<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Peer certificate chain building failed due to unable to get local issuer certificate in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/peer-certificate-chain-building-failed-due-to-unable-to-get/m-p/551880#M112343</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I'm in similar situation, but mine is more weird. I have PA820 at HQ and two PA410 at remote offices. Both PA410 have almost identical configuration (only IP addresses are different). I'm trying to build IPSec tunnels from HQ to remote offices. One of them works as expected. The other gives me the error in the topic of this thread. The weird thing is that the same CA (internally generated at PA820) issued certificates to both remote offices, but only one of them works while the other doesn't. I checked hundred times and I'm sure the configuration is identical, the "local issuer certificate" is the same for both IKE gateways. I can't understand how is it possible that one remote site works without problems while the other fails to get that local issuer certificate ?!?&lt;/P&gt;</description>
    <pubDate>Mon, 31 Jul 2023 21:20:26 GMT</pubDate>
    <dc:creator>GeorgeAPH</dc:creator>
    <dc:date>2023-07-31T21:20:26Z</dc:date>
    <item>
      <title>Peer certificate chain building failed due to unable to get local issuer certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/peer-certificate-chain-building-failed-due-to-unable-to-get/m-p/324544#M82843</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is my first post here as I am a new customer of PaloAlto, but not new to networking. I have extensive Cisco background.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are having an odd problem when trying to create an IKEv1 s2s tunnel between a remote PA220 and Cisco ASA 5525X headend. The PA outside interface has a dynamic address.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have worked on this issue for days now and even opened a case with PA Support.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are getting this error on the PA side:&lt;/P&gt;&lt;P&gt;IKE phase-1 negotiation is failed. Peer certificate chain building failed due to unable to get local issuer certificate&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the logs obtained in the CLI, we are seeing this information:&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;2020-04-23 09:28:06.066 -0400&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;[PERR]: Trusted CA not found for '/C=US/O=DigiCert Inc/OU=&lt;A href="http://www.digicert.com/CN=DigiCert" target="_blank"&gt;www.digicert.com/CN=DigiCert&lt;/A&gt; Global Root CA' because of subject issuer mismatch.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;2020-04-23 09:28:06.066 -0400&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;[PERR]: Peer certificate chain building failed due to unable to get local issuer certificate.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;I have verified that the certificate chain for the public cert being used on the Cisco ASA headend is intact and complete.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="p1"&gt;Any ideas??? We have scoured the internet for solution/clues on both sides, Cisco and PA, to no avail.&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="p1"&gt;Thanks in advance.&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="p1"&gt;John&lt;/P&gt;</description>
      <pubDate>Thu, 23 Apr 2020 13:45:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/peer-certificate-chain-building-failed-due-to-unable-to-get/m-p/324544#M82843</guid>
      <dc:creator>JohnRumball</dc:creator>
      <dc:date>2020-04-23T13:45:09Z</dc:date>
    </item>
    <item>
      <title>Re: Peer certificate chain building failed due to unable to get local issuer certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/peer-certificate-chain-building-failed-due-to-unable-to-get/m-p/324636#M82858</link>
      <description>&lt;P&gt;John,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm in a similar position.&amp;nbsp; I will be following this thread closely.&amp;nbsp; Thanks for posting.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Apr 2020 19:26:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/peer-certificate-chain-building-failed-due-to-unable-to-get/m-p/324636#M82858</guid>
      <dc:creator>l.pelland</dc:creator>
      <dc:date>2020-04-23T19:26:01Z</dc:date>
    </item>
    <item>
      <title>Re: Peer certificate chain building failed due to unable to get local issuer certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/peer-certificate-chain-building-failed-due-to-unable-to-get/m-p/432090#M95169</link>
      <description>&lt;P&gt;Did you ever find the answer to this issue?&amp;nbsp; Typically the error "&lt;SPAN class="s1"&gt;unable to get local issuer certificate&lt;/SPAN&gt;" means that the CA used to &lt;STRONG&gt;issue&lt;/STRONG&gt; your peer certificate is not in your certificate profile (configured under your IKE Gateway).&amp;nbsp; The certificate profile must contain the entire CA certificate chain regardless of what is in the Default Trusted Certificate Authorities.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Sep 2021 19:10:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/peer-certificate-chain-building-failed-due-to-unable-to-get/m-p/432090#M95169</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2021-09-06T19:10:44Z</dc:date>
    </item>
    <item>
      <title>Re: Peer certificate chain building failed due to unable to get local issuer certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/peer-certificate-chain-building-failed-due-to-unable-to-get/m-p/551880#M112343</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I'm in similar situation, but mine is more weird. I have PA820 at HQ and two PA410 at remote offices. Both PA410 have almost identical configuration (only IP addresses are different). I'm trying to build IPSec tunnels from HQ to remote offices. One of them works as expected. The other gives me the error in the topic of this thread. The weird thing is that the same CA (internally generated at PA820) issued certificates to both remote offices, but only one of them works while the other doesn't. I checked hundred times and I'm sure the configuration is identical, the "local issuer certificate" is the same for both IKE gateways. I can't understand how is it possible that one remote site works without problems while the other fails to get that local issuer certificate ?!?&lt;/P&gt;</description>
      <pubDate>Mon, 31 Jul 2023 21:20:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/peer-certificate-chain-building-failed-due-to-unable-to-get/m-p/551880#M112343</guid>
      <dc:creator>GeorgeAPH</dc:creator>
      <dc:date>2023-07-31T21:20:26Z</dc:date>
    </item>
    <item>
      <title>Re: Peer certificate chain building failed due to unable to get local issuer certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/peer-certificate-chain-building-failed-due-to-unable-to-get/m-p/552073#M112362</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/144616"&gt;@GeorgeAPH&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is your PAN-OS the same on both NGFWs?&amp;nbsp; I ran into this error with a certificate profile for an EDL.&amp;nbsp; An upgrade to 10.2.4 fixed the issue.&amp;nbsp; It turned out to be a bug in the code.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Tue, 01 Aug 2023 13:35:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/peer-certificate-chain-building-failed-due-to-unable-to-get/m-p/552073#M112362</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-08-01T13:35:53Z</dc:date>
    </item>
    <item>
      <title>Re: Peer certificate chain building failed due to unable to get local issuer certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/peer-certificate-chain-building-failed-due-to-unable-to-get/m-p/552079#M112364</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/77347"&gt;@TomYoung&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes, both my satellite firewalls (working and non-working) are one and the same 11.x.x version.&lt;/P&gt;
&lt;P&gt;The hub however is on 10.x.x. Thanks for the suggestion, I'll try to see what an upgrade would do for me.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Aug 2023 13:53:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/peer-certificate-chain-building-failed-due-to-unable-to-get/m-p/552079#M112364</guid>
      <dc:creator>GeorgeAPH</dc:creator>
      <dc:date>2023-08-01T13:53:54Z</dc:date>
    </item>
    <item>
      <title>Re: Peer certificate chain building failed due to unable to get local issuer certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/peer-certificate-chain-building-failed-due-to-unable-to-get/m-p/577748#M115934</link>
      <description>&lt;P&gt;Hi guys:)&lt;BR /&gt;&lt;BR /&gt;Do you have some updates about this problem?&lt;/P&gt;</description>
      <pubDate>Tue, 20 Feb 2024 13:05:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/peer-certificate-chain-building-failed-due-to-unable-to-get/m-p/577748#M115934</guid>
      <dc:creator>Parsek</dc:creator>
      <dc:date>2024-02-20T13:05:01Z</dc:date>
    </item>
    <item>
      <title>Re: Peer certificate chain building failed due to unable to get local issuer certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/peer-certificate-chain-building-failed-due-to-unable-to-get/m-p/580922#M116308</link>
      <description>&lt;P&gt;Hi TomYoung,&lt;/P&gt;
&lt;P&gt;I have a customer facing same issue with EDL certificate, I saw you post here as well&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/next-generation-firewall/edl-unable-to-get-local-issuer-certificate/td-p/540800" target="_blank"&gt;https://live.paloaltonetworks.com/t5/next-generation-firewall/edl-unable-to-get-local-issuer-certificate/td-p/540800&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The customer is not willing to upgrade without knowing the bug ID, do you have it?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you in advance.&lt;/P&gt;
&lt;P&gt;Best regards&lt;/P&gt;
&lt;P&gt;Angelo Oghittu&lt;/P&gt;</description>
      <pubDate>Tue, 19 Mar 2024 14:45:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/peer-certificate-chain-building-failed-due-to-unable-to-get/m-p/580922#M116308</guid>
      <dc:creator>AngeloOghittu</dc:creator>
      <dc:date>2024-03-19T14:45:19Z</dc:date>
    </item>
    <item>
      <title>Re: Peer certificate chain building failed due to unable to get local issuer certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/peer-certificate-chain-building-failed-due-to-unable-to-get/m-p/580936#M116309</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/116295"&gt;@AngeloOghittu&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;TAC would not give me a bug ID.&amp;nbsp; I would send the customer this link -&amp;gt; and encourage they upgrade to the recommended version.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Tue, 19 Mar 2024 16:03:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/peer-certificate-chain-building-failed-due-to-unable-to-get/m-p/580936#M116309</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2024-03-19T16:03:48Z</dc:date>
    </item>
    <item>
      <title>Re: Peer certificate chain building failed due to unable to get local issuer certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/peer-certificate-chain-building-failed-due-to-unable-to-get/m-p/581067#M116330</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/77347"&gt;@TomYoung&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;thank you for your reply. The problem is that the customer is not willing to upgrade to the recommended version due to another bug and&amp;nbsp;&lt;/P&gt;
&lt;P&gt;because need to know the issue ID.&lt;/P&gt;
&lt;P&gt;I think I should contact the TAC at this point.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Br&lt;/P&gt;
&lt;P&gt;Angelo&lt;/P&gt;</description>
      <pubDate>Wed, 20 Mar 2024 14:40:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/peer-certificate-chain-building-failed-due-to-unable-to-get/m-p/581067#M116330</guid>
      <dc:creator>AngeloOghittu</dc:creator>
      <dc:date>2024-03-20T14:40:14Z</dc:date>
    </item>
  </channel>
</rss>

