---
sourceDocument: Yokohama Security Management
sourceDocumentLink: https://www.servicenow.com/docs/r/yokohama/security-management

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Create a certificate profile for the Palo Alto Networks Next-Generation Firewall

# Create a certificate profile for the Palo Alto Networks Next-Generation Firewall {#ariaid-title1}

* Release version: Yokohama
* 
* Updated January 30, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

The integration requires a certificate profile to validate and authenticate the
secure connection between the ServiceNow AI Platform® server and the Palo Alto Networks Next-Generation Firewall
server.
Role required: Palo Alto Networks Next-Generation Firewall Administrator.
A Palo Alto Networks Next-Generation Firewall authenticates to a ServiceNow AI Platform® instance, retrieves EDL entries from the database table, and incorporates the entries into corresponding firewall policy rules. This retrieval requires the API user account role in the ServiceNow AI Platform® instance, which is used by the PAN firewall admin to access the ServiceNow AI Platform® API.

Follow the steps below on how to download DigiCertificates and configure the certificate profile.

1. Download DigiCert or Entrust CA Gateway Certificate based on the use case. For more information, see the [KB1702083](https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB1702083) article in the Now Support Knowledge Base.
2. Configure the certificate profile. For more information, see [Palo Alto Networks documentation](https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-admin/certificate-management/configure-a-certificate-profile).
{#paloalto-create-cert-profile__steps_nxd_23v_mdc}
**Previous topic:** [Palo Alto Networks Next-Generation Firewall integration](https://www.servicenow.com/docs/XXkmuUtILzqsR2QMP55hZw "Once installed and configured, the security incident analyst uses this integration to block malicious IP addresses, URLs, and domains using External Dynamic List (EDL) capabilities with the ServiceNow Security Incident Response (SIR) products. The security incident analyst creates entries for an EDL from observables determined to be malicious on ServiceNow SIR security incidents.")  
**Next topic:** [Set up and install Palo Alto Networks Next-Generation Firewall](https://www.servicenow.com/docs/mf_0KeIhLFmOJQ4JZ5RAQg "Complete the following setup checklist prior to installation. These setup tasks are required for a smooth installation.")  
**Related topics**   

* ["Configure a Certificate Profile" in the PAN-OS 10.0 Administrator's
  Guide](https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-admin/certificate-management/configure-a-certificate-profile)

