Coming soon - Get a detailed view of why an account is flagged as spam!
view details

This post has been de-listed

It is no longer included in search results and normal feeds (front page, hot posts, subreddit posts, etc). It remains visible only via the author's post history.

0
Palo USER-ID certs - and HA
Post Flair (click to view more posts with a particular flair)
Author Summary
jkw118 is in Idaho
Post Body

So I'm installing new user-ID agents on new DC's and from everything I've read so far, palo didn't provide correct builtin certs. And the answer is to create new (self signed / microsoft CA certs) and use those. Which of course their's no instructions for what really needs to get done.

So if I understand it correctly I need to have the palo create a cert request, have it filled by my CA.. As well as for each DC. then convert it to PEM so I can get it into each of these. And since my palo is in HA (active/passive) I need a cert for each one? right.

And then on the CA side of things (which I'm sure is outside of the PAlo side of things (I have a XXX.local for internal stuff, but then externally I have a xxx.org (which is also used for some internal servers that arent' externally available. Can my CA even give out certs for it? (I'm sure I can get around it, but it makes everything weird as the palo has it's hostname as the .org for several of it's settings..

Author
Account Strength
100%
Account Age
6 years
Verified Email
Yes
Verified Flair
No
Total Karma
8,615
Link Karma
587
Comment Karma
7,918
Profile updated: 3 days ago
Posts updated: 5 months ago

Subreddit

Post Details

Location
We try to extract some basic information from the post title. This is not always successful or accurate, please use your best judgement and compare these values to the post title and body for confirmation.
Posted
10 months ago