<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: server certificate is invalid on chromebooks and phones in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/server-certificate-is-invalid-on-chromebooks-and-phones/m-p/380721#M806</link>
    <description>&lt;P&gt;Hello &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/168665"&gt;@CertInvalid&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;please see &lt;A href="https://support.sectigo.com/Com_KnowledgeDetailPage?Id=kA03l00000117LT" target="_blank"&gt;https://support.sectigo.com/Com_KnowledgeDetailPage?Id=kA03l00000117LT&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 19 Jan 2021 07:20:57 GMT</pubDate>
    <dc:creator>JoergSchuetter</dc:creator>
    <dc:date>2021-01-19T07:20:57Z</dc:date>
    <item>
      <title>server certificate is invalid on chromebooks and phones</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/server-certificate-is-invalid-on-chromebooks-and-phones/m-p/380676#M805</link>
      <description>&lt;P&gt;So for about the last month (just before xmas) we seem to be having certificate errors for our wildcard cert. Its a wildcard purchased from instantSSL. (sectigo) when using it with global protect client.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It works fine on windows machines. Just seems to be chromebooks and phones. When you go to connect it prints the error "Gateway XXX: The server certificate is invalid. Please contact your IT administrator"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;chromebook was restored to factory defaults. Global protect client is from the play store and is version 5.2.4-14 on my test device.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the logs, i am able to see the following:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;(1769)01/18 15:10:57:74295 - PanHttpsClient: 1738, found exception:javax.net.ssl.SSLHandshakeException: Certificate expired at Sat May 30 03:48:38 PDT 2020 (compared to Mon Jan 18 15:10:57 PST 2021)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;(1769)01/18 15:10:57:74340 - PanHttpsClient: server cert error&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However when i inspect the certificate on the website portal, it says valid till 2022 at a completely different date... So where does this panhttps certificate live? Is there multiple certificates? And also in the same log, it appears to be using this certificate with info as below, clearly valid...&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;Issuer: C=GB, ST=Greater Manchester, L=Salford, O=Sectigo Limited, CN=Sectigo RSA Domain Validation Secure Server CA&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Validity&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Not Before: Dec 4 00:00:00 2019 GMT&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Not After : Mar 7 00:00:00 2022 GMT&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jan 2021 23:35:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/server-certificate-is-invalid-on-chromebooks-and-phones/m-p/380676#M805</guid>
      <dc:creator>CertInvalid</dc:creator>
      <dc:date>2021-01-18T23:35:05Z</dc:date>
    </item>
    <item>
      <title>Re: server certificate is invalid on chromebooks and phones</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/server-certificate-is-invalid-on-chromebooks-and-phones/m-p/380721#M806</link>
      <description>&lt;P&gt;Hello &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/168665"&gt;@CertInvalid&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;please see &lt;A href="https://support.sectigo.com/Com_KnowledgeDetailPage?Id=kA03l00000117LT" target="_blank"&gt;https://support.sectigo.com/Com_KnowledgeDetailPage?Id=kA03l00000117LT&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jan 2021 07:20:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/server-certificate-is-invalid-on-chromebooks-and-phones/m-p/380721#M806</guid>
      <dc:creator>JoergSchuetter</dc:creator>
      <dc:date>2021-01-19T07:20:57Z</dc:date>
    </item>
    <item>
      <title>Re: server certificate is invalid on chromebooks and phones</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/server-certificate-is-invalid-on-chromebooks-and-phones/m-p/380825#M807</link>
      <description>&lt;P&gt;Wow thanks man, yes that does explain it!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;how to resolve though? Can i just install this on the server? i wont be able to update peoples personal phones obviously. Chromebooks i dont know...&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"You may need to update any such systems to include more modern roots if it’s possible to do so."&lt;/P&gt;&lt;P&gt;Does it mean the clients need to be updated, or the palo alto firewall needs it?&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jan 2021 16:00:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/server-certificate-is-invalid-on-chromebooks-and-phones/m-p/380825#M807</guid>
      <dc:creator>CertInvalid</dc:creator>
      <dc:date>2021-01-19T16:00:34Z</dc:date>
    </item>
  </channel>
</rss>

