: Restore an Expired Device Certificate
Focus
Focus

Restore an Expired Device Certificate

Table of Contents
End-of-Life (EoL)

Restore an Expired Device Certificate

Restore an expired device certificate on your Panorama™ management server, Dedicated Log Collector, or managed firewalls.
The device certificate installed on your Panorama™ management server, Dedicated Log Collector, or managed firewalls have a 90 day lifetime. Panorama, Dedicated Log Collectors, and managed firewalls with the device certificate installed automatically attempt to reinstall the device certificate 15 days before the certificate expires. However, you have the ability to manually reinstall the device certificate if it fails to reinstall automatically.
  1. Review the device certificate status for Panorama, Dedicated Log Collectors, and managed firewalls.
    1. To review the Panorama device certificate status, select PanoramaSetupManagement and review the Current Device Certificate Status in the Device Certificate Section.
      The Current Device Certificate Status displays Expired.
    2. To review the Dedicated Log Collector device certificate status, log in to the Dedicated Log Collector CLI and enter the following command:
      admin>show device-certificate status
      The Current Device Certificate Status displays Expired.
    3. To review the managed firewall device certificate status, select PanoramaManaged FirewallsSummary and filter for expired.
      The Device Certificate column displays the current Expired device certificate status.
  2. Reinstall the expired device certificate on Panorama, Dedicated Log Collectors, or managed firewalls.
    If the request certificate fetch otp <otp_value> command is not available, it means the Panorama, Log Collector, or managed firewall is a Trusted Platform Module (TPM) device.
    To restore the device certificate for a TPM device, run the following command:
    request certificate fetch