Skip to main content

Paloalto firewalls use internal ssl certificates. It should be important to monitor this certificates through SSH:

admin@fw01-bz> show sslmgr-store config-certificate-info

AF05329B:A856B404C25A48A0C02F0A7A3A2036925B9BA5C2
serial number:
issuer: /CN=81.161.232.189
issuer-subjecthash: A856B404C25A48A0C02F0A7A3A2036925B9BA5C2
issuer-keyhash:
db-type: V
db-exp-date: 321008075404Z(Oct 8 07:54:04 2032 GMT)
db-rev-date: ()
db-serialno: AF05329B
db-file: unknown
db-name: /CN=vpn.i-vertix.com
db-status: V

7CE5E3F56B1AB38C4D0BC440823B9E9:273F5E283B4F4D0879716CD0E32A886B8195C0F3
serial number:
issuer: /CN=Microsoft Azure Federated SSO Certificate
issuer-subjecthash: 273F5E283B4F4D0879716CD0E32A886B8195C0F3
issuer-keyhash:
db-type: V
db-exp-date: 251011072048Z(Oct 11 07:20:48 2025 GMT)
db-rev-date: ()
db-serialno: 7CE5E3F56B1AB38C4D0BC440823B9E99unknown
db-file: unknown
db-name: /CN=Microsoft Azure Federated SSO Certificate
db-status: V

AF05329A:A856B404C25A48A0C02F0A7A3A2036925B9BA5C2
serial number:
issuer: /CN=81.161.232.189
issuer-subjecthash: A856B404C25A48A0C02F0A7A3A2036925B9BA5C2
issuer-keyhash:
db-type: V
db-exp-date: 321008075349Z(Oct 8 07:53:49 2032 GMT)
db-rev-date: ()
db-serialno: AF05329A
db-file: unknown
db-name: /CN=81.161.232.189
db-status: V


admin@fw01-bz>
NewDiscussion ongoing

Discussion ongoingNeeds Votes

Hello,

It would be interesting to be able to check using the firewall API rather than SSH/SNMP too, as some competitors do (EV Observe ..). Thanks


Hello ​@RDPrevi :)

We're totally considering handling this idea (and idea 3224 ) using the Palo Alto Rest API, as discussed with ​@joschi99. We've decided to segment by doing a first release on the current scope of the SSH plugin. And then we'd like to add improvements as suggested in the two ideas and why not identify other API endpoints of interest.

Best regards.