A remote administrator needs firewall access on an untrusted interface. Which two components are required on the firewall to configure certificate-based administrator authentication to the web Ul? (Choose two.)
Should be AD.
Generate a certificate authority (CA) certificate on the firewall.
https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/firewall-administration/manage-firewall-administrators/configure-administrative-accounts-and-authentication/configure-certificate-based-administrator-authentication-to-the-web-interface.html
A and D
Steps
Generate a certificate authority (CA) certificate on the firewall.
Configure a certificate profile for securing access to the web interface.
Configure the firewall to use the certificate profile for authenticating administrators.
Configure the administrator accounts to use client certificate authentication.
Generate a client certificate for each administrator.
Export the client certificate.
Import the client certificate into the client system of each administrator who will access the web interface.
Answers are A, D. As a more secure alternative to password-based authentication to the firewall web interface, you can configure certificate-based authentication for administrator accounts that are local to the firewall. Generate a certificate authority (CA) certificate on the firewall. You will use this CA certificate to sign the client certificate of each administrator. Configure a certificate profile for securing access to the web interface. Configure the firewall to use the certificate profile for authenticating administrators.
Question asks "required on the firewall" so it's A and D. Client certificate is required to be on the client device, not on the firewall. Firewall needs to trust client certificate which needs to be assigned by a CA that firewall trusts, therefore CA root certificate needs to be imported to firewall.
In the documentation:
https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/certificate-management/configure-an-ssltls-service-profile
It says: Use only signed certificates, not CA certificates, in SSL/TLS service profiles.
So I think it is C and D.
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Marcyy
Highly Voted 2 years, 7 months agohomersimpson
2 years, 6 months agoduckduckgooo
1 year, 3 months ago443Annny
Most Recent 3 weeks, 2 days ago123XYZT
1 month, 2 weeks agoWhizdhum
7 months agoAndromeda1800
7 months, 1 week agoAndromeda1800
7 months, 1 week agoKalipso21
1 year, 5 months agoDenskyDen
1 year, 5 months agoDenskyDen
1 year, 6 months agoAbuHussain
2 years, 3 months agoRamanJoshi
2 years, 5 months agoGivemeMoney
2 years, 6 months agodrrealest
2 years, 7 months agoJared28
2 years, 3 months agoPretorian
1 year, 11 months ago