Configure the Master Key Strata Cloud Manager
Focus
Focus
Next-Generation Firewall

Configure the Master Key Strata Cloud Manager

Table of Contents


Configure the Master Key Strata Cloud Manager

Strata Cloud Manager provides two methods to configure and manage master keys on your cloud-managed firewalls:
  • Sync to SCM Master Key (recommended)—Configure a per-tenant master key in Strata Cloud Manager and synchronize it to all managed firewalls. Strata Cloud Manager stores the key, tracks versions, handles rotations without requiring the previous key, and automatically deploys the key to newly bootstrapped firewalls.
  • Deploy Master Key (legacy)—Deploy a master key directly to individual firewalls. Keys deployed through this method are not stored or tracked by Strata Cloud Manager, and you must provide the current key for subsequent rotations.
Master key configuration status never blocks device onboarding. If you have not configured a master key for the tenant, the Device Management page displays a warning banner. Devices onboard successfully with the default key, and you can configure and synchronize a custom key at any time.
Role requirements: Updating the Strata Cloud Manager master key (creating a new key version) requires the Superuser role. Synchronizing the master key to devices and viewing master key state requires the Admin role or higher.
This feature is available on request. Contact your account team to enable the feature.

Sync to SCM Master Key

Use the centralized workflow to configure a single master key for your tenant and synchronize it to all managed firewalls. This is the recommended approach for replacing the default master key before the grace period expires.
  1. Log in to Strata Cloud Manager.
  2. Select System SettingsDevice Management.
    The Cloud Managed Devices tab displays the device table with master key status columns including Status, Master Key Managed By SCM, Grace Period, Updated At, Last Sync Status, Device Status, and Bootstrap Status.
    The Device Management toolbar displays the following master key actions depending on what is enabled for your tenant:
    • Master Key Actions dropdown (includes Update SCM Master Key and Sync to SCM Master Key)—Appears when centralized master key management is enabled for your tenant.
    • Deploy Master Key button—This button is disabled (grayed out) when centralized master key management is active and the selected devices are already managed by Strata Cloud Manager.
  3. Select Master Key ActionsUpdate SCM Master Key.
    This creates a new master key version for the tenant. Firewalls that are already connected continue to use their current key until you synchronize the new key to them.
  4. Choose a generation method:
    • Auto-generate (Recommended)—Strata Cloud Manager generates a secure 16-character key and stores it in a vault. The master key lifetime is set to the maximum value. Use this option when you do not need to know the key value and plan to keep the firewalls managed by Strata Cloud Manager.
    • Provide Custom Key—Manually enter a 16-character alphanumeric key (A-Z, a-z, 0-9). Use this option when you need to know the key value, for example, if you plan to offboard firewalls from Strata Cloud Manager in the future.
    If you use the auto-generate option and later offboard a firewall from Strata Cloud Manager, you will not have the key value needed to change the master key on that firewall. Before offboarding a firewall, update the master key to a known custom key and synchronize it to the firewall.
  5. (Custom Key only) Configure the following fields:
    • Enter the 16-character key value in Enter Custom Master Key. The key must be exactly 16 alphanumeric characters (A-Z, a-z, 0-9).
    • Set the Master Key Lifetime — the duration (in hours) before the key must be rotated.
    • Set the Update Reminder — the number of hours before expiry that Strata Cloud Manager displays a reminder to rotate the key.
  6. Select Save.
  7. Select one or more firewalls in the device table, then select Master Key ActionsSync to SCM Master Key.
    The sync dialog adapts based on each device's master key status:
    • If a device is on the default master key or its key is already managed by Strata Cloud Manager, no key input is required. The Current Master Key Input column displays "Not required (known by SCM)."
    • If a device has a locally configured custom key that is not managed by Strata Cloud Manager, you must enter the device's current master key value. The Current Master Key Input column displays a text field.
    The dialog displays the selected firewalls with the following columns:
    • Name—The firewall serial number.
    • Status—The current master key status.
    • Master Key Managed By SCM—Whether Strata Cloud Manager currently manages the key on this device.
    • Stored on HSM—Select this checkbox if the firewall stores the master key on a hardware security module (HSM).
    • Current Master Key Input—If the firewall has a locally-configured custom key that is unknown to Strata Cloud Manager, enter the current key value. If Strata Cloud Manager already knows the key (because it previously deployed it), this field displays "Not required (known by SCM)."
  8. Select Sync to SCM Master Key.
    Strata Cloud Manager pushes the master key to each selected firewall and commits the change. Monitor the Last Sync Status and Updated At columns to verify the operation completed successfully.
  9. Verify the sync was successful.
    After a successful sync:
    • The Status column shows Custom Key (green).
    • The Master Key Managed By SCM column shows Yes.
    • The Last Sync Status column shows Success.
    • The Updated At column shows the sync timestamp.
    If the Last Sync Status shows Failed, select the status link to view error details. Common causes include:
    • Invalid current master key—The key value you entered for a locally-managed device does not match the key on the firewall.
    • Pending configuration changes—The firewall has uncommitted changes. Revert pending changes on the firewall and retry the sync.
Master Key on First Connect (Bootstrap)—When you configure a Strata Cloud Manager master key before onboarding a new firewall, the firewall automatically receives the custom master key during the bootstrap process on first connect. After bootstrapping, the Status column shows Custom Key and Master Key Managed By SCM shows Yes. No additional sync action is required for newly bootstrapped firewalls.
Configure Grace Period and Auto-Renew Settings
Configure the default master key grace period and auto-renew lifetime as part of your device configuration. These settings are pushed to firewalls using the standard Push Config workflow. These fields appear under General Settings when the master key management feature is enabled for your tenant.
  1. Select ConfigurationNGFW and Prisma Access.
  2. Select the appropriate Configuration Scope:
    • All Firewalls—Applies to all managed firewalls (lowest precedence).
    • Folder—Applies to firewalls in a specific folder.
    • Snippet—Applies to firewalls associated with the snippet.
    • Device—Applies to a specific firewall (highest precedence).
  3. Select Network & DeviceDevice Setup.
  4. Under General Settings, select the settings icon and configure:
    • Auto Renew With Same Master Key—The interval (in hours or days) at which the firewall automatically renews the master key using the same value. This prevents the key from expiring and the firewall from entering maintenance mode. Set to 0 to disable auto-renewal (recommended when Strata Cloud Manager manages key rotation explicitly). A non-zero value means the firewall automatically renews the key lifetime at the specified interval without generating a new key — the device remains synchronized with Strata Cloud Manager.
    • Default Master Key Grace Period (days)—The number of days (60 to 120) before a firewall using the default key triggers a commit failure (PAN-OS 12.2.2 and later). Defaults to 60 days if not configured.
  5. Select OK to save the settings.
  6. Select Push Config to push the configuration to the target firewalls.
Master key settings follow the Strata Cloud Manager configuration scope hierarchy. If you configure settings at a higher scope (for example, All Firewalls), lower scopes (Device) inherit those values — the General Settings panel displays "Inherited from [scope name]." If you then configure the settings at an intermediate scope (for example, Snippet), the Device scope inherits from the Snippet instead. Settings configured at a higher scope are inherited by firewalls at lower scopes unless overridden. Precedence order (lowest to highest): All Firewalls, Folder, Snippet, Device.
Load a Local Configuration Version
The Local Config Management option is available in the per-device Actions menu when this feature is enabled for your tenant. This feature allows you to load a previous local configuration version snapshot on a firewall from Strata Cloud Manager.
Local configuration version snapshots represent the local firewall running configuration only — they do not include the SCM-pushed configuration. If you pushed a master key from Strata Cloud Manager to a device, any secrets in the local configuration are encrypted using that master key version. When you load a previous configuration version, Strata Cloud Manager must supply the correct key to decrypt those secrets.
Strata Cloud Manager handles this automatically based on the device's master key status:
  • Key managed by Strata Cloud Manager—If Strata Cloud Manager knows the master key version that was active when the configuration snapshot was captured, it automatically sends that key version as part of the load operation. No user action is required.
  • Locally configured key unknown to Strata Cloud Manager—If the device has a locally configured master key that Strata Cloud Manager does not know about, you must enter the key value before loading the configuration.
This capability requires PAN-OS 12.2.2 or later. For firewalls running earlier versions, load the configuration locally using the CLI command load config key <value>.
  1. Select System SettingsDevice ManagementCloud Managed Devices.
  2. Locate the firewall and select the Actions menu (three dots).
  3. Select Local Config Management.
  4. In the Local Config Version Snapshots dialog, locate the version you want to restore.
  5. Select Load for the desired version.
    A confirmation dialog box appears.
  6. Select Load.
    Strata Cloud Manager automatically supplies the correct master key version if the key was managed by Strata Cloud Manager when the snapshot was captured.

Deploy a Master Key to Individual Firewalls (Legacy)

Use this per-device method only if you need to manage individual device keys independently of the centralized Strata Cloud Manager workflow. Keys deployed through this action are not stored or tracked by Strata Cloud Manager.
For centralized key lifecycle management, use the Sync to SCM Master Key workflow instead.
  1. Log in to Strata Cloud Manager.
  2. Select System SettingsDevice Management.
    The Device Management page displays the firewalls.
  3. Select the required firewalls, click Deploy Master Key and edit the Deploy Master Key section.
  4. Enter the Current Master Key if one exists.
  5. Define a new New Master Key, and then Confirm New Master Key. The key must contain exactly 16 characters.
  6. To specify the master key Lifetime, enter the number of Days or Hours after which the key expires.
    Configure a new master key before the current one expires. You can set the lifetime of the master key from 1 to 18,250 days. If the master key expires, the firewall automatically reboots in Maintenance mode. Then, you must reset the NGFW to factory default settings.
    Set the Lifetime to two years or less, depending on how many encryptions the device performs. The more encryptions a device performs, the shorter the Lifetime you should set. The critical consideration is to not run out of unique encryptions before you change the master key. Each master key can provide up to 232 unique encryptions based on the master key value and the Initialization Vector (IV) value. After 232 unique encryptions, encryptions repeat (are no longer unique), which is a security risk.
    Set a Time for Reminder value (see next step) for the master key and when the reminder notification occurs, change the master key.
  7. Enter a Time for Reminder that specifies the number of Days and Hours before the master key expires when the firewall generates an expiration alarm. The firewall automatically opens the System Alarms dialog to display the alarm.
    Set the reminder so that it gives you plenty of time to configure a new master key before it expires in a scheduled maintenance window. When the Time for Reminder expires and the firewall sends a notification log, change the master key, do not wait for the Lifetime to expire.
  8. (Optional) For added security, select whether to use an HSM to encrypt the master key. For details, see Encrypt and Refresh Master Keys Using an HSM.
  9. Click Deploy Master Key.
    Keys deployed using this method are not tracked as Strata Cloud Manager-managed. The Master Key Managed By SCM column displays No for these devices and the Updated At and Last Sync Status columns are not populated.