<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Unable to Commit Changes after Installing New Certificate in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-commit-changes-after-installing-new-certificate/m-p/1263683#M126970</link>
    <description>&lt;P&gt;I was asked to assist with a new wildcard certificate that was uploaded to the firewall yesterday, update the SSL/TLS Service Profile and confirmed settings for GP.&amp;nbsp; Commit failed so began reviewing configuration. The 2 reasons listed for the failure were:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;client useridd phase 1 failure&lt;BR /&gt;client gp_broker phase 1 failure&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Double checking and the wildcard certificate was set active for the Authentication Override between the GP Portal and Gateway; reverted to the old certificate and the that error cleared.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;While looking into the other commit error was for found that the SSL/TLS profile had been used in the user-id settings for the server monitor section.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I was able to create a new SSL/TLS profile using the new correct certificate and confirmed that is now working for the GP login page, but would like to get the other 2 errors corrected so I can remove the expired certificates.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What I did notice is that if I select TLS 1.3 as the maximum version for in the SSL/TLS profile, the new profile isn't listed as an option in the User-ID Syslog Service Profile drop down.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Both old and new certificates are from the same CA.&amp;nbsp; The only real difference I see between the 2 certificates is that the old certificate had the following SANs:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;*.mydomain.org&lt;/P&gt;
&lt;P&gt;mydomain.org&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;While the new only has *.mydomain.org.&lt;/P&gt;</description>
    <pubDate>Fri, 04 Sep 2026 13:45:43 GMT</pubDate>
    <dc:creator>DJ_1924</dc:creator>
    <dc:date>2026-09-04T13:45:43Z</dc:date>
    <item>
      <title>Unable to Commit Changes after Installing New Certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-commit-changes-after-installing-new-certificate/m-p/1263683#M126970</link>
      <description>&lt;P&gt;I was asked to assist with a new wildcard certificate that was uploaded to the firewall yesterday, update the SSL/TLS Service Profile and confirmed settings for GP.&amp;nbsp; Commit failed so began reviewing configuration. The 2 reasons listed for the failure were:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;client useridd phase 1 failure&lt;BR /&gt;client gp_broker phase 1 failure&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Double checking and the wildcard certificate was set active for the Authentication Override between the GP Portal and Gateway; reverted to the old certificate and the that error cleared.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;While looking into the other commit error was for found that the SSL/TLS profile had been used in the user-id settings for the server monitor section.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I was able to create a new SSL/TLS profile using the new correct certificate and confirmed that is now working for the GP login page, but would like to get the other 2 errors corrected so I can remove the expired certificates.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What I did notice is that if I select TLS 1.3 as the maximum version for in the SSL/TLS profile, the new profile isn't listed as an option in the User-ID Syslog Service Profile drop down.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Both old and new certificates are from the same CA.&amp;nbsp; The only real difference I see between the 2 certificates is that the old certificate had the following SANs:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;*.mydomain.org&lt;/P&gt;
&lt;P&gt;mydomain.org&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;While the new only has *.mydomain.org.&lt;/P&gt;</description>
      <pubDate>Fri, 04 Sep 2026 13:45:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-commit-changes-after-installing-new-certificate/m-p/1263683#M126970</guid>
      <dc:creator>DJ_1924</dc:creator>
      <dc:date>2026-09-04T13:45:43Z</dc:date>
    </item>
  </channel>
</rss>

