<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Since upgrade globalprotect 2.1 certificate problems in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/since-upgrade-globalprotect-2-1-certificate-problems/m-p/30130#M22019</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Johan, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Make sense...Did you install root certificate on GP client ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hardik shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 11 Oct 2014 16:21:47 GMT</pubDate>
    <dc:creator>hshah</dc:creator>
    <dc:date>2014-10-11T16:21:47Z</dc:date>
    <item>
      <title>Since upgrade globalprotect 2.1 certificate problems</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/since-upgrade-globalprotect-2-1-certificate-problems/m-p/30124#M22013</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We experiencing a problem with the new version of Global Protect 2.1.We have PA 6.0.3. We use a 3th party as authenticaton manager. The problem appears with the certificate of the gateway : we use forthis certificate a wildcard signed certificate. All the gp clients upgraded to this version receive the following error : Gateway external_gateway_2: Server certificate verification failed. With version 2.0.x , this problem didnt arrive. This is no problem with all clients (laptops, androids, ...), butthis has become problem with ios-devices, since they upgraded automically from appstore, since appstore upgraded their version to 2.1. Anybody knows if this is a general problem.Has the new globalprotect client a requirement of &amp;gt; panos 6.0.3 ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Error message : Gateway external_gateway_2: Server certificate verification failed&lt;/P&gt;&lt;P&gt;from logs tested with 64 bit laptop win7 :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(T99064) 10/11/14 13:32:30:934 Error(2147): Failed to verify server certificate of gateway xxxxxxxxxxxx.&lt;/P&gt;&lt;P&gt;(T99064) 10/11/14 13:32:30:934 Error(1520): Failed to retrieve info for gateway xxxxxxxxx.&lt;/P&gt;&lt;P&gt;(T99064) 10/11/14 13:32:30:934 Error(2350): NetworkDiscoverThread: failed to discover external network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;greetz&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 11 Oct 2014 11:38:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/since-upgrade-globalprotect-2-1-certificate-problems/m-p/30124#M22013</guid>
      <dc:creator>johan.boeckx</dc:creator>
      <dc:date>2014-10-11T11:38:12Z</dc:date>
    </item>
    <item>
      <title>Re: Since upgrade globalprotect 2.1 certificate problems</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/since-upgrade-globalprotect-2-1-certificate-problems/m-p/30125#M22014</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Johan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you confirm if the Gateway's ip address is fqdn or IP address under External Gateways? If its IP address can you change it to FQDN, commit and try again? Thank you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 11 Oct 2014 14:34:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/since-upgrade-globalprotect-2-1-certificate-problems/m-p/30125#M22014</guid>
      <dc:creator>ssharma</dc:creator>
      <dc:date>2014-10-11T14:34:52Z</dc:date>
    </item>
    <item>
      <title>Re: Since upgrade globalprotect 2.1 certificate problems</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/since-upgrade-globalprotect-2-1-certificate-problems/m-p/30126#M22015</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That was correct answer. I changed the gateway address now tothe url, which makes part of the wildcard certficate. It works now. What troubles me a bit, is that I still see in the logging of the gp client : "&lt;/P&gt;&lt;P&gt;(T92424) 10/11/14 16:40:16:525 Info ( 107): Failed to verify server cert. Result is self signed certificate in certificate chain &lt;/P&gt;&lt;P&gt;(T92424) 10/11/14 16:40:16:525 Info ( 126): SSL_get_verify_result() failed: (null)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any idea about this ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;greetz,&lt;/P&gt;&lt;P&gt;Johan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 11 Oct 2014 15:08:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/since-upgrade-globalprotect-2-1-certificate-problems/m-p/30126#M22015</guid>
      <dc:creator>johan.boeckx</dc:creator>
      <dc:date>2014-10-11T15:08:20Z</dc:date>
    </item>
    <item>
      <title>Re: Since upgrade globalprotect 2.1 certificate problems</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/since-upgrade-globalprotect-2-1-certificate-problems/m-p/30127#M22016</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Joan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I had similar issue with GP 2.1.0. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was suggested that CN of gateway certificate has to be same as gateway name provided by Portal.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try this change, it should work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hardik Shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 11 Oct 2014 15:09:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/since-upgrade-globalprotect-2-1-certificate-problems/m-p/30127#M22016</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2014-10-11T15:09:39Z</dc:date>
    </item>
    <item>
      <title>Re: Since upgrade globalprotect 2.1 certificate problems</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/since-upgrade-globalprotect-2-1-certificate-problems/m-p/30128#M22017</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Joahn,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As of now end client doesnt trust the root CA which signed "GP Certificate".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Which means you are supposed to install root certificate.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hardik Shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 11 Oct 2014 15:52:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/since-upgrade-globalprotect-2-1-certificate-problems/m-p/30128#M22017</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2014-10-11T15:52:18Z</dc:date>
    </item>
    <item>
      <title>Re: Since upgrade globalprotect 2.1 certificate problems</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/since-upgrade-globalprotect-2-1-certificate-problems/m-p/30129#M22018</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Doesnt work&lt;/P&gt;&lt;P&gt;I suppose it is not the cn of the name you give in the PA. I tried to give the gateway name the same as the name of the certificate . Still the same result&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;greetz,&lt;/P&gt;&lt;P&gt;Johan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 11 Oct 2014 15:54:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/since-upgrade-globalprotect-2-1-certificate-problems/m-p/30129#M22018</guid>
      <dc:creator>johan.boeckx</dc:creator>
      <dc:date>2014-10-11T15:54:42Z</dc:date>
    </item>
    <item>
      <title>Re: Since upgrade globalprotect 2.1 certificate problems</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/since-upgrade-globalprotect-2-1-certificate-problems/m-p/30130#M22019</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Johan, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Make sense...Did you install root certificate on GP client ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hardik shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 11 Oct 2014 16:21:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/since-upgrade-globalprotect-2-1-certificate-problems/m-p/30130#M22019</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2014-10-11T16:21:47Z</dc:date>
    </item>
    <item>
      <title>Re: Since upgrade globalprotect 2.1 certificate problems</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/since-upgrade-globalprotect-2-1-certificate-problems/m-p/30131#M22020</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;I'm getting the same error with GP 2.1 on Windows 8.1 , actually I always have big trouble with windows machines. &lt;BR /&gt;it works perfect on Android, Apple, but Windows takes me hours and not working every time. I do huge hit and miss config every time.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can somebody explain how to configure this please? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I bought the domain.&lt;/P&gt;&lt;P&gt;I generated new CSR and signed it by the Trusted CA (VeriSign) &lt;/P&gt;&lt;P&gt;I imported the cert and I see the certs "merged" and have the FQDN name of a cert with "private key"&lt;/P&gt;&lt;P&gt;I select the cert for Server Cert&lt;/P&gt;&lt;P&gt;I connect to the gateway and get the same error as everybody in this post. &lt;/P&gt;&lt;P&gt;Can not select continue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I use FQDN for Cert name, Portal address, and in GP client to connect.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do I still need to export the cert and import to the windows client root folder? if so , why ? &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Nov 2014 21:44:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/since-upgrade-globalprotect-2-1-certificate-problems/m-p/30131#M22020</guid>
      <dc:creator>Mariusz.pianka</dc:creator>
      <dc:date>2014-11-25T21:44:00Z</dc:date>
    </item>
  </channel>
</rss>

