<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Add Device Authentication Failure in Expedition Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/expedition-discussions/add-device-authentication-failure/m-p/528380#M4361</link>
    <description>&lt;P&gt;I did both.&amp;nbsp; Added a new user account with API read permissions, as well as removing the special character.&amp;nbsp; Thank you sir!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 24 Jan 2023 17:20:09 GMT</pubDate>
    <dc:creator>M.Anderson</dc:creator>
    <dc:date>2023-01-24T17:20:09Z</dc:date>
    <item>
      <title>Add Device Authentication Failure</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/add-device-authentication-failure/m-p/522797#M4290</link>
      <description>&lt;P&gt;More of an advice posting than a request for assistance.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do not make your PA firewall admin password really crazy long and complex (like I did ~ at 19 characters long).&lt;/P&gt;
&lt;P&gt;If you do, you might get tripped up by Expedition when you try and add a device and the user API keys.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Background:&lt;/P&gt;
&lt;P&gt;New PA-440 Firewall (FW)&lt;/P&gt;
&lt;P&gt;Stood up Expedition VM on Monday the 21st.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I kept getting "Invalid Credential" in Expedition when trying to add the API key for admin with my crazy long complex pwd.&lt;/P&gt;
&lt;P&gt;I was able to SSH from the Ubuntu Server to the FW using admin with its 19-character long password so was greatly puzzled why Expedition was bombing out. Even opened a case on PA support. Lots of inconclusive results found.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After a zoom session a short time ago with my local PA VAR and a SE with PA, I found a clue to a possible solution in the /home/userSpace/devices/debug.txt file: only part of that long booger of a pwd was being transmitted to the FW so of course(!) authentication is going to fail! As an aside, I find it curious that the pwd used is in clear text in the debug.txt file!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After changing my FW admin pwd to something that _just_ meets the security requirements (8 long, one cap, 5 lower and 2 bangs), committing, signing out of everything, signing back into Expedition, adding my device and using the shorter admin pwd, the add succeeded and the 3 keys were populated!&lt;/P&gt;</description>
      <pubDate>Tue, 29 Nov 2022 22:36:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/add-device-authentication-failure/m-p/522797#M4290</guid>
      <dc:creator>UNMPDgordon</dc:creator>
      <dc:date>2022-11-29T22:36:34Z</dc:date>
    </item>
    <item>
      <title>Re: Add Device Authentication Failure</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/add-device-authentication-failure/m-p/528026#M4355</link>
      <description>&lt;P&gt;I'm running into the same issue.&amp;nbsp; PWD = 9 characters, upper case, lower case, number, special character #&lt;/P&gt;
&lt;P&gt;Any recommendations?&lt;/P&gt;</description>
      <pubDate>Fri, 20 Jan 2023 21:44:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/add-device-authentication-failure/m-p/528026#M4355</guid>
      <dc:creator>M.Anderson</dc:creator>
      <dc:date>2023-01-20T21:44:54Z</dc:date>
    </item>
    <item>
      <title>Re: Add Device Authentication Failure</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/add-device-authentication-failure/m-p/528032#M4356</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/79377"&gt;@M.Anderson&lt;/a&gt;&amp;nbsp;Try to remove the special character and try again, if it's still not working, you can try create a new user account on the firewall and assign the API read permission.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Jan 2023 22:32:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/add-device-authentication-failure/m-p/528032#M4356</guid>
      <dc:creator>lychiang</dc:creator>
      <dc:date>2023-01-20T22:32:32Z</dc:date>
    </item>
    <item>
      <title>Re: Add Device Authentication Failure</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/add-device-authentication-failure/m-p/528380#M4361</link>
      <description>&lt;P&gt;I did both.&amp;nbsp; Added a new user account with API read permissions, as well as removing the special character.&amp;nbsp; Thank you sir!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jan 2023 17:20:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/add-device-authentication-failure/m-p/528380#M4361</guid>
      <dc:creator>M.Anderson</dc:creator>
      <dc:date>2023-01-24T17:20:09Z</dc:date>
    </item>
    <item>
      <title>Re: Add Device Authentication Failure</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/add-device-authentication-failure/m-p/573199#M4891</link>
      <description>&lt;P&gt;any resolution to this? I've tried username/password, api login, removal of special characters, etc&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jan 2024 15:35:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/add-device-authentication-failure/m-p/573199#M4891</guid>
      <dc:creator>AnthonyPacheco</dc:creator>
      <dc:date>2024-01-16T15:35:23Z</dc:date>
    </item>
    <item>
      <title>Re: Add Device Authentication Failure</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/add-device-authentication-failure/m-p/573210#M4892</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/302615"&gt;@AnthonyPacheco&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Try to execute the external command and later in Expedition create the device and add directly the created API_KEY&lt;/P&gt;
&lt;DIV&gt;
&lt;DIV class="code-btn-container"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;
&lt;PRE class="pre codeblock " data-label="PRE CODEBLOCK"&gt;curl -H &lt;SPAN class="hljs-string"&gt;"Content-Type: application/x-www-form-urlencoded"&lt;/SPAN&gt; -X POST https://firewall/api/?&lt;SPAN class="hljs-built_in"&gt;type&lt;/SPAN&gt;=keygen &lt;SPAN class="hljs-_"&gt;-d&lt;/SPAN&gt; &lt;SPAN class="hljs-string"&gt;'user=&amp;lt;user&amp;gt;&amp;amp;password=&amp;lt;password&amp;gt;'&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;P&gt;Reference article:&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/pan-os-api-authentication/get-your-api-key" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/pan-os-api-authentication/get-your-api-key&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;David&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jan 2024 17:05:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/add-device-authentication-failure/m-p/573210#M4892</guid>
      <dc:creator>dpuigdomenec</dc:creator>
      <dc:date>2024-01-16T17:05:33Z</dc:date>
    </item>
  </channel>
</rss>

