<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Gateway certificate issue on Android Globalprotect in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/gateway-certificate-issue-on-android-globalprotect/m-p/1263304#M7516</link>
    <description>&lt;P&gt;I experimented a bit this morning and determined that if I manually installed the signing certificate as a trusted CA on my Android device, I was able to connect with 6.1.14 again.&amp;nbsp; This leads me to believe one or more of the following may be true:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;The root CA is not being installed on the mobile Android device, despite the settings on the firewall telling it to install on client device's trust stores (I thought I read somewhere that the certs are installed to a private GP trust store on Android but I'm not sure how accurate that information is).&lt;/LI&gt;
&lt;LI&gt;Something has changed on the GP Android client, such as not having access to the private certificate store file (if it ever existed), not having access to the Android trusted CA list to install the cert, or that the client was never previously actually verifying the certificate chain but it is now&lt;/LI&gt;
&lt;LI&gt;Something has changed on Android that the developers need to account for (less likely I think since 6.1.11 and 6.1.12 still work)&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;I've got a ticket open for this issue and have updated it with the info about testing the manual certificate install.&lt;/P&gt;</description>
    <pubDate>Mon, 31 Aug 2026 14:26:04 GMT</pubDate>
    <dc:creator>jsalmans</dc:creator>
    <dc:date>2026-08-31T14:26:04Z</dc:date>
    <item>
      <title>Gateway certificate issue on Android Globalprotect</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/gateway-certificate-issue-on-android-globalprotect/m-p/1262832#M7498</link>
      <description>&lt;P&gt;I've currently got a support case open for this, but I'm trying to see if other users are having the same issue.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;From what I've seen:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;6.1.11 - No issue&lt;/P&gt;
&lt;P&gt;6.1.12 - No issue&lt;/P&gt;
&lt;P&gt;6.1.13 - Issue Occurs&lt;/P&gt;
&lt;P&gt;6.1.14 - Issue Occurs (current version on Play Store)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The issue seems to be that the client doesn't trust the certificate for the gateway.&amp;nbsp; I'm not sure if it's the same bug or not, but it sounds similar to:&lt;/P&gt;
&lt;P&gt;GPC-24228&lt;BR /&gt;Fixed an issue where Android devices running the GlobalProtect agent were unable to connect to gateways, displaying a "Could not verify the server certificate of the gateway" error. This occurred because a common code change caused the GlobalProtect agent to use the OpenSSL framework for gateway server certificate handshakes, which was unable to access certificates stored in the Android key-store.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;GPC-24228 was marked as fixed in 6.1.11, though.&amp;nbsp; The actual error I see on an Android client:&lt;/P&gt;
&lt;P&gt;"GlobalProtect failed to connect to the login server.&amp;nbsp; Contact your IT help desk to resolve the issue&lt;BR /&gt;&lt;BR /&gt;Error Details:&lt;BR /&gt;The certificate for this server was signed by an unknown certifying authority.&amp;nbsp; You might be connecting to a server that is pretending to be [insert gateway cert CN here] which could put your confidential information at risk."&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The fact that it is getting my gateway list implies it is authenticating past the portal, SSO, and MFA.&amp;nbsp; I can downgrade from 6.1.14 to 6.1.12 and connect with no errors with no config change on the firewall or client (other than the re-install).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Anyone else seeing this?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 25 Aug 2026 20:24:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/gateway-certificate-issue-on-android-globalprotect/m-p/1262832#M7498</guid>
      <dc:creator>jsalmans</dc:creator>
      <dc:date>2026-08-25T20:24:57Z</dc:date>
    </item>
    <item>
      <title>Re: Gateway certificate issue on Android Globalprotect</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/gateway-certificate-issue-on-android-globalprotect/m-p/1263298#M7513</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;We're having the same problem with our self-signed certificate.&lt;BR /&gt;The following error appears in the client log:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;javax.net.ssl.SSLPeerUnverifiedException: Hostname gp.domain.com not verified:
    certificate: sha1/TzYD8P8Glo0Ha4UUtj5iUe8xkBM=
    DN: CN=gp.domain.com
    subjectAltNames: []
(21433)08/31 12:13:34:876212 - PanHttpsClient: exception GetHttpResponse, response code is 0
(21433)08/31 12:13:34:876645 - PanHttpsClient: response from server is:
null, exception Message: Hostname gp.domain.com not verified:
    certificate: sha1/TzYD8P8Glo0Ha4UUtj5iUe8xkBM=
    DN: CN=gp.domain.com
    subjectAltNames: []
 eType:javax.net.ssl.SSLPeerUnverifiedException: Hostname gp.domain.com not verified:
    certificate: sha1/TzYD8P8Glo0Ha4UUtj5iUe8xkBM=
    DN: CN=gp.domain.com
    subjectAltNames: []
(21433)08/31 12:13:34:876743 - (l6)JNI,21491,228,after JNIGetHttpResponse, ret=Valid(21433)08/31 12:13:34:876889 - (l5)JNI,21491,324,not handled, ret=error, javax.net.ssl.SSLPeerUnverifiedException: Hostname gp.domain.com not verified:
    certificate: sha1/TzYD8P8Glo0Ha4UUtj5iUe8xkBM=
    DN: CN=gp.domain.com
    subjectAltNames: [], return NULL now
(21433)08/31 12:13:34:876918 - (l6)JNI,21491,8121,prelogin to portal result is 
(null)
(21433)08/31 12:13:34:876961 - (l6)JNI,21491,8461,Failed to pre-login to the portal gp.domain.com with return value 0(0).&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;However, it works with the Global Protect app version 6.1.12.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best regards&lt;/P&gt;</description>
      <pubDate>Mon, 31 Aug 2026 11:23:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/gateway-certificate-issue-on-android-globalprotect/m-p/1263298#M7513</guid>
      <dc:creator>Helmut_Wenzel</dc:creator>
      <dc:date>2026-08-31T11:23:04Z</dc:date>
    </item>
    <item>
      <title>Re: Gateway certificate issue on Android Globalprotect</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/gateway-certificate-issue-on-android-globalprotect/m-p/1263304#M7516</link>
      <description>&lt;P&gt;I experimented a bit this morning and determined that if I manually installed the signing certificate as a trusted CA on my Android device, I was able to connect with 6.1.14 again.&amp;nbsp; This leads me to believe one or more of the following may be true:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;The root CA is not being installed on the mobile Android device, despite the settings on the firewall telling it to install on client device's trust stores (I thought I read somewhere that the certs are installed to a private GP trust store on Android but I'm not sure how accurate that information is).&lt;/LI&gt;
&lt;LI&gt;Something has changed on the GP Android client, such as not having access to the private certificate store file (if it ever existed), not having access to the Android trusted CA list to install the cert, or that the client was never previously actually verifying the certificate chain but it is now&lt;/LI&gt;
&lt;LI&gt;Something has changed on Android that the developers need to account for (less likely I think since 6.1.11 and 6.1.12 still work)&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;I've got a ticket open for this issue and have updated it with the info about testing the manual certificate install.&lt;/P&gt;</description>
      <pubDate>Mon, 31 Aug 2026 14:26:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/gateway-certificate-issue-on-android-globalprotect/m-p/1263304#M7516</guid>
      <dc:creator>jsalmans</dc:creator>
      <dc:date>2026-08-31T14:26:04Z</dc:date>
    </item>
  </channel>
</rss>

