<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Authentication Failure at Home Network in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/authentication-failure-at-home-network/m-p/1256858#M126630</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1667123005"&gt;@omkar15525&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-path-to-node="15"&gt;The error &lt;CODE data-index-in-node="10" data-path-to-node="16"&gt;12019&lt;/CODE&gt;&amp;nbsp;indicates that the client certificate authentication process is failing. The gateway is requesting a client certificate, but it cannot be found, accessed, or successfully validated over your home network.&lt;/P&gt;
&lt;P data-path-to-node="15"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-path-to-node="17"&gt;Since this works on the office network, please verify the client certificate configuration using this guide&lt;SPAN&gt;:&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClFoCAK" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClFoCAK&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Before modifying anything, I recommend to open a support case with TAC and provide your GlobalProtect logs so they can identify&amp;nbsp;the exact certificate error or missing chain component without you needing to guess.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've seen scenarios where duplicate certificate entries in the store cause this exact issue. For pre-logon connections, if multiple matching certificates exist (e.g., an expired one or one with a missing key associated with the cert), PanGPS will pick the first match it finds. If you locate invalid duplicates via &lt;FONT color="#000000"&gt;&lt;STRONG&gt;certutil&lt;/STRONG&gt;&lt;/FONT&gt; that aren't showing up in the MMC graphics window, you can clean them out of the registry.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Check the MMC on the PC and make sure to have the valid certificate installed in the Machine store with its private key. If you are sure that the certificate is valid and the key exists, dump the whole machine certificate store with &lt;FONT color="#000000"&gt;certutil&lt;/FONT&gt; to see if there are any duplicates that could be the cause of the issue.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If such certificates are seen in the certutil output and registry but not on MMC, delete the unnecessary ones from the registry and leave only the one which is intended for pre-logon certificate authentication. Don't make any changes for any other certificates which might be used for other purposes !&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG data-index-in-node="3" data-path-to-node="11,0"&gt;Note:&lt;/STRONG&gt; Modifying the Windows Registry and deleting certificate objects carries a risk of breaking other system functionalities or authentication mechanisms. If you are not a administrator, then please forward this information to your internal IT Helpdesk or an administrator to assist you with the cleanup, if needed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Ultimately, with the lack of current information it's impossible for me to be sure what the issue is. Please prioritize opening a support case first. Having TAC analyze the log package is the safest step to pinpoint the exact failure before doing any manual registry or certificate troubleshooting.&lt;BR /&gt;&lt;BR /&gt;Best regards,&lt;/P&gt;</description>
    <pubDate>Fri, 19 Jun 2026 14:50:30 GMT</pubDate>
    <dc:creator>kiwi</dc:creator>
    <dc:date>2026-06-19T14:50:30Z</dc:date>
    <item>
      <title>Authentication Failure at Home Network</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/authentication-failure-at-home-network/m-p/1256779#M126626</link>
      <description>&lt;P&gt;My Authentication does work correctly on Office Network, But It does not work on my Home Network. Lan Cable, Wifi and Mobile Hotspot does not work at all.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I did drop a mail from my official email id, somebody please help.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jun 2026 02:47:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/authentication-failure-at-home-network/m-p/1256779#M126626</guid>
      <dc:creator>omkar15525</dc:creator>
      <dc:date>2026-06-19T02:47:51Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication Failure at Home Network</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/authentication-failure-at-home-network/m-p/1256843#M126627</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1667123005"&gt;@omkar15525&lt;/a&gt;&amp;nbsp;,&lt;BR /&gt;&lt;BR /&gt;Can you provide more info ? Guessing you're talking about Prisma Access Agent ?&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P data-path-to-node="4"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-path-to-node="5"&gt;Did you check your agent logs to see exactly where the connection is breaking.&lt;/P&gt;
&lt;P data-path-to-node="6"&gt;When you have a moment on your home network, please pull the logs and verify if you have more info in there.&lt;/P&gt;
&lt;P data-path-to-node="6"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-path-to-node="6"&gt;When the connection fails at home, what exact message does the agent display? (e.g., &lt;I data-index-in-node="89" data-path-to-node="12"&gt;"Connecting..." indefinitely, "Gateway not reachable," "Invalid username or password," or a specific certificate error?&lt;/I&gt;)&lt;BR /&gt;&lt;BR /&gt;Kind regards,&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jun 2026 11:47:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/authentication-failure-at-home-network/m-p/1256843#M126627</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2026-06-19T11:47:57Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication Failure at Home Network</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/authentication-failure-at-home-network/m-p/1256856#M126629</link>
      <description>&lt;P&gt;I see the error as: Couldnt Query the server certificate chain. This could be due to network configuration decrypting the SSL connection between this machine and the server agents.den.prismaaccess.com (12019)&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jun 2026 14:01:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/authentication-failure-at-home-network/m-p/1256856#M126629</guid>
      <dc:creator>omkar15525</dc:creator>
      <dc:date>2026-06-19T14:01:24Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication Failure at Home Network</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/authentication-failure-at-home-network/m-p/1256858#M126630</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1667123005"&gt;@omkar15525&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-path-to-node="15"&gt;The error &lt;CODE data-index-in-node="10" data-path-to-node="16"&gt;12019&lt;/CODE&gt;&amp;nbsp;indicates that the client certificate authentication process is failing. The gateway is requesting a client certificate, but it cannot be found, accessed, or successfully validated over your home network.&lt;/P&gt;
&lt;P data-path-to-node="15"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-path-to-node="17"&gt;Since this works on the office network, please verify the client certificate configuration using this guide&lt;SPAN&gt;:&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClFoCAK" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClFoCAK&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Before modifying anything, I recommend to open a support case with TAC and provide your GlobalProtect logs so they can identify&amp;nbsp;the exact certificate error or missing chain component without you needing to guess.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've seen scenarios where duplicate certificate entries in the store cause this exact issue. For pre-logon connections, if multiple matching certificates exist (e.g., an expired one or one with a missing key associated with the cert), PanGPS will pick the first match it finds. If you locate invalid duplicates via &lt;FONT color="#000000"&gt;&lt;STRONG&gt;certutil&lt;/STRONG&gt;&lt;/FONT&gt; that aren't showing up in the MMC graphics window, you can clean them out of the registry.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Check the MMC on the PC and make sure to have the valid certificate installed in the Machine store with its private key. If you are sure that the certificate is valid and the key exists, dump the whole machine certificate store with &lt;FONT color="#000000"&gt;certutil&lt;/FONT&gt; to see if there are any duplicates that could be the cause of the issue.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If such certificates are seen in the certutil output and registry but not on MMC, delete the unnecessary ones from the registry and leave only the one which is intended for pre-logon certificate authentication. Don't make any changes for any other certificates which might be used for other purposes !&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG data-index-in-node="3" data-path-to-node="11,0"&gt;Note:&lt;/STRONG&gt; Modifying the Windows Registry and deleting certificate objects carries a risk of breaking other system functionalities or authentication mechanisms. If you are not a administrator, then please forward this information to your internal IT Helpdesk or an administrator to assist you with the cleanup, if needed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Ultimately, with the lack of current information it's impossible for me to be sure what the issue is. Please prioritize opening a support case first. Having TAC analyze the log package is the safest step to pinpoint the exact failure before doing any manual registry or certificate troubleshooting.&lt;BR /&gt;&lt;BR /&gt;Best regards,&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jun 2026 14:50:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/authentication-failure-at-home-network/m-p/1256858#M126630</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2026-06-19T14:50:30Z</dc:date>
    </item>
  </channel>
</rss>

