<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Problem with the DuckDNS certificate for the DDNS service. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/problem-with-the-duckdns-certificate-for-the-ddns-service/m-p/1234291#M124799</link>
    <description>&lt;P data-start="660" data-end="899"&gt;Hi,&lt;BR data-start="663" data-end="666" /&gt;I'm having an issue with Palo Alto and DDNS — specifically with DuckDNS. Everything had been working fine for the past two years, but for about a month now, Palo Alto is showing an SSL certificate error.&lt;BR data-start="869" data-end="872" /&gt;The exact error message is:&lt;/P&gt;
&lt;P data-start="901" data-end="989"&gt;&lt;STRONG data-start="901" data-end="989"&gt;Server response: Peer certificate cannot be authenticated with given CA certificates&lt;/STRONG&gt;&lt;/P&gt;
&lt;P data-start="991" data-end="1102"&gt;I’m not sure which certificate I should be using to fix this.&lt;BR data-start="1052" data-end="1055" /&gt;Has anyone encountered and resolved this issue?&lt;/P&gt;</description>
    <pubDate>Fri, 18 Jul 2025 08:21:14 GMT</pubDate>
    <dc:creator>A.Kuszaj</dc:creator>
    <dc:date>2025-07-18T08:21:14Z</dc:date>
    <item>
      <title>Problem with the DuckDNS certificate for the DDNS service.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-with-the-duckdns-certificate-for-the-ddns-service/m-p/1234291#M124799</link>
      <description>&lt;P data-start="660" data-end="899"&gt;Hi,&lt;BR data-start="663" data-end="666" /&gt;I'm having an issue with Palo Alto and DDNS — specifically with DuckDNS. Everything had been working fine for the past two years, but for about a month now, Palo Alto is showing an SSL certificate error.&lt;BR data-start="869" data-end="872" /&gt;The exact error message is:&lt;/P&gt;
&lt;P data-start="901" data-end="989"&gt;&lt;STRONG data-start="901" data-end="989"&gt;Server response: Peer certificate cannot be authenticated with given CA certificates&lt;/STRONG&gt;&lt;/P&gt;
&lt;P data-start="991" data-end="1102"&gt;I’m not sure which certificate I should be using to fix this.&lt;BR data-start="1052" data-end="1055" /&gt;Has anyone encountered and resolved this issue?&lt;/P&gt;</description>
      <pubDate>Fri, 18 Jul 2025 08:21:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-with-the-duckdns-certificate-for-the-ddns-service/m-p/1234291#M124799</guid>
      <dc:creator>A.Kuszaj</dc:creator>
      <dc:date>2025-07-18T08:21:14Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with the DuckDNS certificate for the DDNS service.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-with-the-duckdns-certificate-for-the-ddns-service/m-p/1234298#M124800</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/839806719"&gt;@A.Kuszaj&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Root and intermediate CA certificates expire, or new ones are issued, and the Palo Alto firewall's trusted CA store needs to be updated to reflect these changes. Since it was working for two years and stopped about a month ago, it's probable that a certificate in DuckDNS's chain either expired or was updated, and your firewall hasn't updated its trusted CA store accordingly.&amp;nbsp;&amp;nbsp;&lt;SPAN&gt;Possibly you may have to install and set the Intermediate Certificate as a Trusted Route CA.&amp;nbsp; You may have to delete and recreate the Certificate Profile for this to take effect.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here are a few things you can check:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Clarify which certificate chain you have installed to the firewall ? Refer to the article link to install correct intermediate CA on the firewall:&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cm66CAC" target="_blank" rel="noopener" data-aura-rendered-by="150:27498;a"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cm66CAC&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Validate the DDNS configurations referring to this document link:&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/networking/configure-dynamic-dns-for-firewall-interfaces" target="_blank" rel="noopener" data-aura-rendered-by="150:27498;a"&gt;https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/networking/configure-dynamic-dns-for-firewall-interfaces&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;Please refer to this article link providing resolution for Error message: Peer certificate cannot be authenticated with given CA certificates:&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PLz3CAG&amp;amp;lang=en_US%E2%80%A9" target="_blank" rel="noopener" data-aura-rendered-by="150:27498;a"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PLz3CAG&amp;amp;lang=en_US%E2%80%A9&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps,&lt;/P&gt;
&lt;P&gt;-Kim.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Jul 2025 08:41:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-with-the-duckdns-certificate-for-the-ddns-service/m-p/1234298#M124800</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2025-07-18T08:41:16Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with the DuckDNS certificate for the DDNS service.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-with-the-duckdns-certificate-for-the-ddns-service/m-p/1234786#M124848</link>
      <description>&lt;P&gt;I had the same issue. You'll need the "&lt;SPAN&gt;Amazon RSA 2048 M02" and "Amazon Root CA 1"&amp;nbsp;and create a new cert profile for DuckDNS.&amp;nbsp;&lt;/SPAN&gt;Click the download link next to "Additional Certificates (if supplied)". Copy the middle and last cert in the chain and create new PEM files in notepad.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.ssllabs.com/ssltest/analyze.html?d=duckdns.org" target="_blank"&gt;SSL Server Test: duckdns.org (Powered by Qualys SSL Labs)&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jul 2025 14:17:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-with-the-duckdns-certificate-for-the-ddns-service/m-p/1234786#M124848</guid>
      <dc:creator>akolodziej</dc:creator>
      <dc:date>2025-07-28T14:17:41Z</dc:date>
    </item>
  </channel>
</rss>

