Previously, in HA Active/Passive pairs with service routes configured for
Palo Alto Networks services or DNS servers, it was impossible to renew device
certificates on the passive device because the passive device's dataplane functions
are down. Starting with this PAN-OSĀ® release, the passive device can have service
routes configured and receive
certificate updates and renewals through
its HA interface connected to the active device. You do not have to configure or
change your network security policy to perform this function; the process happens
automatically when a certificate is near its expiry date. This allows your HA pair
to maintain up to date and secure connections with Palo Alto Networks licenses and
services even after a failover event.
You can verify if the passive device has successfully renewed a certificate
using the following CLI command:
show device-certificate status
.