FAQs
How to Generate a CSR on a Palo Alto Networks Firewall
Overview
By following this article, you will create a Certificate Signing Request (CSR) on a Palo Alto Networks firewall and export it in a format you can submit to Sectigo during SSL/TLS certificate enrollment.
The article covers the prerequisites you need, the eight steps of the procedure, including signing in to the firewall, opening Certificate Management, entering certificate details such as the Common Name (CN) and Fully Qualified Domain Name (FQDN), adding certificate attributes, generating the request, exporting the file, and using it for enrollment.
A CSR is an encoded text block containing your organization's details and public key. The matching private key is created at the same time and remains securely stored on the firewall.
Prerequisites
- Administrative access to the Palo Alto Networks firewall web management interface.
- A valid Fully Qualified Domain Name (FQDN) for the certificate.
- The full legal name and registered address of your organization.
Steps
Step 1 – Sign in to the Palo Alto Networks Firewall
- Open a web browser.
- Go to the address of your Palo Alto Networks firewall web management interface.
- Sign in using your administrator credentials.
Step 2 – Open the Certificates Page
- Click the Device tab.
- Expand Certificate Management in the navigation pane.
- Select Certificates.
Figure 1: Palo Alto Networks Device tab with Certificate Management expanded and Certificates selected
Step 3 – Open the Generate Certificate Window
- Scroll to the bottom of the Certificates page.
- Click Generate.
Figure 2: Generate button at the bottom of the Palo Alto Networks Certificates page
Step 4 – Enter the Certificate Details
| Field | Value to Enter |
|---|---|
| Certificate Type | Local |
| Certificate Name | A friendly name such as example_ssl_cert |
| Common Name (CN) | The FQDN to secure, such as www.yoursite.com |
| Signed By | External Authority (CSR) |
| Certificate Authority | Leave blank |
| OCSP Responder | Leave the default setting |
| Algorithm | RSA or ECDSA |
| Number of Bits | 2048 |
| Digest | SHA-256 |
| Expiration (Days) | Leave blank |
Note: For a wildcard certificate, prefix the domain name with an asterisk, for example *.yoursite.com.
Step 5 – Add the Certificate Attributes
| Attribute | Value to Enter |
|---|---|
| Country | Two-letter ISO country code (for example, US) |
| State | Full state name (for example, Hawaii) |
| Locality | Full city name (for example, Honolulu) |
| Organization | Full legal company name |
Figure 3: Certificate Attributes section of the Generate Certificate window
Step 6 – Generate the CSR
- Review all entered information.
- Leave Certificate Authority blank.
- Click Generate.
Important: The private key remains stored on the Palo Alto Networks firewall and is not exported.
Figure 4: Completed Generate Certificate window with the Generate button ready to be clicked
Step 7 – Export the CSR File
- Locate the certificate you created.
- Select the certificate checkbox.
- Click Export.
Figure 5: Certificates page with the new certificate selected and the Export button at the bottom
Step 8 – Use the CSR for SSL/TLS Certificate Enrollment
- Open the exported CSR file in a text editor.
- Copy the complete CSR content, including BEGIN CERTIFICATE REQUEST and END CERTIFICATE REQUEST.
- Paste the CSR into the CSR field during certificate enrollment with Sectigo.
How to Verify Success
- The Certificate Authority accepts the CSR without errors.
- The signed certificate appears under Device → Certificate Management → Certificates after import.
- SSL/TLS services such as GlobalProtect function without certificate warnings.
Important Notes
- The private key must never be shared.
- If the private key is lost, generate a new CSR and request a replacement certificate.
- The Common Name (CN) must exactly match the FQDN being secured.
Similar Questions
- How do I create a CSR on a Palo Alto Networks firewall?
- What are the steps to request an SSL/TLS certificate for a Palo Alto Networks firewall?
- How do I export a certificate signing request from a Palo Alto Networks device?
- Palo Alto Networks firewall CSR generation for a wildcard certificate.
- Where is Certificate Management on a Palo Alto Networks firewall?
Related Articles:
How to install the SSL Certificate into a Palo Alto Firewall | Sectigo® Official
Need assistance?
Contact our team for help with your purchase or issuing your certificate.