Palo Alto Networks Pan-Os
SSLNexus can manage externally signed certificates on Palo Alto Networks firewalls and Panorama through the PAN-OS HTTPS management API. The certificate private key remains on the appliance.
Requirements
- HTTPS management/API reachability from the SSLNexus server.
- A PAN-OS API key with permission to manage certificates and commit the required configuration.
- The certificate object name and its scope: a specific
vsysor Shared. - For Panorama, the template and, where used, template stack that owns and distributes the certificate configuration.
- The client-facing FQDN and SANs the certificate must protect.
Palo Alto Networks documents case-sensitive names using letters, numbers, hyphens and underscores, with a maximum of 63 characters on a firewall and 31 characters on Panorama.
Add The Target
- Open Deployment targets and choose Network appliance / HTTPS API.
- Select Palo Alto Networks PAN-OS.
- Enter the firewall or Panorama management address, API port and API key.
- Enter the certificate object name and choose its vsys or Shared scope.
- If Panorama is used, enter the template, template vsys where applicable, and the template stack used by the managed firewalls. If your deployment pushes a template directly, the stack can be left blank.
- Optionally record the SSL/TLS Service Profile when managing a firewall directly. SSLNexus can use it as a safety check before committing a renewal.
- Select the required RSA size and digest, configure the target CA, then run Test target and Test CA.
Management Certificate Trust
PAN-OS frequently begins with a self-signed management certificate. If the management certificate is not yet trusted by the SSLNexus server, enable the bootstrap trust exception on the target only for as long as required. Disable it after a trusted management certificate is installed.
Common Name And SANs
Use the FQDN clients actually connect to. Palo Alto Networks requires the Host Name certificate attribute to match the Common Name for GlobalProtect, so make sure the SSLNexus certificate identity reflects the real portal or gateway name.
Renewal And Commit
SSLNexus retains the configured certificate object and scope for later renewals. For direct firewalls, accepted certificate updates are committed on the appliance. For Panorama-managed deployments, SSLNexus also pushes the configured template or template stack and waits for Panorama to report a successful result before recording the deployment as complete.
SSLNexus does not silently change an unexpected production service-profile relationship. Review inherited Panorama template and template-stack policy in a non-production environment before broad rollout.
Palo Alto Networks References
The integration follows Palo Alto Networks guidance for externally signed certificates, certificate management through the XML API, certificate import, commit operations and Panorama commit-all operations.

