<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Enterprise PKI Cert Chain Error in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/enterprise-pki-cert-chain-error/m-p/558273#M113234</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/152128"&gt;@RVizcarra&lt;/a&gt;&amp;nbsp;Yes.. I uploaded certificates one by one, starting from the device cert, then intermediate cert and then the root cert.&lt;/P&gt;</description>
    <pubDate>Mon, 18 Sep 2023 04:36:08 GMT</pubDate>
    <dc:creator>rjdahav163</dc:creator>
    <dc:date>2023-09-18T04:36:08Z</dc:date>
    <item>
      <title>Enterprise PKI Cert Chain Error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/enterprise-pki-cert-chain-error/m-p/188301#M57170</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;we have our enterprise CA and our PA firewalls have signed certs from it. Now for our captive portal, we also have a certi signed from our enterprise CA. Everything works and there is no browser error for certificate.&lt;/P&gt;&lt;P&gt;But in the FW commit, we get a warning "&lt;SPAN&gt;Warning: cannot find complete certificate chain for certificate&amp;nbsp;...&lt;/SPAN&gt;"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I found the following KB for a Public CA&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/How-to-Install-a-Chained-Certificate-Signed-by-a-Public-CA/ta-p/55523" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/How-to-Install-a-Chained-Certificate-Signed-by-a-Public-CA/ta-p/55523&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and I also tried the Workaround mentioned at the bottom of the KB, but it does not work.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any suggestions?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks and Regards,&lt;/P&gt;&lt;P&gt;R&lt;/P&gt;</description>
      <pubDate>Wed, 22 Nov 2017 09:41:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/enterprise-pki-cert-chain-error/m-p/188301#M57170</guid>
      <dc:creator>rjdahav163</dc:creator>
      <dc:date>2017-11-22T09:41:43Z</dc:date>
    </item>
    <item>
      <title>Re: Enterprise PKI Cert Chain Error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/enterprise-pki-cert-chain-error/m-p/188310#M57172</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/44973"&gt;@rjdahav163&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My advice would be to take a look at the certificate hierarchy in Windows, are you seeing the full chain there that is expected when you open up the file?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Example here, taken from the live community website:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="certhier.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/12577i15B15BB9535653C1/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="certhier.png" alt="certhier.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;hope this helps,&lt;/P&gt;&lt;P&gt;Ben&lt;/P&gt;</description>
      <pubDate>Wed, 22 Nov 2017 09:52:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/enterprise-pki-cert-chain-error/m-p/188310#M57172</guid>
      <dc:creator>bmorris1</dc:creator>
      <dc:date>2017-11-22T09:52:36Z</dc:date>
    </item>
    <item>
      <title>Re: Enterprise PKI Cert Chain Error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/enterprise-pki-cert-chain-error/m-p/188317#M57176</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/5403"&gt;@bmorris1&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes I see the complete chain in the hierarchy as expected and installed the same on FW but still firewall complains. &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;R&lt;/P&gt;</description>
      <pubDate>Wed, 22 Nov 2017 10:34:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/enterprise-pki-cert-chain-error/m-p/188317#M57176</guid>
      <dc:creator>rjdahav163</dc:creator>
      <dc:date>2017-11-22T10:34:55Z</dc:date>
    </item>
    <item>
      <title>Re: Enterprise PKI Cert Chain Error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/enterprise-pki-cert-chain-error/m-p/547374#M111811</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/44973"&gt;@rjdahav163&lt;/a&gt; , have you resolved this issue? I'm having the same.&lt;/P&gt;</description>
      <pubDate>Tue, 27 Jun 2023 07:47:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/enterprise-pki-cert-chain-error/m-p/547374#M111811</guid>
      <dc:creator>RVizcarra</dc:creator>
      <dc:date>2023-06-27T07:47:14Z</dc:date>
    </item>
    <item>
      <title>Re: Enterprise PKI Cert Chain Error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/enterprise-pki-cert-chain-error/m-p/558273#M113234</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/152128"&gt;@RVizcarra&lt;/a&gt;&amp;nbsp;Yes.. I uploaded certificates one by one, starting from the device cert, then intermediate cert and then the root cert.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Sep 2023 04:36:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/enterprise-pki-cert-chain-error/m-p/558273#M113234</guid>
      <dc:creator>rjdahav163</dc:creator>
      <dc:date>2023-09-18T04:36:08Z</dc:date>
    </item>
    <item>
      <title>Re: Enterprise PKI Cert Chain Error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/enterprise-pki-cert-chain-error/m-p/558359#M113254</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/44973"&gt;@rjdahav163&lt;/a&gt; , &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/152128"&gt;@RVizcarra&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;I have noticed that when generating certificate from our internal Windows PKI and opeing the cert with text editor it looks like PKI is listing the full chain (the root, the intermiediate, the server and then the key), but the order is wrong. In my experience the root and the intermediate order was mixed and if put them in correct order (root, intermediate, server) and&amp;nbsp; then upload it palo fw. After that the warning is gone.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Sep 2023 11:57:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/enterprise-pki-cert-chain-error/m-p/558359#M113254</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2023-09-18T11:57:40Z</dc:date>
    </item>
  </channel>
</rss>

