creating a new key version) requires the Superuser role. Synchronizing the master key to devices and viewing master key state requires the Admin role or higher.
This feature is available on request. Contact your account team to enable the feature.

Sync to SCM Master Key

Use the centralized workflow to configure a single master key for your tenant and synchronize it to all managed firewalls. This is the recommended approach for replacing the default master key before the grace period expires.
  1. Log in to Strata Cloud Manager.
  2. Select System SettingsDevice Management.
    The Cloud Managed Devices tab displays the device table with master key status columns including Status, Master Key Managed By SCM, Grace Period, Updated At, Last Sync Status, Device Status, and Bootstrap Status.
    The Device Management toolbar displays the following master key actions depending on what is enabled for your tenant:
    • Master Key Actions dropdown (includes Update SCM Master Key and Sync to SCM Master Key)—Appears when centralized master key management is enabled for your tenant.
    • Deploy Master Key button—This button is disabled (grayed out) when centralized master key management is active and the selected devices are already managed by Strata Cloud Manager.
  3. Select Master Key ActionsUpdate SCM Master Key.
    This creates a new master key version for the tenant. Firewalls that are already connected continue to use their current key until you synchronize the new key to them.
  4. Choose a generation method:
    • Auto-generate (Recommended)—Strata Cloud Manager generates a secure 16-character key and stores it in a vault. The master key lifetime is set to the maximum value. Use this option when you do not need to know the key value and plan to keep the firewalls managed by Strata Cloud Manager.
    • Provide Custom Key—Manually enter a 16-character alphanumeric key (A-Z, a-z, 0-9). Use this option when you need to know the key value, for example, if you plan to offboard firewalls from Strata Cloud Manager in the future.
    If you use the auto-generate option and later offboard a firewall from Strata Cloud Manager, you will not have the key value needed to change the master key on that firewall. Before offboarding a firewall, update the master key to a known custom key and synchronize it to the firewall.
  5. (Custom Key only) Configure the following fields:
    • Enter the 16-character key value in Enter Custom Master Key. The key must be exactly 16 alphanumeric characters (A-Z, a-z, 0-9).
    • Set the Master Key Lifetime — the duration (in hours) before the key must be rotated.
    • Set the Update Reminder — the number of hours before expiry that Strata Cloud Manager displays a reminder to rotate the key.
  6. Select Save.
  7. Select one or more firewalls in the device table, then select Master Key ActionsSync to SCM Master Key.
    The sync dialog adapts based on each device's master key status:
    • If a device is on the default master key or its key is already managed by Strata Cloud Manager, no key input is required. The Current Master Key Input column displays "Not required (known by SCM)."
    • If a device has a locally configured custom key that is not managed by Strata Cloud Manager, you must enter the device's current master key value. The Current Master Key Input column displays a text field.
    The dialog displays the selected firewalls with the following columns:
    • Name—The firewall serial number.
    • Status—The current master key status.
    • Master Key Managed By SCM—Whether Strata Cloud Manager currently manages the key on this device.
    • Stored on HSM—Select this checkbox if the firewall stores the master key on a hardware security module (HSM).
    • Current Master Key Input—If the firewall has a locally-configured custom key that is unknown to Strata Cloud Manager, enter the current key value. If Strata Cloud Manager already knows the key (because it previously deployed it), this field displays "Not required (known by SCM)."
  8. Select Sync to SCM Master Key.
    Strata Cloud Manager pushes the master key to each selected firewall and commits the change. Monitor the Last Sync Status and Updated At columns to verify the operation completed successfully.
  9. Verify the sync was successful.
    After a successful sync:
    • The Status column shows Custom Key (green).
    • The Master Key Managed By SCM column shows Yes.
    • The Last Sync Status column shows Success.
    • The Updated At column shows the sync timestamp.
    If the Last Sync Status shows Failed, select the status link to view error details. Common causes include:
    • Invalid current master key—The key value you entered for a locally-managed device does not match the key on the firewall.
    • Pending configuration changes—The firewall has uncommitted changes. Revert pending changes on the firewall and retry the sync.
Master Key on First Connect (Bootstrap)—When you configure a Strata Cloud Manager master key before onboarding a new firewall, the firewall automatically receives the custom master key during the bootstrap process on first connect. After bootstrapping, the Status column shows Custom Key and Master Key Managed By SCM shows Yes. No additional sync action is required for newly bootstrapped firewalls.
Configure Grace Period and Auto-Renew Settings
Configure the default master key grace period and auto-renew lifetime as part of your device configuration. These settings are pushed to firewalls using the standard Push Config workflow. These fields appear under General Settings when the master key management feature is enabled for your tenant.
  1. Select ConfigurationNGFW and Prisma Access.
  2. Select the appropriate Configuration Scope:
    • All Firewalls—Applies to all managed firewalls (lowest precedence).
    • Folder—Applies to firewalls in a specific folder.
    • Snippet—Applies to firewalls associated with the snippet.
    • Device—Applies to a specific firewall (highest precedence).
  3. Select Network & DeviceDevice Setup.
  4. Under General Settings, select the settings icon and configure:
    • Auto Renew With Same Master Key—The interval (in hours or days) at which the firewall automatically renews the master key using the same value. This prevents the key from expiring and the firewall from entering maintenance mode. Set to 0 to disable auto-renewal (recommended when Strata Cloud Manager manages key rotation explicitly). A non-zero value means the firewall automatically renews the key lifetime at the specified interval without generating a new key — the device remains synchronized with Strata Cloud Manager.
    • Default Master Key Grace Period (days)—The number of days (60 to 120) before a firewall using the default key triggers a commit failure (PAN-OS 12.2.2 and later). Defaults to 60 days if not configured.
  5. Select OK to save the settings.
  6. Select Push Config to push the configuration to the target firewalls.
Master key settings follow the Strata Cloud Manager configuration scope hierarchy. If you configure settings at a higher scope (for example, All Firewalls), lower scopes (Device) inherit those values — the General Settings panel displays "Inherited from [scope name]." If you then configure the settings at an intermediate scope (for example, Snippet), the Device scope inherits from the Snippet instead. Settings configured at a higher scope are inherited by firewalls at lower scopes unless overridden. Precedence order (lowest to highest): All Firewalls, Folder, Snippet, Device.
Load a Local Configuration Version
The Local Config Management option is available in the per-device Actions menu when this feature is enabled for your tenant. This feature allows you to load a previous local configuration version snapshot on a firewall from Strata Cloud Manager.
Local configuration version snapshots represent the local firewall running configuration only — they do not include the SCM-pushed configuration. If you pushed a master key from Strata Cloud Manager to a device, any secrets in the local configuration are encrypted using that master key version. When you load a previous configuration version, Strata Cloud Manager must supply the correct key to decrypt those secrets.
Strata Cloud Manager handles this automatically based on the device's master key status:
  • Key managed by Strata Cloud Manager—If Strata Cloud Manager knows the master key version that was active when the configuration snapshot was captured, it automatically sends that key version as part of the load operation. No user action is required.
  • Locally configured key unknown to Strata Cloud Manager—If the device has a locally configured master key that Strata Cloud Manager does not know about, you must enter the key value before loading the configuration.
This capability requires PAN-OS 12.2.2 or later. For firewalls running earlier versions, load the configuration locally using the CLI command load config key <value>.
  1. Select System SettingsDevice ManagementCloud Managed Devices.
  2. Locate the firewall and select the Actions menu (three dots).
  3. Select Local Config Management.
  4. In the Local Config Version Snapshots dialog, locate the version you want to restore.
  5. Select Load for the desired version.
    A confirmation dialog box appears.
  6. Select Load.
    Strata Cloud Manager automatically supplies the correct master key version if the key was managed by Strata Cloud Manager when the snapshot was captured.

Deploy a Master Key to Individual Firewalls (Legacy)

Use this per-device method only if you need to manage individual device keys independently of the centralized Strata Cloud Manager workflow. Keys deployed through this action are not stored or tracked by Strata Cloud Manager.
For centralized key lifecycle management, use the Sync to SCM Master Key workflow instead.
  1. Log in to Strata Cloud Manager.
  2. Select System SettingsDevice Management.
    The Device Management page displays the firewalls.
  3. Select the required firewalls, click Deploy Master Key and edit the Deploy Master Key section.
  4. Enter the Current Master Key if one exists.
  5. Define a new New Master Key, and then Confirm New Master Key. The key must contain exactly 16 characters.
  6. To specify the master key Lifetime, enter the number of Days or Hours after which the key expires.
    Configure a new master key before the current one expires. You can set the lifetime of the master key from 1 to 18,250 days. If the master key expires, the firewall automatically reboots in Maintenance mode. Then, you must reset the NGFW to factory default settings.
    Set the Lifetime to two years or less, depending on how many encryptions the device performs. The more encryptions a device performs, the shorter the Lifetime you should set. The critical consideration is to not run out of unique encryptions before you change the master key. Each master key can provide up to 232 unique encryptions based on the master key value and the Initialization Vector (IV) value. After 232 unique encryptions, encryptions repeat (are no longer unique), which is a security risk.
    Set a Time for Reminder value (see next step) for the master key and when the reminder notification occurs, change the master key.
  7. Enter a Time for Reminder that specifies the number of Days and Hours before the master key expires when the firewall generates an expiration alarm. The firewall automatically opens the System Alarms dialog to display the alarm.
    Set the reminder so that it gives you plenty of time to configure a new master key before it expires in a scheduled maintenance window. When the Time for Reminder expires and the firewall sends a notification log, change the master key, do not wait for the Lifetime to expire.
  8. (Optional) For added security, select whether to use an HSM to encrypt the master key. For details, see Encrypt and Refresh Master Keys Using an HSM.
  9. Click Deploy Master Key.
    Keys deployed using this method are not tracked as Strata Cloud Manager-managed. The Master Key Managed By SCM column displays No for these devices and the Updated At and Last Sync Status columns are not populated.