<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: EDL server certificate authentication failed. A local copy of associated external dynamic list will be used in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/edl-server-certificate-authentication-failed-a-local-copy-of/m-p/1234706#M124838</link>
    <description>&lt;P&gt;FYI, We have just identified that this issue appears to be related to the internal logging and alerting process in the firewall rather than an actual fault with the firewall successfully accessing and updating the EDL from the cortex tenant. We noticed that while we are getting email alerts for the issue every hour, (which is how often the cortex EDLs are set to update) the system logs in the firewall do not show any further alerts for this issue since July 15th. We then created a new entry into the domain EBL in cortex as testbad.com, logged into the firewall, checked the EDL and then clicked import now and the new domain showed up in the list on the firewall.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;TLDR; even though we continue to get email alerts regarding Cortex EDL Sources failing to authenticate due to self signed cert, the firewall is downloading them anyway.&lt;/P&gt;</description>
    <pubDate>Fri, 25 Jul 2025 15:03:01 GMT</pubDate>
    <dc:creator>ycgmis</dc:creator>
    <dc:date>2025-07-25T15:03:01Z</dc:date>
    <item>
      <title>EDL server certificate authentication failed. A local copy of associated external dynamic list will be used</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/edl-server-certificate-authentication-failed-a-local-copy-of/m-p/1233923#M124755</link>
      <description>&lt;P&gt;I'm receiving this error from our firewall every 2 minutes, I can't figure out what the cause is. The reason says "self signed certificate in certificate chain" but I don't know what self signed cert it is talking about. This has been working for years now, the cert selected on the firewall is the GoDaddy root from&amp;nbsp;&lt;A class="link ft-external-link" href="https://certs.godaddy.com/repository/gd-class2-root.crt" target="_blank" rel="noopener"&gt;https://certs.godaddy.com/repository/gd-class2-root.crt&lt;/A&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The source URL is copied our Cortex XDR settings&lt;/P&gt;
&lt;P&gt;&lt;A href="https://edl-hxdr.xdr.us.paloaltonetworks.com/block_list?type=domain" target="_blank"&gt;https://EDL-MyXDRInstance.paloaltonetworks.com/block_list?type=domain&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;'EDL server certificate authentication failed. A local copy of associated external dynamic list will be used, so it won\'t impact your policy. EDL Name: Cortex Domains, EDL Source URL: https://&amp;lt;edl&amp;gt;.paloaltonetworks.com/block_list?type=domain, CN: *.xdr.us.paloaltonetworks.com, Reason: self signed certificate in certificate chain&lt;/P&gt;</description>
      <pubDate>Mon, 14 Jul 2025 13:13:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/edl-server-certificate-authentication-failed-a-local-copy-of/m-p/1233923#M124755</guid>
      <dc:creator>DopedWafer</dc:creator>
      <dc:date>2025-07-14T13:13:56Z</dc:date>
    </item>
    <item>
      <title>Re: EDL server certificate authentication failed. A local copy of associated external dynamic list will be used</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/edl-server-certificate-authentication-failed-a-local-copy-of/m-p/1233924#M124756</link>
      <description>&lt;P&gt;Realizing now that it seems to have stopped at 5am CST this morning, so maybe this is resolved?&lt;/P&gt;</description>
      <pubDate>Mon, 14 Jul 2025 13:52:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/edl-server-certificate-authentication-failed-a-local-copy-of/m-p/1233924#M124756</guid>
      <dc:creator>DopedWafer</dc:creator>
      <dc:date>2025-07-14T13:52:49Z</dc:date>
    </item>
    <item>
      <title>Re: EDL server certificate authentication failed. A local copy of associated external dynamic list will be used</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/edl-server-certificate-authentication-failed-a-local-copy-of/m-p/1234258#M124791</link>
      <description>&lt;P&gt;On same day we also encountered this issue related to the EDL and we also using external go daddy certificate. Have you found any fix from TAC?&lt;/P&gt;
&lt;P&gt;We reached out to TAC and trying to find the root cause.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jul 2025 12:30:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/edl-server-certificate-authentication-failed-a-local-copy-of/m-p/1234258#M124791</guid>
      <dc:creator>S.Venkatesan</dc:creator>
      <dc:date>2025-07-17T12:30:25Z</dc:date>
    </item>
    <item>
      <title>Re: EDL server certificate authentication failed. A local copy of associated external dynamic list will be used</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/edl-server-certificate-authentication-failed-a-local-copy-of/m-p/1234263#M124792</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The digital certificate presented by edl-hxdr.xdr.us.paloaltonetworks.com has a chain issue.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.ssllabs.com/ssltest/analyze.html?d=edl-hxdr.xdr.us.paloaltonetworks.com" target="_blank" rel="noopener"&gt;https://www.ssllabs.com/ssltest/analyze.html?d=edl-hxdr.xdr.us.paloaltonetworks.com&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To fix that you need to download the intermediate authority certificate and to import into your firewall, then mark the imported certificate as Trust Root CA Certificate.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To help you, I already downloaded the intermediate authority certificate and you can take it from this comment. Just unzip and upload the extracted certificate to your firewall.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you want to know more how to fix incomplete chain issues, please have a look here:&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/network-security/decryption/administration/troubleshooting-decryption/repair-incomplete-certificate-chains#repair-incomplete-certificate-chains-pan-os" target="_blank" rel="noopener"&gt;Repair Incomplete Certificate Chains&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jul 2025 15:08:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/edl-server-certificate-authentication-failed-a-local-copy-of/m-p/1234263#M124792</guid>
      <dc:creator>CosminM</dc:creator>
      <dc:date>2025-07-17T15:08:21Z</dc:date>
    </item>
    <item>
      <title>Re: EDL server certificate authentication failed. A local copy of associated external dynamic list will be used</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/edl-server-certificate-authentication-failed-a-local-copy-of/m-p/1234486#M124818</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/197789"&gt;@CosminM&lt;/a&gt;&amp;nbsp;we have tried that procedure and it work it until we referenced the&amp;nbsp;intermediate authority certificate into the certificate profile associated to the EDL. That was on a PA-440 without decryption.&lt;BR /&gt;&lt;BR /&gt;We are trying to stop this alert on a PA-3220 with the same procedure but we still having the alert.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Has anyone fix this issue ?&lt;/P&gt;</description>
      <pubDate>Tue, 22 Jul 2025 18:39:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/edl-server-certificate-authentication-failed-a-local-copy-of/m-p/1234486#M124818</guid>
      <dc:creator>Suscripciones</dc:creator>
      <dc:date>2025-07-22T18:39:18Z</dc:date>
    </item>
    <item>
      <title>Re: EDL server certificate authentication failed. A local copy of associated external dynamic list will be used</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/edl-server-certificate-authentication-failed-a-local-copy-of/m-p/1234660#M124830</link>
      <description>&lt;P&gt;We began having the same issue on our 3220. The certificate path has apparently changed. Before it was using GlobalSign. Now it's pointing to Godaddy. We have a TAC case open but the TAC doesn't seem to know what the issue is either. I've tried the suggested fixes, including the one on this thread but still no luck.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jul 2025 20:16:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/edl-server-certificate-authentication-failed-a-local-copy-of/m-p/1234660#M124830</guid>
      <dc:creator>ycgmis</dc:creator>
      <dc:date>2025-07-24T20:16:59Z</dc:date>
    </item>
    <item>
      <title>Re: EDL server certificate authentication failed. A local copy of associated external dynamic list will be used</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/edl-server-certificate-authentication-failed-a-local-copy-of/m-p/1234706#M124838</link>
      <description>&lt;P&gt;FYI, We have just identified that this issue appears to be related to the internal logging and alerting process in the firewall rather than an actual fault with the firewall successfully accessing and updating the EDL from the cortex tenant. We noticed that while we are getting email alerts for the issue every hour, (which is how often the cortex EDLs are set to update) the system logs in the firewall do not show any further alerts for this issue since July 15th. We then created a new entry into the domain EBL in cortex as testbad.com, logged into the firewall, checked the EDL and then clicked import now and the new domain showed up in the list on the firewall.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;TLDR; even though we continue to get email alerts regarding Cortex EDL Sources failing to authenticate due to self signed cert, the firewall is downloading them anyway.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Jul 2025 15:03:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/edl-server-certificate-authentication-failed-a-local-copy-of/m-p/1234706#M124838</guid>
      <dc:creator>ycgmis</dc:creator>
      <dc:date>2025-07-25T15:03:01Z</dc:date>
    </item>
  </channel>
</rss>

