<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Global protect VPN server certificate error in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-vpn-server-certificate-error/m-p/590490#M117629</link>
    <description>&lt;P&gt;I agree with&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;if this is an existing deployment with nothing new it seems odd that this error is just randomly occurring.&amp;nbsp; At face value there's 2 things going on here.&amp;nbsp; Either the certificate being presented by the firewall isn't trusted by the machine that's trying to connect to the VPN (meaning you are missing at least one of the following in the local machine cert store:&amp;nbsp; root, intermediate, or issuer.)&amp;nbsp; Option 2 is the certificate is expired and inherently will be untrusted.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There are be other more intricate issues like&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;mentioned with the cert name not matching the SN/SAN (subject alternative name)&amp;nbsp; -- This wouldn't make sense though to "just have broken" with nothing else being changed.&lt;/P&gt;</description>
    <pubDate>Wed, 26 Jun 2024 14:21:21 GMT</pubDate>
    <dc:creator>Brandon_Wertz</dc:creator>
    <dc:date>2024-06-26T14:21:21Z</dc:date>
    <item>
      <title>Global protect VPN server certificate error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-vpn-server-certificate-error/m-p/590350#M117603</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am new to this community I am here to get some help on a issue I am experiencing with my organization vpn network gp vpn server certificate is not trusted.&lt;/P&gt;
&lt;P&gt;Here is the error screenshot.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 294px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/60496iD4863806A967E2A5/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Any help to troubleshoot this issue would be greatly appreciated &lt;span class="lia-unicode-emoji" title=":thumbs_up:"&gt;👍&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Sanjib&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jun 2024 18:27:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-vpn-server-certificate-error/m-p/590350#M117603</guid>
      <dc:creator>Sanjib1549</dc:creator>
      <dc:date>2024-06-25T18:27:23Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect VPN server certificate error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-vpn-server-certificate-error/m-p/590355#M117604</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/303416993"&gt;@Sanjib1549&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;I'm assuming that this is a new configuration and not an existing configuration. You'll either need to get a certificate that is signed by a public trusted certificate authority, an internal certificate authority trusted by your endpoints, or utilize a self-signed certificate and deploy out the certificate to your endpoints.&lt;/P&gt;
&lt;P&gt;I don't recommend utilizing an IP for VPN personally and would recommend setting up an FQDN, but if you're going to utilize an IP it needs to be listed as a SAN for modern browsers to accept it as well. I wouldn't recommend relying solely on IP instead of a DNS entry in a production environment however.&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jun 2024 19:26:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-vpn-server-certificate-error/m-p/590355#M117604</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2024-06-25T19:26:49Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect VPN server certificate error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-vpn-server-certificate-error/m-p/590470#M117626</link>
      <description>&lt;P&gt;Thanks for your assistance it is actually not a new configuration I am actually need some references article or documents if I can get a that will be helpful.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Sanjib&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jun 2024 12:29:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-vpn-server-certificate-error/m-p/590470#M117626</guid>
      <dc:creator>Sanjib1549</dc:creator>
      <dc:date>2024-06-26T12:29:23Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect VPN server certificate error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-vpn-server-certificate-error/m-p/590490#M117629</link>
      <description>&lt;P&gt;I agree with&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;if this is an existing deployment with nothing new it seems odd that this error is just randomly occurring.&amp;nbsp; At face value there's 2 things going on here.&amp;nbsp; Either the certificate being presented by the firewall isn't trusted by the machine that's trying to connect to the VPN (meaning you are missing at least one of the following in the local machine cert store:&amp;nbsp; root, intermediate, or issuer.)&amp;nbsp; Option 2 is the certificate is expired and inherently will be untrusted.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There are be other more intricate issues like&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;mentioned with the cert name not matching the SN/SAN (subject alternative name)&amp;nbsp; -- This wouldn't make sense though to "just have broken" with nothing else being changed.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jun 2024 14:21:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-vpn-server-certificate-error/m-p/590490#M117629</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2024-06-26T14:21:21Z</dc:date>
    </item>
  </channel>
</rss>

