6.5.12 Palo Alto
Import the certificate through the PAN-OS API, commit, and optionally push to firewalls
The Palo Alto templates import the certificate, private key, and intermediate chain through the PAN-OS XML API, then request a commit.
| Template | Use it for | Agent |
|---|---|---|
| Palo Alto Firewall (PAN-OS API) | A firewall you manage directly. | Windows or Linux |
| Palo Alto Panorama (PAN-OS API) | Certificates used by Panorama itself, such as its management interface. | Windows |
| Palo Alto Panorama Template (PAN-OS API) | Certificates in Panorama Templates, with an optional push to managed firewalls. | Windows |
Requirements
- The agent host must reach the firewall or Panorama management address over HTTPS.
- The admin account’s role must allow XML API Import and Commit. The Panorama Template template also needs XML API Configuration, plus Operational Requests if it pushes to firewalls.
- Set New or existing certificate name to update to the certificate you want replaced, or a new name for the first deployment.
Reuse the certificate name on renewal to preserve references from SSL/TLS Service Profiles and GlobalProtect. If you create a new name, bind it to the service after the first deployment.
The commit includes every pending change on the device, not just CertKit’s. If other admins leave uncommitted changes, a scheduled renewal will commit them too.
Panorama Templates
Set Template name(s) to the comma-separated names from Panorama > Templates. Names are case-sensitive. CertKit validates them before making changes, then imports the certificate under Template > Shared for each Template.
Use Template Stack Name(s) to push to select the stacks for deployment to firewalls.
Pushing to firewalls
The certificate reaches managed firewalls only after a push.
- Leave Template Stack Name(s) to push as
noneto stop after the Panorama commit. Push later with Commit > Push to Devices. - Enter one or more Template Stack names to push automatically. CertKit waits for the Panorama commit to finish (up to 20 minutes), then pushes each stack. The push sends everything pending in that stack, not only the certificate.
CertKit starts the push but does not wait for it to finish. Check the result under Tasks in Panorama.
Intermediate certificates
The upload includes the intermediate chain. PAN-OS may not show the intermediates as separate certificate entries in the management UI.
Common problems
- Upload works but the commit fails: check that the role has Commit permission, and look for other pending changes blocking the commit.
- Panorama deployment succeeds but nothing was committed: without a push, a failed Panorama commit is logged, not treated as an error. Check Commit status in the deployment output and Tasks in Panorama.
- Traffic still uses the old certificate: check that the service profile or setting points at the certificate name CertKit updates.
- Sign-in works but the upload is denied: API access alone isn’t enough. The role also needs the Import permission.
- Can’t connect to the management address: check the hostname or IP, that HTTPS management is enabled, and routing from the agent host.
- “Could not find these Panorama Templates”: a name doesn’t match a Template exactly. Nothing was changed.
- “Failed to query Panorama Templates”: the role is missing XML API Configuration permission.
- “Failed to query Panorama commit job”: the role is missing XML API Operational Requests permission, which pushing needs.
- “Panorama returned success but no commit job ID”: Panorama didn’t start a commit, so CertKit didn’t push. Commit and push by hand, then run the deployment again.
- “Panorama commit failed (cannot push to devices)”, or the commit job times out or fails: fix the commit problem in Panorama under Tasks. CertKit only pushes after a successful commit.
- “Template Stack … push request failed”: check the stack name and that the role has Commit permission.
- Firewalls still have the old certificate: check that a push ran and succeeded, and that the firewall belongs to that Template Stack.
For a product overview, see certificate automation for Palo Alto firewalls.