<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GlobalProtect reports a &amp;quot;Client Certificate Error&amp;quot; but still connects in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-reports-a-quot-client-certificate-error-quot-but/m-p/22235#M16200</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;do you open support case ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 17 Mar 2015 16:15:03 GMT</pubDate>
    <dc:creator>Gregoux</dc:creator>
    <dc:date>2015-03-17T16:15:03Z</dc:date>
    <item>
      <title>GlobalProtect reports a "Client Certificate Error" but still connects</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-reports-a-quot-client-certificate-error-quot-but/m-p/22234#M16199</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm running a PA-500 on with GlobalProtect for VPN access.&amp;nbsp; Just recently our users started experiencing an issue wherein they try to connect and receive a "Client Certificate Error" error dialog.&amp;nbsp; However, after they click &lt;EM&gt;OK&lt;/EM&gt; to close the dialog, the agent connects anyway.&amp;nbsp; I investigated the issue myself and found what follows below.&amp;nbsp; Note that I initiated the connection at around 19:24 and closed it at around 19:33.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Environment&lt;/STRONG&gt;:&lt;/P&gt;&lt;P&gt;Firewall OS: 5.0.14&lt;/P&gt;&lt;P&gt;GlobalProtect Client: 1.2.5-2&lt;/P&gt;&lt;P&gt;User OS: Windows 7 (all our users are Win 7, so I can't determine whether this is OS-specific)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The exported &lt;STRONG&gt;PanGPA&lt;/STRONG&gt; log reports this at the time of making the connection:&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;(T4860) 03/15/15 19:24:39:713 Error(1172): error = ERROR_WINHTTP_CLIENT_AUTH_CERT_NEEDED&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;(T4860) 03/15/15 19:24:39:900 Error(1172): error = ERROR_WINHTTP_CLIENT_AUTH_CERT_NEEDED&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;(T2844) 03/15/15 19:24:48:683 Error(1172): error = ERROR_WINHTTP_CLIENT_AUTH_CERT_NEEDED&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;(T4328) 03/15/15 19:24:49:354 Error(1172): error = ERROR_WINHTTP_CLIENT_AUTH_CERT_NEEDED&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;(T3180) 03/15/15 19:24:57:154 Error(1172): error = ERROR_WINHTTP_CLIENT_AUTH_CERT_NEEDED&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The exported &lt;STRONG&gt;PanGPS&lt;/STRONG&gt; log reports this (I've removed IP addresses):&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;(T2080) 03/15/15 12:13:26:571 Error(&amp;nbsp; 80): Failed to open sub key 'Software\Palo Alto Networks\VPN Agent\PanSetup'&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;(T2176) 03/15/15 19:24:39:619 Error(&amp;nbsp; 95): SSL connect failed (error:00000001:lib(0):func(0):reason(1))&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;(T2176) 03/15/15 19:24:39:619 Error( 141): connect() failed&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;(T2176) 03/15/15 19:24:39:619 Error(7805): Protocol error. Check server certificate. Failed to ssl connect to '&amp;lt;Portal IP&amp;gt;:443', Disconect ssl and returns false.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;(T2176) 03/15/15 19:24:45:891 Error(12151): pre-login error message: GlobalProtect portal does not exist&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;(T2176) 03/15/15 19:24:45:891 Error(8298): pan_obj_get_value() failed with tag client-cert. Returns false.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;(T2176) 03/15/15 19:24:45:891 Error(11000): Failed to export client cert.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;(T4256) 03/15/15 19:24:45:984 Error(&amp;nbsp; 95): SSL connect failed (error:00000001:lib(0):func(0):reason(1))&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;(T4256) 03/15/15 19:24:45:984 Error( 141): connect() failed&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;(T4256) 03/15/15 19:24:45:984 Error(7805): Protocol error. Check server certificate. Failed to ssl connect to '&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;lt;Portal IP&amp;gt;&lt;/SPAN&gt;:443', Disconect ssl and returns false.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;(T4264) 03/15/15 19:24:51:444 Error(13520): CheckHipMissingPatchInOtherProcess(): Wait timeout for process PanGpHipMp.exe&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;(T4264) 03/15/15 19:28:56:737 Error(13520): CheckHipMissingPatchInOtherProcess(): Wait timeout for process PanGpHipMp.exe&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;(T2176) 03/15/15 19:32:49:238 Error(1767): UnsetRoutes: DeleteIpForwardEntry[0] (0.0.0.0) failed (Element not found.&lt;/SPAN&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;(T2176) 03/15/15 19:32:49:238 Error(1767): UnsetRoutes: DeleteIpForwardEntry[1] (&amp;lt;Some IP 1&amp;gt;) failed (Element not found.&lt;/SPAN&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;(T2176) 03/15/15 19:32:49:238 Error(1767): UnsetRoutes: DeleteIpForwardEntry[2] (&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;lt;Some IP 2&amp;gt;&lt;/SPAN&gt;) failed (Element not found.&lt;/SPAN&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;(T2176) 03/15/15 19:32:49:238 Error(1767): UnsetRoutes: DeleteIpForwardEntry[3] (&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;lt;Some IP 1&amp;gt;&lt;/SPAN&gt;) failed (Element not found.&lt;/SPAN&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;(T2176) 03/15/15 19:32:49:238 Error(1767): UnsetRoutes: DeleteIpForwardEntry[4] (&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;lt;Some IP 2&amp;gt;&lt;/SPAN&gt;) failed (Element not found.&lt;/SPAN&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;(T2960) 03/15/15 19:32:49:270 Error(1739): UnsetRoutes: No route installed before&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;(T2960) 03/15/15 19:33:01:339 Error(1199): IpReleaseAddress done&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;(T2176) 03/15/15 19:33:01:558 Error(&amp;nbsp; 95): SSL connect failed (error:00000001:lib(0):func(0):reason(1))&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;(T2176) 03/15/15 19:33:01:558 Error( 141): connect() failed&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;(T2176) 03/15/15 19:33:01:558 Error( 978): ConnectSSL: Failed to connect to '&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;lt;Portal IP&amp;gt;&lt;/SPAN&gt;:443'&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;(T2176) 03/15/15 19:33:01:558 Error(1025): ConnectSSL(false) failed&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;(T2176) 03/15/15 19:33:01:558 Error(1221): Logout: SendNReceive() failed&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;(T2176) 03/15/15 19:33:01:558 Error(2013): Disconnect: Logout() failed&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One of the first things I did was check out the certificates assigned to the clients, and they all appear to be fine.&amp;nbsp; At least, nothing in them was changed or expired.&amp;nbsp; I also checked out the firewall's system logs and they don't give a hint of any error (they just show a successful authentication and connection), which leads me to believe that the error is completely client-side.&amp;nbsp; Does anybody have any input on this?&amp;nbsp; I like that my users can still connect, but for obvious reasons I don't like seeing certificate errors that are apparently being ignored...if the logs say "&lt;SPAN style="font-family: courier new,courier;"&gt;Failed to ssl connect&lt;/SPAN&gt;" but it connects anyway, then what's it using to connect?&amp;nbsp; Not an unencrypted, non-SSL connection, I hope.&amp;nbsp; I'm hesitant to use the VPN until I can resolve this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;By the way, this seems to be a possibly related and unanswered question:&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/message/43849"&gt;https://live.paloaltonetworks.com/message/43849&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Mar 2015 15:15:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-reports-a-quot-client-certificate-error-quot-but/m-p/22234#M16199</guid>
      <dc:creator>NinthShot</dc:creator>
      <dc:date>2015-03-16T15:15:00Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect reports a "Client Certificate Error" but still connects</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-reports-a-quot-client-certificate-error-quot-but/m-p/22235#M16200</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;do you open support case ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Mar 2015 16:15:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-reports-a-quot-client-certificate-error-quot-but/m-p/22235#M16200</guid>
      <dc:creator>Gregoux</dc:creator>
      <dc:date>2015-03-17T16:15:03Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect reports a "Client Certificate Error" but still connects</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-reports-a-quot-client-certificate-error-quot-but/m-p/22236#M16201</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No, not yet.&amp;nbsp; I was going to check with the community first and then open a support case if nobody here knew anything.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Mar 2015 20:05:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-reports-a-quot-client-certificate-error-quot-but/m-p/22236#M16201</guid>
      <dc:creator>NinthShot</dc:creator>
      <dc:date>2015-03-17T20:05:58Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect reports a "Client Certificate Error" but still connects</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-reports-a-quot-client-certificate-error-quot-but/m-p/22237#M16202</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Could you please check the certificate common name is an IP address or a FQDN. For example,&amp;nbsp; If the certificate is having IP address in the CN, you have to connect with IP from the GP client. Otherwise it will show you a certificate warning. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Mar 2015 20:13:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-reports-a-quot-client-certificate-error-quot-but/m-p/22237#M16202</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2015-03-17T20:13:46Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect reports a "Client Certificate Error" but still connects</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-reports-a-quot-client-certificate-error-quot-but/m-p/571834#M115108</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/17881"&gt;@NinthShot&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have seen error like this where in PA issuing cert was expired but Root Cert was not and PC machine cert was verified by the Root Cert on the PA.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope it helps.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jan 2024 22:24:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-reports-a-quot-client-certificate-error-quot-but/m-p/571834#M115108</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2024-01-04T22:24:08Z</dc:date>
    </item>
  </channel>
</rss>

