<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Failed to renew device certificate in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/failed-to-renew-device-certificate/m-p/442061#M100060</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/197200"&gt;@esheldon&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;The device certificate process checks in regularly to automatically keep the certificate up to date and to make sure it isn't revoked. The error that you are getting can be caused by a few different things actually. I would verify that your firewall is actually getting to the URL properly according to your logs and verify that a client behind the firewall can reach that URL.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Be aware that the website will give you a certificate error and will prompt you for a client certificate. As long as you can get that prompt your firewall should be able to access the website without issue. The firewall trusts the website and presents the device certificate to authenticate to the site, so as long as your device certificate is valid you should be all set.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 20 Oct 2021 01:33:06 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2021-10-20T01:33:06Z</dc:date>
    <item>
      <title>Failed to renew device certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/failed-to-renew-device-certificate/m-p/442031#M100059</link>
      <description>&lt;P&gt;Sorry, not sure what board to post this on, as it's my first support post.&amp;nbsp; Getting an error on my Primary PaloAlto firewall: Failed to renew device certificate.Failed to send request to CSP server.Error: OpenSSL SSL_connect: SSL_ERROR_SYSCALL in connection to certificatetrusted.paloaltonetworks.com:443&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I log onto the firewall, it shows the device certificate is valid on the main dashboard, and when I go to Device-&amp;gt;Certificate Management-&amp;gt;Certificates, all certs show fine until at least March of 2022.&amp;nbsp; I'm not sure what to do at this point.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Oct 2021 23:40:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/failed-to-renew-device-certificate/m-p/442031#M100059</guid>
      <dc:creator>esheldon</dc:creator>
      <dc:date>2021-10-19T23:40:53Z</dc:date>
    </item>
    <item>
      <title>Re: Failed to renew device certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/failed-to-renew-device-certificate/m-p/442061#M100060</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/197200"&gt;@esheldon&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;The device certificate process checks in regularly to automatically keep the certificate up to date and to make sure it isn't revoked. The error that you are getting can be caused by a few different things actually. I would verify that your firewall is actually getting to the URL properly according to your logs and verify that a client behind the firewall can reach that URL.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Be aware that the website will give you a certificate error and will prompt you for a client certificate. As long as you can get that prompt your firewall should be able to access the website without issue. The firewall trusts the website and presents the device certificate to authenticate to the site, so as long as your device certificate is valid you should be all set.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Oct 2021 01:33:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/failed-to-renew-device-certificate/m-p/442061#M100060</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2021-10-20T01:33:06Z</dc:date>
    </item>
    <item>
      <title>Re: Failed to renew device certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/failed-to-renew-device-certificate/m-p/442448#M100102</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/197200"&gt;@esheldon&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The error is referring to the certificate under Device &amp;gt; Setup &amp;gt; Management &amp;gt; Device Certificate.&amp;nbsp; It is not listed under Certificate Management.&amp;nbsp; It is used to leverage cloud services.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-admin/certificate-management/obtain-certificates/device-certificate.html" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-admin/certificate-management/obtain-certificates/device-certificate.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Thu, 21 Oct 2021 05:22:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/failed-to-renew-device-certificate/m-p/442448#M100102</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2021-10-21T05:22:09Z</dc:date>
    </item>
  </channel>
</rss>

