<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic NGFW unable to fetch device certificate due to bug in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ngfw-unable-to-fetch-device-certificate-due-to-bug/m-p/1252107#M6850</link>
    <description>&lt;P&gt;Hi Team,&lt;BR /&gt;&lt;BR /&gt;In reference to&amp;nbsp;PAN-313623 describes an issue on Palo Alto Networks firewalls with Trusted Platform Module (TPM), support where device certificate renewals, may fail due to a disk partition becoming full . &lt;BR /&gt;&lt;BR /&gt;This occurs because temporary .pub_pem files accumulate in the /opt/pancfg/mgmt/ssl/private/ directory and are not deleted during device certificate status checks, specifically when the show device-certificate status CLI command is executed .&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;The issue PAN-313623 has been addressed and fixed in various PAN-OS versions, including:&lt;/P&gt;
&lt;P&gt;PAN-OS 11.1.6-h29&lt;/P&gt;
&lt;P&gt;PAN-OS 11.1.10-h21&lt;/P&gt;
&lt;P&gt;PAN-OS 11.1.13-h3&lt;/P&gt;
&lt;P&gt;PAN-OS 11.2.7-h12&lt;/P&gt;
&lt;P&gt;PAN-OS 11.2.10-h5&lt;/P&gt;
&lt;P&gt;PAN-OS 11.2.11&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;For PAN-OS 12.1.x, PAN-313623 is still listed as a known issue in versions 12.1.3, 12.1.4, 12.1.5, and 12.1.6.&lt;BR /&gt;&lt;BR /&gt;My client is at 12.1.6 and needs information about the fix version and when it will be available. As far as now is to reboot NGFW in orden to cleanup this directory and refetech device certificate again.&lt;/P&gt;</description>
    <pubDate>Mon, 13 Apr 2026 14:27:43 GMT</pubDate>
    <dc:creator>P.RuizLopez</dc:creator>
    <dc:date>2026-04-13T14:27:43Z</dc:date>
    <item>
      <title>NGFW unable to fetch device certificate due to bug</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ngfw-unable-to-fetch-device-certificate-due-to-bug/m-p/1252107#M6850</link>
      <description>&lt;P&gt;Hi Team,&lt;BR /&gt;&lt;BR /&gt;In reference to&amp;nbsp;PAN-313623 describes an issue on Palo Alto Networks firewalls with Trusted Platform Module (TPM), support where device certificate renewals, may fail due to a disk partition becoming full . &lt;BR /&gt;&lt;BR /&gt;This occurs because temporary .pub_pem files accumulate in the /opt/pancfg/mgmt/ssl/private/ directory and are not deleted during device certificate status checks, specifically when the show device-certificate status CLI command is executed .&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;The issue PAN-313623 has been addressed and fixed in various PAN-OS versions, including:&lt;/P&gt;
&lt;P&gt;PAN-OS 11.1.6-h29&lt;/P&gt;
&lt;P&gt;PAN-OS 11.1.10-h21&lt;/P&gt;
&lt;P&gt;PAN-OS 11.1.13-h3&lt;/P&gt;
&lt;P&gt;PAN-OS 11.2.7-h12&lt;/P&gt;
&lt;P&gt;PAN-OS 11.2.10-h5&lt;/P&gt;
&lt;P&gt;PAN-OS 11.2.11&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;For PAN-OS 12.1.x, PAN-313623 is still listed as a known issue in versions 12.1.3, 12.1.4, 12.1.5, and 12.1.6.&lt;BR /&gt;&lt;BR /&gt;My client is at 12.1.6 and needs information about the fix version and when it will be available. As far as now is to reboot NGFW in orden to cleanup this directory and refetech device certificate again.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Apr 2026 14:27:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/ngfw-unable-to-fetch-device-certificate-due-to-bug/m-p/1252107#M6850</guid>
      <dc:creator>P.RuizLopez</dc:creator>
      <dc:date>2026-04-13T14:27:43Z</dc:date>
    </item>
    <item>
      <title>Re: NGFW unable to fetch device certificate due to bug</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ngfw-unable-to-fetch-device-certificate-due-to-bug/m-p/1253567#M6906</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/444912017"&gt;@P.RuizLopez&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;At this time, I do not see a public 12.1.x fixed version listed for PAN-313623. Since the customer needs a fix version/ETA, I would recommend opening a TAC case.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 07 May 2026 01:42:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/ngfw-unable-to-fetch-device-certificate-due-to-bug/m-p/1253567#M6906</guid>
      <dc:creator>JayGolf</dc:creator>
      <dc:date>2026-05-07T01:42:48Z</dc:date>
    </item>
  </channel>
</rss>

