<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Unable to apply Device Certificate in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/unable-to-apply-device-certificate/m-p/1247962#M6688</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/522563181"&gt;@J.Santos708860&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Can you go to the NGFW's CLI and send the following command?&lt;BR /&gt;&lt;BR /&gt;&amp;gt; commit force&lt;BR /&gt;&lt;BR /&gt;And verify with a ping if every FW's MGT has Internet access for example to a public website as follows:&lt;BR /&gt;&lt;BR /&gt;&amp;gt; ping host paloaltonetworks.com&lt;BR /&gt;&lt;BR /&gt;If the ping is successful, confirm that traffic is allowed from the MGT IP address; if not, check from any security device along the path to the Internet, including the NGFW itself, in its security logs under Monitor &amp;gt; Logs &amp;gt; Traffic, URL Filtering, Threat, Decryption, that the SSL and web browsing traffic is not blocked by any security rules, profiles, or decryption rules. This issue could affect the device certification renewal process.&lt;BR /&gt;&lt;BR /&gt;Also try to restart the MGT server process and make the import device certificate again from Panorama&lt;BR /&gt;&lt;BR /&gt;&amp;gt;&amp;nbsp;debug software restart process management-server&lt;BR /&gt;&amp;gt;&amp;nbsp;request certificate fetch&lt;BR /&gt;&lt;BR /&gt;Best Regards,&lt;/P&gt;</description>
    <pubDate>Wed, 11 Feb 2026 18:28:56 GMT</pubDate>
    <dc:creator>DanielS.Romero</dc:creator>
    <dc:date>2026-02-11T18:28:56Z</dc:date>
    <item>
      <title>Unable to apply Device Certificate</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/unable-to-apply-device-certificate/m-p/1247440#M6655</link>
      <description>&lt;P data-start="85" data-end="357"&gt;Hi Everyone, I am following the instructions to apply the device certificate, but I am blocked by the following error:&lt;BR data-start="194" data-end="197" /&gt;&lt;STRONG data-start="199" data-end="355"&gt;“Unable to execute OTP install operations command to some firewalls. Please identify the firewalls that failed the process from Panorama and retry OTP.”&lt;/STRONG&gt;&lt;/P&gt;
&lt;P data-start="364" data-end="549"&gt;I followed the instructions provided in this link:&lt;BR data-start="414" data-end="417" /&gt;&lt;A class="decorated-link" href="https://live.paloaltonetworks.com/t5/customer-advisories/update-to-additional-pan-os-certificate-expirations-and-new/ta-p/572158" target="_new" rel="noopener" data-start="419" data-end="547"&gt;https://live.paloaltonetworks.com/t5/customer-advisories/update-to-additional-pan-os-certificate-expirations-and-new/ta-p/572158&lt;/A&gt;&lt;/P&gt;
&lt;P data-start="556" data-end="585"&gt;&lt;STRONG data-start="556" data-end="583"&gt;My setup is as follows:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL data-start="588" data-end="693"&gt;
&lt;LI data-start="588" data-end="632"&gt;
&lt;P data-start="590" data-end="632"&gt;&lt;STRONG data-start="590" data-end="603"&gt;Panorama:&lt;/STRONG&gt; Software version 11.1.6-h3&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="635" data-end="689"&gt;
&lt;P data-start="637" data-end="689"&gt;&lt;STRONG data-start="637" data-end="646"&gt;NGFW:&lt;/STRONG&gt; Model PA-850, Software version 11.1.6-h3&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-start="696" data-end="743"&gt;The command below shows the following output:&lt;/P&gt;
&lt;P data-start="750" data-end="784"&gt;&lt;CODE data-start="750" data-end="782"&gt;show device-certificate status&lt;/CODE&gt;&lt;/P&gt;
&lt;P data-start="791" data-end="828"&gt;&lt;STRONG data-start="791" data-end="826"&gt;Device Certificate Information:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL data-start="831" data-end="1135"&gt;
&lt;LI data-start="831" data-end="875"&gt;
&lt;P data-start="833" data-end="875"&gt;Current device certificate status: Valid&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="878" data-end="923"&gt;
&lt;P data-start="880" data-end="923"&gt;Not valid before: 2025/12/26 05:26:50 CST&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="926" data-end="970"&gt;
&lt;P data-start="928" data-end="970"&gt;Not valid after: 2026/03/26 06:26:49 CDT&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="973" data-end="1024"&gt;
&lt;P data-start="975" data-end="1024"&gt;Last fetched timestamp: 2026/02/04 10:42:39 CST&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="1027" data-end="1059"&gt;
&lt;P data-start="1029" data-end="1059"&gt;Last fetched status: Failure&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="1062" data-end="1135"&gt;
&lt;P data-start="1064" data-end="1135"&gt;Last fetched info: Failed to fetch device certificate. OTP is not valid&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Has anyone encountered the same issue?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Wed, 04 Feb 2026 17:15:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/unable-to-apply-device-certificate/m-p/1247440#M6655</guid>
      <dc:creator>J.Santos708860</dc:creator>
      <dc:date>2026-02-04T17:15:03Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to apply Device Certificate</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/unable-to-apply-device-certificate/m-p/1247646#M6668</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/522563181"&gt;@J.Santos708860&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;At least in the example that you posted, you have an active certificate as of 2025/12/26 and you do not need another one. If you're trying to go through this workflow again with a valid certificate it's going to error, so from what you're showing this is what I would expect and you don't need to take any further action here.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Feb 2026 22:20:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/unable-to-apply-device-certificate/m-p/1247646#M6668</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2026-02-06T22:20:26Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to apply Device Certificate</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/unable-to-apply-device-certificate/m-p/1247749#M6674</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;I see. I'm a bit confused about whether I need to do something before the device certificate is enforced, which is why I followed the guide in the link. Is there a way for me to confirm that the certificate will be automatically renewed moving forward?&lt;/P&gt;</description>
      <pubDate>Mon, 09 Feb 2026 17:55:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/unable-to-apply-device-certificate/m-p/1247749#M6674</guid>
      <dc:creator>J.Santos708860</dc:creator>
      <dc:date>2026-02-09T17:55:54Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to apply Device Certificate</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/unable-to-apply-device-certificate/m-p/1247752#M6675</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/522563181"&gt;@J.Santos708860&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Could you try sending the commit force command on both the PA 850's and then retrying the certificate request?&lt;/P&gt;
&lt;P&gt;Do you have any DNS proxy or service route configured on the MGT interface?&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Best regards,&lt;/P&gt;</description>
      <pubDate>Mon, 09 Feb 2026 19:39:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/unable-to-apply-device-certificate/m-p/1247752#M6675</guid>
      <dc:creator>DanielS.Romero</dc:creator>
      <dc:date>2026-02-09T19:39:42Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to apply Device Certificate</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/unable-to-apply-device-certificate/m-p/1247929#M6683</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/289674"&gt;@DanielS.Romero&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;I don’t have any pending commits from Panorama, if that’s what you’re referring to. Also, I don’t have a DNS proxy or service route configured on my management interface—it’s directly connected to my ISP with a public IP.&lt;/P&gt;
&lt;P&gt;Please let me know if my response doesn’t align with your suggestion. Thank you!&lt;/P&gt;</description>
      <pubDate>Wed, 11 Feb 2026 11:24:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/unable-to-apply-device-certificate/m-p/1247929#M6683</guid>
      <dc:creator>J.Santos708860</dc:creator>
      <dc:date>2026-02-11T11:24:35Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to apply Device Certificate</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/unable-to-apply-device-certificate/m-p/1247930#M6684</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/522563181"&gt;@J.Santos708860&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In order to update the device certificate for a manage firewall, you need to follow the steps mentioned here:&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/panorama/11-1/panorama-admin/manage-firewalls/install-the-device-certificate-for-managed-firewalls/install-the-device-certificate-for-a-managed-firewall" target="_blank"&gt;https://docs.paloaltonetworks.com/panorama/11-1/panorama-admin/manage-firewalls/install-the-device-certificate-for-managed-firewalls/install-the-device-certificate-for-a-managed-firewall&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Even the process for OTP generation is between Panorama and Palo Alto Networks CSP, &lt;STRONG&gt;the managed firewall must have an outbound internet connection to successfully install the device certificate&lt;/STRONG&gt;. After you upload the OTP from Panorama, the managed firewall connects to the Palo Alto Networks CSP to install the device certificate.&lt;/P&gt;
&lt;P&gt;When the manage firewall connects to the Palo Alto Networks, it using the source interface configured under&amp;nbsp;"Palo Alto Networks Services" on Service Route Configuration. By default, is configured to use the MGMT interface of the firewall.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Feb 2026 11:53:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/unable-to-apply-device-certificate/m-p/1247930#M6684</guid>
      <dc:creator>CosminM</dc:creator>
      <dc:date>2026-02-11T11:53:50Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to apply Device Certificate</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/unable-to-apply-device-certificate/m-p/1247962#M6688</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/522563181"&gt;@J.Santos708860&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Can you go to the NGFW's CLI and send the following command?&lt;BR /&gt;&lt;BR /&gt;&amp;gt; commit force&lt;BR /&gt;&lt;BR /&gt;And verify with a ping if every FW's MGT has Internet access for example to a public website as follows:&lt;BR /&gt;&lt;BR /&gt;&amp;gt; ping host paloaltonetworks.com&lt;BR /&gt;&lt;BR /&gt;If the ping is successful, confirm that traffic is allowed from the MGT IP address; if not, check from any security device along the path to the Internet, including the NGFW itself, in its security logs under Monitor &amp;gt; Logs &amp;gt; Traffic, URL Filtering, Threat, Decryption, that the SSL and web browsing traffic is not blocked by any security rules, profiles, or decryption rules. This issue could affect the device certification renewal process.&lt;BR /&gt;&lt;BR /&gt;Also try to restart the MGT server process and make the import device certificate again from Panorama&lt;BR /&gt;&lt;BR /&gt;&amp;gt;&amp;nbsp;debug software restart process management-server&lt;BR /&gt;&amp;gt;&amp;nbsp;request certificate fetch&lt;BR /&gt;&lt;BR /&gt;Best Regards,&lt;/P&gt;</description>
      <pubDate>Wed, 11 Feb 2026 18:28:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/unable-to-apply-device-certificate/m-p/1247962#M6688</guid>
      <dc:creator>DanielS.Romero</dc:creator>
      <dc:date>2026-02-11T18:28:56Z</dc:date>
    </item>
  </channel>
</rss>

