Learn how to configure a unique master key to secure all private keys and passwords
in a particular configuration.
| Where Can I Use This? | What Do I Need? |
|
|
One of these licenses for Strata Cloud Manager managed NGFWs:
- Strata Cloud Manager Essentials
- Strata Cloud Manager Pro
|
A
master key encrypts all private keys and passwords in a configuration to
secure them (such as the private key used for SSL Forward Proxy decryption). Every
Next-Generation Firewall (NGFW), Panorama appliance, log collector, and WF-500
appliance has a default master key.
Master key requirements vary by deployment:
In a high availability (HA) configuration, both NGFWs or Panorama appliances
must use the same master key since keys are not synchronized across HA
peers. Otherwise, HA synchronization will not work properly.
If you're using Panorama to manage your NGFWs, you can either configure the
same master key on Panorama and the managed NGFWs or configure a unique
master key for each managed NGFW. The most secure option is to configure a
unique master key for Panorama and each managed NGFW. This limits the
security impact of a compromised master key. See
Manage the Master Key from
Panorama if your NGFWs are managed by a Panorama
appliance.
Unique master keys are supported only for Panorama and managed NGFWs. Log
collectors and WF-500 appliances must share the same master key as
Panorama.
Change the default master key as soon
as possible to ensure that you use a unique master key for
encryption.
(PAN-OS 12.2.2 and later
releases) PAN-OS 12.2.2 enforces replacement of the default master
key with a custom master key within a specific grace period. Configure a
custom master key before the 60-day default grace period expires. See
Default Master Key Replacement below for full details.
Default Master
Key Replacement
(PAN-OS 12.2.2 and later
releases)
The default master key is publicly known
and poses a critical security risk. Starting with PAN-OS 12.2.2, the system enforces
replacement of the default master key with a custom master key within a configurable
grace period.
When the system detects the default
master key, a 60-day grace period begins automatically. If you need additional time,
you can extend the grace period to a maximum of 120 days, but you must configure
this extension before the current grace period expires. This 120-day limit is
absolute and measured from the original trigger event — an upgrade, factory reset,
or first power-on. The extension does not add a new window from the date you
configure it. The system always calculates the final deadline from the date of the
original trigger event, regardless of when you configure the extension. You cannot
extend the grace period beyond 120 days under any circumstances.
After the grace period expires, the
system blocks all standard configuration commits, commit-all jobs, and HA
synchronization until you configure a custom master key. Auto-commits and dynamic
updates, including content and antivirus deployments, continue to operate normally
during this blocked state.
Palo Alto Networks
strongly recommends configuring a custom master key immediately after upgrading
to PAN-OS 12.2.2. Do not wait for the default grace period of 60 days to
approach expiry.
The countdown begins when any
of the following trigger events are detected:
You upgrade a device to PAN-OS 12.2.2 or a later version.
You restore a device running PAN-OS 12.2.2 or a later version to
factory default settings.
You power on a new factory-default device running PAN-OS 12.2.2 or
a later version for the first time.
If a grace period timer is already running, upgrading or downgrading
between PAN-OS 12.2.2 and later versions does not restart the timer. If the
grace period has already expired and you downgrade to another PAN-OS 12.2.2 or
later release, the timer does not restart and commits fail immediately on the
downgraded version.