<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic TPM public key match failed in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/tpm-public-key-match-failed/m-p/1239222#M125256</link>
    <description>&lt;P&gt;I have two PA-400 series devices that failed to renew their device certificates and now I get "TPM public key match failed" when trying to renew their certs.&amp;nbsp; Any way to fix this on my own?&amp;nbsp; I see some posts saying PA support had to fix it, but as of now my 3rd party support provider is being unresponsive&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":unamused_face:"&gt;😒&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 01 Oct 2025 18:32:02 GMT</pubDate>
    <dc:creator>S.Hodgson131490</dc:creator>
    <dc:date>2025-10-01T18:32:02Z</dc:date>
    <item>
      <title>TPM public key match failed</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tpm-public-key-match-failed/m-p/1239222#M125256</link>
      <description>&lt;P&gt;I have two PA-400 series devices that failed to renew their device certificates and now I get "TPM public key match failed" when trying to renew their certs.&amp;nbsp; Any way to fix this on my own?&amp;nbsp; I see some posts saying PA support had to fix it, but as of now my 3rd party support provider is being unresponsive&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":unamused_face:"&gt;😒&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Oct 2025 18:32:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tpm-public-key-match-failed/m-p/1239222#M125256</guid>
      <dc:creator>S.Hodgson131490</dc:creator>
      <dc:date>2025-10-01T18:32:02Z</dc:date>
    </item>
    <item>
      <title>Re: TPM public key match failed</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tpm-public-key-match-failed/m-p/1239352#M125269</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/740637157"&gt;@S.Hodgson131490&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You could try with a commit force.&amp;nbsp; I've seen reports where it resolved this issue.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Worst case you'll have to connect with support in order for them to root into the device&amp;nbsp;to e&lt;SPAN&gt;rase/remove the existing invalid device certificate&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;and then r&lt;/SPAN&gt;&lt;SPAN&gt;e-generate the device certificate with a new OTP.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Hope this works !&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;-Kim.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Oct 2025 13:43:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tpm-public-key-match-failed/m-p/1239352#M125269</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2025-10-03T13:43:38Z</dc:date>
    </item>
    <item>
      <title>Re: TPM public key match failed</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tpm-public-key-match-failed/m-p/1239464#M125282</link>
      <description>&lt;P&gt;I had already tried a commit force and it changed nothing.&amp;nbsp; Ultimately, I was able to convince Palo Alto to handle my case directly since my provider is still dragging their feet.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Indeed Palo Alto support must go through a challenge/response process to gain root access to the device in order to clear out the old cert and generate a new one.&amp;nbsp; I asked and this seems to be a regular problem.&amp;nbsp; I'm not sure why Palo Alto wouldn't prioritize a proper fix for this issue both to alleviate support load and to enable their customers to continue working.&amp;nbsp; Since the device certificate was preventing a successful CIE sync, all VPN user/group addition/removals were blocked until we could get support's attention to fix the issue.&amp;nbsp; This should not be an acceptable bug to leave in the product.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Oct 2025 13:04:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tpm-public-key-match-failed/m-p/1239464#M125282</guid>
      <dc:creator>S.Hodgson131490</dc:creator>
      <dc:date>2025-10-06T13:04:11Z</dc:date>
    </item>
  </channel>
</rss>

