©
Palo
Alto
Networks,
Inc.
Panorama
6.1
Administrator’s
Guide
•
79
Set
Up
Panorama
Set
Up
Administrative
Access
to
Panorama
Step
3
Create
or
modify
an
administrator
account
to
enable
client
certificate
authentication
on
the
account.
1.
Select
Panorama > Administrators
and
then
click
Add
.
2.
Enter
a
login
name
for
the
administrator;
the
name
is
case
‐
sensitive.
3.
Select
Use only client certificate authentication (Web)
to
enable
the
use
of
the
certificate
for
authentication.
4.
Select
the
Role
to
assign
to
this
administrator.
You
can
either
select
one
of
the
predefined
dynamic
roles
or
select
a
custom
role
and
attach
an
authentication
profile
that
specifies
the
access
privileges
for
this
administrator.
5.
(Optional)
For
custom
roles,
select
the
device
groups,
templates
and
the
firewall
context
that
the
administrative
user
can
modify.
6.
Click
OK
to
save
the
account
settings.
Step
4
Create
the
Client
Certificate
Profile
that
will
be
used
for
securing
access
to
the
web
interface.
1.
Select
Panorama > Certificate Management > Certificate
Profile
and
click
Add
.
2.
Enter
a
name
for
the
certificate
profile
and
in
the
Username
Field
select
Subject
.
3.
Select
Add
in
the
CA
Certificates
section
and
from
the
CA
Certificate
drop
‐
down,
select
the
CA
certificate
you
just
created.
Step
5
Configure
Panorama
to
use
the
client
certificate
profile
for
authentication.
1.
On
the
Panorama > Setup
tab,
edit
the
Authentication
Settings.
2.
In
the
Certificate Profile
field,
select
the
client
certificate
profile
you
just
created.
3.
Click
OK
to
save
your
changes.
Step
6
Save
the
configuration
changes.
Click
Commit
and
select
Panorama
as
the
Commit Type
.
You
will
be
logged
out
of
the
device.
Step
7
Import
the
administrator's
client
certificate
into
the
web
browser
on
the
client
system
that
the
administrator
will
use
to
access
the
Panorama
web
interface.
For
example,
in
Firefox:
1.
Select
Tools > Options > Advanced
.
2.
Click
View Certificates
.
3.
Select
the
Your Certificates
tab
and
click
Import
.
Browse
to
the
location
where
you
saved
the
client
certificate.
4.
When
prompted,
enter
the
passphrase
to
decrypt
the
private
key.
Step
8
Verify
that
certificate
‐
based
authentication
is
configured.
1.
From
a
client
system
that
has
the
client
certificate
loaded,
access
the
Panorama
IP
address
or
hostname.
2.
When
prompted,
select
the
client
certificate
you
imported
in
.
A
certificate
warning
will
display.
3.
Add
the
certificate
to
the
exception
list
and
log
in
to
the
Panorama
web
interface.
Enable
Certificate
‐
Based
Authentication
for
the
Web
Interface
(Continued)