<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Device Certificate Issues. in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/device-certificate-issues/m-p/593419#M3498</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/197789"&gt;@CosminM&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The firewall is trying to fetch the certificate but it is getting failed with no error.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Monica Shree.&lt;/P&gt;</description>
    <pubDate>Tue, 30 Jul 2024 03:39:27 GMT</pubDate>
    <dc:creator>Monicashree</dc:creator>
    <dc:date>2024-07-30T03:39:27Z</dc:date>
    <item>
      <title>Device Certificate Issues.</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/device-certificate-issues/m-p/593227#M3492</link>
      <description>&lt;P&gt;Hi Friends,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;One of our customer is facing issues in fetching the device certificate on a PA-410 device running on PAN OS 11.0.4-h2.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We are logging into the CLI of the firewall with Super User credentials and try to fetch the certificate with the below command&lt;/P&gt;
&lt;P&gt;&amp;gt; request certificate fetch opt &amp;lt; &amp;gt;&lt;BR /&gt;It shows us invalid syntax error. From the GUI we could not see the get certificate option as well.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;We have created a policy to allow paloalto-shared services but it didn’t help. Tried by restarting the management server as well but it didn’t help us.&lt;BR /&gt;As it is a PA-410 devices we could not able to see the traffic logs to see weather by any chance the traffic is getting blocked.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When we check the device certgen.log we could see the below error.&lt;BR /&gt;2024-07-23 16:13:19,013 device_certgen ERROR Error: (35, 'OpenSSL SSL_connect: SSL_ERROR_SYSCALL in connection to certificate.paloaltonetworks.com:443 ')&lt;BR /&gt;2024-07-23 16:13:19,526 device_certgen ERROR Error: (35, 'OpenSSL SSL_connect: SSL_ERROR_SYSCALL in connection to certificate.paloaltonetworks.com:443 ')&lt;BR /&gt;2024-07-23 16:15:12,498 device_certgen INFO Device certificate not found&lt;BR /&gt;2024-07-23 16:16:49,070 device_certgen INFO Device certificate not found&lt;BR /&gt;2024-07-23 16:22:04,924 device_certgen INFO Fetching device certificate&lt;BR /&gt;2024-07-23 16:22:56,968 device_certgen INFO Secret_key generated&lt;BR /&gt;2024-07-23 16:22:56,968 device_certgen INFO Generated pkey and CSR&lt;BR /&gt;2024-07-23 16:22:57,173 device_certgen INFO Source interface: 45.112.139.226&lt;BR /&gt;2024-07-23 16:22:57,805 device_certgen ERROR Error: (35, 'OpenSSL SSL_connect: SSL_ERROR_SYSCALL in connection to certificate.paloaltonetworks.com:443 ')&lt;BR /&gt;2024-07-23 16:22:58,337 device_certgen ERROR Error: (35, 'OpenSSL SSL_connect: SSL_ERROR_SYSCALL in connection to certificate.paloaltonetworks.com:443 ')&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Any help or suggestions on how to Proceed further.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks and Regards&lt;/P&gt;
&lt;P&gt;Monica Shree.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 27 Jul 2024 10:12:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/device-certificate-issues/m-p/593227#M3492</guid>
      <dc:creator>Monicashree</dc:creator>
      <dc:date>2024-07-27T10:12:16Z</dc:date>
    </item>
    <item>
      <title>Re: Device Certificate Issues.</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/device-certificate-issues/m-p/593236#M3493</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/265072"&gt;@Monicashree&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For devices equipped with a TPM chipset (like PA-400 series), the CLI command is simply:&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;gt; &lt;STRONG&gt;&lt;EM&gt;request certificate fetch&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;This will create a job, and you can view the details using:&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;gt;&lt;STRONG&gt;&lt;EM&gt; show jobs id XX&lt;/EM&gt;&lt;/STRONG&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;---&amp;gt; replace XX with your actual job ID.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The command "&lt;STRONG&gt;&lt;EM&gt;show device-certificate status&lt;/EM&gt;&lt;/STRONG&gt;" allows you to verify the status of your device's certificate.&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jul 2024 07:41:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/device-certificate-issues/m-p/593236#M3493</guid>
      <dc:creator>CosminM</dc:creator>
      <dc:date>2024-07-31T07:41:29Z</dc:date>
    </item>
    <item>
      <title>Re: Device Certificate Issues.</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/device-certificate-issues/m-p/593419#M3498</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/197789"&gt;@CosminM&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The firewall is trying to fetch the certificate but it is getting failed with no error.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Monica Shree.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jul 2024 03:39:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/device-certificate-issues/m-p/593419#M3498</guid>
      <dc:creator>Monicashree</dc:creator>
      <dc:date>2024-07-30T03:39:27Z</dc:date>
    </item>
    <item>
      <title>Re: Device Certificate Issues.</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/device-certificate-issues/m-p/593526#M3502</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/265072"&gt;@Monicashree&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The error shows up under the "show jobs id &amp;lt;job-id&amp;gt;" command.&amp;nbsp; Did you run the command as &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/197789"&gt;@CosminM&lt;/a&gt; explained?&amp;nbsp; I have never seen it fail without an error, but this could be the 1st.&amp;nbsp; On very rare occasions, I have seen the job stay in pending forever.&amp;nbsp; That obviously shows no error but the fact that the job did not complete is the error.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jul 2024 15:58:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/device-certificate-issues/m-p/593526#M3502</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2024-07-30T15:58:50Z</dc:date>
    </item>
    <item>
      <title>Re: Device Certificate Issues.</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/device-certificate-issues/m-p/593657#M3507</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/77347"&gt;@TomYoung&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes I ran the command mentioned by&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/197789"&gt;@CosminM&lt;/a&gt;&amp;nbsp;and still I could only see fetch failed with out error.&lt;/P&gt;
&lt;P&gt;I am adding the screenshots for reference.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Device certificate - CLI.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/61263i9134890F84234F17/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Device certificate - CLI.png" alt="Device certificate - CLI.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Device certificate -1.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/61262i06C8EE881066DA56/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Device certificate -1.png" alt="Device certificate -1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Monica Shree&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jul 2024 15:39:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/device-certificate-issues/m-p/593657#M3507</guid>
      <dc:creator>Monicashree</dc:creator>
      <dc:date>2024-07-31T15:39:21Z</dc:date>
    </item>
    <item>
      <title>Re: Device Certificate Issues.</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/device-certificate-issues/m-p/593658#M3508</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/265072"&gt;@Monicashree&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for the screen shots!&amp;nbsp; Well, that's disappointing that there is no error.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I apologize.&amp;nbsp; You already provided the relevant error messages in your original post.&amp;nbsp; It looks like your traffic is not connecting to the CSP.&amp;nbsp; &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000HBgsCAG&amp;amp;lang=en_US%E2%80%A9" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000HBgsCAG&amp;amp;lang=en_US%E2%80%A9&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This may be caused by not having a security policy rule as the article says or by a routing or other issue.&amp;nbsp; Do you see the traffic from the NGFW to the CSP being allowed under Monitor &amp;gt; Logs &amp;gt; Traffic?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jul 2024 15:51:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/device-certificate-issues/m-p/593658#M3508</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2024-07-31T15:51:31Z</dc:date>
    </item>
    <item>
      <title>Re: Device Certificate Issues.</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/device-certificate-issues/m-p/593660#M3509</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/77347"&gt;@TomYoung&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is a PA-410 so i could not find the traffic logs and the firewall is not connected to Panorama as well so logs visibility is not there apart from that I have already added a policy for allowing paloalto-shared services and it is in TOP position. I have checked the service routes as well everything seems to be placed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I changed the service route from management to data plane as well but didn't help me. I took Packet Captures from the data interface ip and to certificate.paloaltonetworks.com. Interestingly i got all the four drop ; firewall ; receive and transmit packets.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;customer is yet to share them. In the mean time if you have any suggestions do let me know or else suggest me what two packets should i merge and check.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks and Regards&lt;/P&gt;
&lt;P&gt;Monica Shree&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jul 2024 16:00:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/device-certificate-issues/m-p/593660#M3509</guid>
      <dc:creator>Monicashree</dc:creator>
      <dc:date>2024-07-31T16:00:35Z</dc:date>
    </item>
    <item>
      <title>Re: Device Certificate Issues.</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/device-certificate-issues/m-p/593663#M3510</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/265072"&gt;@Monicashree&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You are doing great!&amp;nbsp; The next step is to check the packet captures.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It could be an MTU issue, but it is doubtful.&amp;nbsp; &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000004NlxCAE&amp;amp;lang=en_US%E2%80%A9" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000004NlxCAE&amp;amp;lang=en_US%E2%80%A9&lt;/A&gt;. Does the traffic go through a VPN before going out to the Internet?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jul 2024 16:14:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/device-certificate-issues/m-p/593663#M3510</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2024-07-31T16:14:48Z</dc:date>
    </item>
    <item>
      <title>Re: Device Certificate Issues.</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/device-certificate-issues/m-p/593699#M3514</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/265072"&gt;@Monicashree&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you please look into process log with command:&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &lt;EM&gt;&lt;STRONG&gt;less mp-log device_certgen.log&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jul 2024 19:35:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/device-certificate-issues/m-p/593699#M3514</guid>
      <dc:creator>CosminM</dc:creator>
      <dc:date>2024-07-31T19:35:07Z</dc:date>
    </item>
  </channel>
</rss>

