|
Answer» The basic methods for deploying certificates for Palo Alto Network Firewalls are: - OBTAIN certificates from a reputable third-party certificate authority (CA): Because many browsers include root CA certificates from well-known CAS in their trusted root certificate stores, getting a certificate from a trusted third-party certificate authority (CA) like VeriSign or GoDaddy has the advantage of end CLIENTS already trusting the certificate.
- Obtain certificates from an enterprise CA: Enterprises with their own INTERNAL CA can utilise it to create and import certificates for firewall applications.
- Create a Self-Signed Root CA Certificate: You can create a Self-Signed Root CA Certificate on the firewall and use it to automatically issue certificates for other firewall apps by creating a Self-Signed Root CA Certificate.
|