<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Device Certificate fetch failure in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/device-certificate-fetch-failure/m-p/529583#M109315</link>
    <description>The issues goes away by itself LOL&lt;BR /&gt;</description>
    <pubDate>Thu, 02 Feb 2023 07:46:20 GMT</pubDate>
    <dc:creator>VLim</dc:creator>
    <dc:date>2023-02-02T07:46:20Z</dc:date>
    <item>
      <title>Device Certificate fetch failure</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/device-certificate-fetch-failure/m-p/514366#M106786</link>
      <description>&lt;P&gt;Version : 10.1.6-h3&lt;/P&gt;
&lt;P&gt;Issue/ Error log : Failed to fetch device certificate. Failed to send request to CSP server. Error: No OCSP response received(dest =&amp;gt; 35.222.13.89)&lt;/P&gt;
&lt;P&gt;Tshoot : Generated OTP over support portal but no option for me to key in the OTP&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;KB unable to resolve : &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000004NlxCAE&amp;amp;lang=en_US%E2%80%A9" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000004NlxCAE&amp;amp;lang=en_US%E2%80%A9&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Require assist on the cli to key in the otp for device certicate&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;BR /&gt;&lt;BR /&gt;Please note you are posting a public message where community members and experts can provide assistance. Sharing private information such as serial numbers or company information is not recommended.</description>
      <pubDate>Fri, 09 Sep 2022 02:52:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/device-certificate-fetch-failure/m-p/514366#M106786</guid>
      <dc:creator>VLim</dc:creator>
      <dc:date>2022-09-09T02:52:14Z</dc:date>
    </item>
    <item>
      <title>Re: Device Certificate fetch failure</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/device-certificate-fetch-failure/m-p/514518#M106797</link>
      <description>&lt;P&gt;I'm seeing the same thing on a PA-410 and a new eval PA-VM when trying to fetch their device certificates.&lt;/P&gt;
&lt;P&gt;On the PA-410, it's preventing ZTP from proceeding.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It looks like an issue at Palo with api.paloaltonetworks.com.&lt;/P&gt;</description>
      <pubDate>Mon, 12 Sep 2022 02:57:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/device-certificate-fetch-failure/m-p/514518#M106797</guid>
      <dc:creator>David_Early</dc:creator>
      <dc:date>2022-09-12T02:57:46Z</dc:date>
    </item>
    <item>
      <title>Re: Device Certificate fetch failure</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/device-certificate-fetch-failure/m-p/514796#M106842</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/196381"&gt;@VLim&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Not sure if you've tried the following.&lt;/P&gt;
&lt;P&gt;Once you generate the OTP on the CSP l&lt;SPAN&gt;og in to your next-generation firewall as an admin user.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Select&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG style="box-sizing: border-box; font-weight: var(--lwc-fontWeightBold,700); color: #181818; font-family: -apple-system, 'system-ui', 'Segoe UI', Roboto, Helvetica, Arial, sans-serif, 'Apple Color Emoji', 'Segoe UI Emoji', 'Segoe UI Symbol'; font-size: 14px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: #ffffff; text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial;" data-aura-rendered-by="236:7306;a"&gt;Device &amp;gt; Setup &amp;gt; Management &amp;gt; Device Certificate&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;and click&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG style="box-sizing: border-box; font-weight: var(--lwc-fontWeightBold,700); color: #181818; font-family: -apple-system, 'system-ui', 'Segoe UI', Roboto, Helvetica, Arial, sans-serif, 'Apple Color Emoji', 'Segoe UI Emoji', 'Segoe UI Symbol'; font-size: 14px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: #ffffff; text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial;" data-aura-rendered-by="236:7306;a"&gt;Get certificate&lt;/STRONG&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;BR style="box-sizing: border-box; color: #181818; font-family: -apple-system, 'system-ui', 'Segoe UI', Roboto, Helvetica, Arial, sans-serif, 'Apple Color Emoji', 'Segoe UI Emoji', 'Segoe UI Symbol'; font-size: 14px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: #ffffff; text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial;" data-aura-rendered-by="236:7306;a" /&gt;&lt;SPAN&gt;Paste the One-time Password you generated and click&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG style="box-sizing: border-box; font-weight: var(--lwc-fontWeightBold,700); color: #181818; font-family: -apple-system, 'system-ui', 'Segoe UI', Roboto, Helvetica, Arial, sans-serif, 'Apple Color Emoji', 'Segoe UI Emoji', 'Segoe UI Symbol'; font-size: 14px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: #ffffff; text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial;" data-aura-rendered-by="236:7306;a"&gt;OK&lt;BR style="box-sizing: border-box;" /&gt;&lt;/STRONG&gt;&lt;SPAN&gt;The firewall should successfully retrieve and install the certificate.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;As for cli, is this the command you were looking for ?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;admin@PA-LAB&amp;gt; request certificate fetch otp &amp;lt;value&amp;gt;&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This will trigger the job 'Device-certificate-fetch'.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps,&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;
&lt;DIV id="ConnectiveDocSignExtentionInstalled" data-extension-version="1.0.4"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Wed, 14 Sep 2022 07:09:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/device-certificate-fetch-failure/m-p/514796#M106842</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2022-09-14T07:09:03Z</dc:date>
    </item>
    <item>
      <title>Re: Device Certificate fetch failure</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/device-certificate-fetch-failure/m-p/515550#M107074</link>
      <description>&lt;P&gt;Seem Palo Alto take times for fetch new certificate, when I tried to execute few days later it shown success&lt;/P&gt;</description>
      <pubDate>Tue, 20 Sep 2022 23:37:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/device-certificate-fetch-failure/m-p/515550#M107074</guid>
      <dc:creator>VLim</dc:creator>
      <dc:date>2022-09-20T23:37:02Z</dc:date>
    </item>
    <item>
      <title>Re: Device Certificate fetch failure</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/device-certificate-fetch-failure/m-p/529427#M109298</link>
      <description>&lt;P&gt;Command is not working&lt;/P&gt;</description>
      <pubDate>Wed, 01 Feb 2023 08:26:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/device-certificate-fetch-failure/m-p/529427#M109298</guid>
      <dc:creator>nkmehta</dc:creator>
      <dc:date>2023-02-01T08:26:12Z</dc:date>
    </item>
    <item>
      <title>Re: Device Certificate fetch failure</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/device-certificate-fetch-failure/m-p/529437#M109301</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/73961"&gt;@nkmehta&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;A bit more context would help us.&amp;nbsp; What's the outcome when you try the command ? Are you seeing an error message ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Feb 2023 09:47:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/device-certificate-fetch-failure/m-p/529437#M109301</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2023-02-01T09:47:54Z</dc:date>
    </item>
    <item>
      <title>Re: Device Certificate fetch failure</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/device-certificate-fetch-failure/m-p/529583#M109315</link>
      <description>The issues goes away by itself LOL&lt;BR /&gt;</description>
      <pubDate>Thu, 02 Feb 2023 07:46:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/device-certificate-fetch-failure/m-p/529583#M109315</guid>
      <dc:creator>VLim</dc:creator>
      <dc:date>2023-02-02T07:46:20Z</dc:date>
    </item>
    <item>
      <title>Re: Device Certificate fetch failure</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/device-certificate-fetch-failure/m-p/542802#M111170</link>
      <description>&lt;P&gt;I have a PA440 that is throwing No Device Certificate error. Go to Device, Setup tab to try to "Get Certificate" however no option to get certificate is available:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="no-cert.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/50262i2AC1583544166BCC/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="no-cert.png" alt="no-cert.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm trying to do this via CLI. When I try to:&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;request certificate fetch otp [what-is-this-value???]&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;i try pasting the OTP from the website and it gives me an error.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 20 May 2023 15:26:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/device-certificate-fetch-failure/m-p/542802#M111170</guid>
      <dc:creator>rpolefka</dc:creator>
      <dc:date>2023-05-20T15:26:24Z</dc:date>
    </item>
    <item>
      <title>Re: Device Certificate fetch failure</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/device-certificate-fetch-failure/m-p/542804#M111171</link>
      <description>&lt;P&gt;Hmm ok well either I did something or it resolved itself.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;I did&amp;nbsp;&lt;/P&gt;
&lt;P&gt;request certificate fetch&amp;nbsp;&lt;/P&gt;
&lt;P&gt;and then i got&lt;/P&gt;
&lt;P&gt;Certificate fetch job enqueued with jobid 8418&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Then went back to Management page and it was there...&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="no-cert.png" style="width: 781px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/50263i849E224F3C9039E1/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="no-cert.png" alt="no-cert.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 20 May 2023 15:38:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/device-certificate-fetch-failure/m-p/542804#M111171</guid>
      <dc:creator>rpolefka</dc:creator>
      <dc:date>2023-05-20T15:38:52Z</dc:date>
    </item>
    <item>
      <title>Re: Device Certificate fetch failure</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/device-certificate-fetch-failure/m-p/568464#M114730</link>
      <description>&lt;P&gt;hello Vlim,&lt;/P&gt;
&lt;P&gt;please this is the error im getting when trying to generate certificate&amp;nbsp;&lt;/P&gt;
&lt;DIV class="x-window-tl"&gt;
&lt;DIV class="x-window-tr"&gt;
&lt;DIV class="x-window-tc"&gt;
&lt;DIV class="x-window-header x-unselectable x-window-draggable"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV id="ext-gen1010" class="x-window-header x-unselectable x-window-draggable"&gt;&lt;SPAN class="x-window-header-text"&gt;Error&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV id="ext-gen1011" class="x-window-bwrap"&gt;
&lt;DIV class="x-window-ml"&gt;
&lt;DIV class="x-window-mr"&gt;
&lt;DIV id="ext-gen1015" class="x-window-mc"&gt;
&lt;DIV id="ext-gen1012" class="x-window-body"&gt;
&lt;DIV id="ext-gen1032"&gt;
&lt;DIV id="ext-gen1033" class="ext-mb-icon x-hidden"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="ext-mb-content"&gt;&lt;SPAN class="ext-mb-text"&gt;request -&amp;gt; certificate -&amp;gt; fetch -&amp;gt; otp unexpected here&lt;BR /&gt;request -&amp;gt; certificate -&amp;gt; fetch is unexpected&lt;BR /&gt;request -&amp;gt; certificate is unexpected&lt;BR /&gt;request is unexpected&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Tue, 05 Dec 2023 16:50:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/device-certificate-fetch-failure/m-p/568464#M114730</guid>
      <dc:creator>PBotchway</dc:creator>
      <dc:date>2023-12-05T16:50:17Z</dc:date>
    </item>
    <item>
      <title>Re: Device Certificate fetch failure</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/device-certificate-fetch-failure/m-p/568555#M114738</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am having the same error;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;request -&amp;gt; certificate -&amp;gt; fetch -&amp;gt; otp unexpected here&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;request -&amp;gt; certificate -&amp;gt; fetch is unexpected&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;request -&amp;gt; certificate is unexpected&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;request is unexpected&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;after copying the OTP from the support portal and pasting it in the get certificate&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;can anyone let me know how to resolve this issue?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Dec 2023 06:25:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/device-certificate-fetch-failure/m-p/568555#M114738</guid>
      <dc:creator>Waly</dc:creator>
      <dc:date>2023-12-06T06:25:49Z</dc:date>
    </item>
    <item>
      <title>Re: Device Certificate fetch failure</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/device-certificate-fetch-failure/m-p/568636#M114741</link>
      <description>&lt;P&gt;The availability of entering "otp" might be depends on your platform and version.&lt;/P&gt;
&lt;P&gt;I'll show you two samples; one is pan-os 11.0 with PA-445, another is pan-os 10.2 with panorama.&lt;/P&gt;
&lt;P&gt;===&lt;/P&gt;
&lt;P&gt;admin@PA-445&amp;gt; show system info | match sw-version&lt;BR /&gt;sw-version: 11.0.2-h2&lt;BR /&gt;admin@PA-445&amp;gt;&lt;BR /&gt;admin@PA-445&amp;gt; request certificate fetch ?&lt;BR /&gt;&amp;lt;Enter&amp;gt; Finish input&lt;/P&gt;
&lt;P&gt;admin@PA-445&amp;gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;admin@Panorama&amp;gt; show system info | match sw-version&lt;BR /&gt;sw-version: 10.2.7&lt;BR /&gt;admin@Panorama&amp;gt;&lt;BR /&gt;admin@Panorama&amp;gt; request certificate fetch ?&lt;BR /&gt;* otp One time password to generate the certificatei&lt;/P&gt;
&lt;P&gt;&lt;A href="mailto:admin@Panorama&amp;gt;" target="_blank"&gt;admin@Panorama&amp;gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;===&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As you can see, PA-445 does not have "otp" option.&lt;/P&gt;
&lt;P&gt;Please check on your platform. You can check with entering "?" on your command.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Dec 2023 08:28:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/device-certificate-fetch-failure/m-p/568636#M114741</guid>
      <dc:creator>emr_1</dc:creator>
      <dc:date>2023-12-06T08:28:31Z</dc:date>
    </item>
    <item>
      <title>Re: Device Certificate fetch failure</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/device-certificate-fetch-failure/m-p/568670#M114746</link>
      <description />
      <pubDate>Wed, 06 Dec 2023 12:25:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/device-certificate-fetch-failure/m-p/568670#M114746</guid>
      <dc:creator>pius.botchway</dc:creator>
      <dc:date>2023-12-06T12:25:32Z</dc:date>
    </item>
    <item>
      <title>Re: Device Certificate fetch failure</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/device-certificate-fetch-failure/m-p/594776#M118383</link>
      <description>&lt;P&gt;We have an issue with the Firewalls 410 and 440 due we can't execute command for get certificate. We request support to Palo Alto on a case &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Aug 2024 16:41:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/device-certificate-fetch-failure/m-p/594776#M118383</guid>
      <dc:creator>felipeorozco</dc:creator>
      <dc:date>2024-08-13T16:41:46Z</dc:date>
    </item>
    <item>
      <title>Re: Device Certificate fetch failure</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/device-certificate-fetch-failure/m-p/1220036#M123241</link>
      <description>&lt;P&gt;I know this is a really old topic, but I found this thread when I was trying to diagnose my own cert download issue.&lt;/P&gt;
&lt;P&gt;I had a problem because my MGMT interface led to a different firewall for outbound that has SSL inspection.&amp;nbsp; Since this changes the cert for the transaction, Palo Alto rejects the transaction.&amp;nbsp; Setting "Palo Alto Networks Services" on the outside interface instead of MGMT fixed the issue.&amp;nbsp; This is changed in Device &amp;gt; Setup &amp;gt; Services &amp;gt; Service Route Configuration.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2025 23:09:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/device-certificate-fetch-failure/m-p/1220036#M123241</guid>
      <dc:creator>wstuart</dc:creator>
      <dc:date>2025-02-11T23:09:18Z</dc:date>
    </item>
  </channel>
</rss>

