<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN certificate error, Android versions in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/vpn-certificate-error-android-versions/m-p/580498#M5133</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/109368"&gt;@jchciazacarrion&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Please check the GP logs for more details but based on the error message it sounds like&amp;nbsp;the intermediate certificate is missing from the trusted certificate authority store on the android device.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Make sure the intermediate certificate is imported to the firewall.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;On the Portal &amp;gt; Agent &amp;gt; Trusted Root CA &amp;gt; Add &amp;gt; Add the Intermediate certificate (check the "Install in Local Root Certificate Store) This way when devices connect to the portal for the first time, this intermediate certificate will be pushed to the trusted certificate store.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also make sure to check the compatibility matrix to make sure it's not something as simple as an incompatibility:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/compatibility-matrix/globalprotect/where-can-i-install-the-globalprotect-app" target="_blank"&gt;https://docs.paloaltonetworks.com/compatibility-matrix/globalprotect/where-can-i-install-the-globalprotect-app&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind regards,&lt;/P&gt;
&lt;P&gt;-Kim.&lt;/P&gt;</description>
    <pubDate>Fri, 15 Mar 2024 11:19:01 GMT</pubDate>
    <dc:creator>kiwi</dc:creator>
    <dc:date>2024-03-15T11:19:01Z</dc:date>
    <item>
      <title>VPN certificate error, Android versions</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/vpn-certificate-error-android-versions/m-p/579930#M5107</link>
      <description>&lt;P&gt;Please, I have a problem with the connection through GlobalProtect VPN, for cell phones or tablets with Android version 12 and 13, the error is the following:&lt;BR /&gt;"There is a problem with the security certificate. The identity xxxx.xxxx.xxxx.xxxx cannot be verified. The portal certificate is not signed by a trusted certificate authority."&lt;/P&gt;
&lt;P&gt;With other versions of Android 8, 9, 10 it works, maybe you know what causes this error?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2024 15:44:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/vpn-certificate-error-android-versions/m-p/579930#M5107</guid>
      <dc:creator>jchciazacarrion</dc:creator>
      <dc:date>2024-03-11T15:44:59Z</dc:date>
    </item>
    <item>
      <title>Re: VPN certificate error, Android versions</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/vpn-certificate-error-android-versions/m-p/580498#M5133</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/109368"&gt;@jchciazacarrion&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Please check the GP logs for more details but based on the error message it sounds like&amp;nbsp;the intermediate certificate is missing from the trusted certificate authority store on the android device.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Make sure the intermediate certificate is imported to the firewall.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;On the Portal &amp;gt; Agent &amp;gt; Trusted Root CA &amp;gt; Add &amp;gt; Add the Intermediate certificate (check the "Install in Local Root Certificate Store) This way when devices connect to the portal for the first time, this intermediate certificate will be pushed to the trusted certificate store.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also make sure to check the compatibility matrix to make sure it's not something as simple as an incompatibility:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/compatibility-matrix/globalprotect/where-can-i-install-the-globalprotect-app" target="_blank"&gt;https://docs.paloaltonetworks.com/compatibility-matrix/globalprotect/where-can-i-install-the-globalprotect-app&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind regards,&lt;/P&gt;
&lt;P&gt;-Kim.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Mar 2024 11:19:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/vpn-certificate-error-android-versions/m-p/580498#M5133</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2024-03-15T11:19:01Z</dc:date>
    </item>
  </channel>
</rss>

