---
title: "Replacing/Uploading Certificates"
slug: "replacinguploading-certificates"
updated: 2022-05-24T15:09:00Z
published: 2022-05-24T15:09:01Z
canonical: "kb.expedient.com/replacinguploading-certificates"
---

> ## Documentation Index
> Fetch the complete documentation index at: https://kb.expedient.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Replacing/Uploading Certificates

File Upload IssueIf you encounter an error when attempting to upload files through Panorama, please open an [SMC ticket](https://support.expedient.com/) with the OSC for assistance.

## Overview

By default, Expedient configures GlobalProtect utilizing the [expedient.com](http://expedient.com) wildcard certificate. If preferred, a client can substitute the [expedient.com](http://expedient.com) wildcard with their own certificate. If a client chooses to use a non-Expedient managed certificate, it is the client's responsibility to manage that certificate. While Expedient may not manage the certificate., Expedient provides this documentation to assist clients with getting started on uploading and renewing their own certificates.

### Prerequisites

The steps described in this document assume that the firewall hosting GlobalProtect has had the GlobalProtect Gateway & Portal configuration sections completed.

### Process

You can use the following process to upload a first-time certificate or replace an existing one.

1. Navigate to primary node firewall UI after successfully authenticating into fw.expedient.cloud.

2. Select **Device** > **Certificate Management** > **Certificates** > **Device Certificates** > **Import**

3. Import the appropriate certificate/key. In our example, we're importing the expedient.cloud certificate.

**"Block Private Key Export" must be selected when configuring the certificate.**

**![](https://cdn.document360.io/69e9f9c7-5da8-45e7-a671-4b8287f36122/Images/Documentation/replacinguploading-certificates-image-o7aeoqd3.png)**

4. Create an SSL/TLS service profile using the certificate you've imported. Select **Device** > **Certificate Management > SSL/TLS Service Profile > Add**

**"TLSv1.2" must be selected when configuring the certificate & SSL/TLS profile.**

**![](https://cdn.document360.io/69e9f9c7-5da8-45e7-a671-4b8287f36122/Images/Documentation/replacinguploading-certificates-image-3sxuiosv.png)**

5. Apply service profile to GlobalProtect gateway. Select **Network > GlobalProtect > Gateways >** Click link for gateway > **Authentication >** Select appropriate SSL/TLS profile from **Server Authentication** drop-down > Click **OK**

**![](https://cdn.document360.io/69e9f9c7-5da8-45e7-a671-4b8287f36122/Images/Documentation/replacinguploading-certificates-image-20o9w1ho.png)**

6. Apply service profile to GlobalProtect portal. Select **Network** > **GlobalProtect > Portals >** Click link for portal > **Authentication >** Select appropriate SSL/TLS profile from **Server Authentication** drop-down **>** Click **OK**

**![](https://cdn.document360.io/69e9f9c7-5da8-45e7-a671-4b8287f36122/Images/Documentation/replacinguploading-certificates-image-24ln2d47.png)**

7. Perform a firewall **Commit** operation to commit your changes.

![](https://cdn.document360.io/69e9f9c7-5da8-45e7-a671-4b8287f36122/Images/Documentation/replacinguploading-certificates-image-3an2sjcc.png)
