<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Error: Certificate failed to load: invalid certificate chain in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/error-certificate-failed-to-load-invalid-certificate-chain/m-p/37983#M27803</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The error about the Certificate chain is just that. &lt;/P&gt;&lt;P&gt;In order for the chain to be complete, it must have the Root-level CA public cert, the Intermediate-level CA public cert (if any) then the Subordinate CA cert, then the Subordinate CA can be the Certificate Authority and create the certs. &lt;/P&gt;&lt;P&gt;Now, if you do not know the full chain, take the Subordinate CA, and then double click on the .cer or .crt file , then click on the Certificate Chain (last tab) and then click on each one up the chain: and you can save off each one and then import it into the Certificates section to ensure the full path is present.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does that make any sense?&amp;nbsp; If not, please let me know, and I will try to provide screenshots.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 13 Apr 2015 16:16:54 GMT</pubDate>
    <dc:creator>jdelio</dc:creator>
    <dc:date>2015-04-13T16:16:54Z</dc:date>
    <item>
      <title>Error: Certificate failed to load: invalid certificate chain</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/error-certificate-failed-to-load-invalid-certificate-chain/m-p/37982#M27802</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I generated a CSR with PAN-OS 6.1.3 and submitted it to our Microsoft AD CA with subordinate CA template. After uploading the certificate it shows up under the root CA certificate of our domain. But when commiting the changes I get an &lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;"Error: Certificate failed to load: invalid certificate chain" error message. What have I done wrong?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The CSR was generated with one main CN as FQDN of both firewalls (leinf-pa-3020-rz.domain.de, it's a HA cluster) and their own management IP adresses and FQDNs for usage as the WebUI certificate.&lt;/P&gt;&lt;P&gt;This is how it looks in the WebUI:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="2015-04-13 11_16_43-LEINF-PA-3020_1-RZ.png" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/19153_2015-04-13 11_16_43-LEINF-PA-3020_1-RZ.png" style="height: 87px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;I tried adding the root cert data into the subordinate cert, and when I export it again it is still in there. So why is it complaining about the chain?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind Regards&lt;/P&gt;&lt;P&gt;Christian&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Apr 2015 09:33:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/error-certificate-failed-to-load-invalid-certificate-chain/m-p/37982#M27802</guid>
      <dc:creator>cale</dc:creator>
      <dc:date>2015-04-13T09:33:45Z</dc:date>
    </item>
    <item>
      <title>Re: Error: Certificate failed to load: invalid certificate chain</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/error-certificate-failed-to-load-invalid-certificate-chain/m-p/37983#M27803</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The error about the Certificate chain is just that. &lt;/P&gt;&lt;P&gt;In order for the chain to be complete, it must have the Root-level CA public cert, the Intermediate-level CA public cert (if any) then the Subordinate CA cert, then the Subordinate CA can be the Certificate Authority and create the certs. &lt;/P&gt;&lt;P&gt;Now, if you do not know the full chain, take the Subordinate CA, and then double click on the .cer or .crt file , then click on the Certificate Chain (last tab) and then click on each one up the chain: and you can save off each one and then import it into the Certificates section to ensure the full path is present.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does that make any sense?&amp;nbsp; If not, please let me know, and I will try to provide screenshots.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Apr 2015 16:16:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/error-certificate-failed-to-load-invalid-certificate-chain/m-p/37983#M27803</guid>
      <dc:creator>jdelio</dc:creator>
      <dc:date>2015-04-13T16:16:54Z</dc:date>
    </item>
    <item>
      <title>Re: Error: Certificate failed to load: invalid certificate chain</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/error-certificate-failed-to-load-invalid-certificate-chain/m-p/37984#M27804</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The complete chain is shown in the Web GUI screenshot. There is only the Root CA from our AD and then the Sub CA certificate for the devices, no intermediates. Viewing the cer file confirms this.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Apr 2015 05:03:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/error-certificate-failed-to-load-invalid-certificate-chain/m-p/37984#M27804</guid>
      <dc:creator>cale</dc:creator>
      <dc:date>2015-04-14T05:03:37Z</dc:date>
    </item>
    <item>
      <title>Re: Error: Certificate failed to load: invalid certificate chain</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/error-certificate-failed-to-load-invalid-certificate-chain/m-p/37985#M27805</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here is what you can try,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;+++ Separate all the certificates in the chain as jdelio suggested.&lt;/P&gt;&lt;P&gt;+++ Open the FW certificate in a notepad. You will find the complete chain there. Just keep the FW certificate in there and remove the other Intermediate and Root certificates. Save it. Make sure not to have an additional, extra spaces.&lt;/P&gt;&lt;P&gt;You can check the certificates using the following link,&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.sslshopper.com/certificate-decoder.html" title="https://www.sslshopper.com/certificate-decoder.html"&gt;https://www.sslshopper.com/certificate-decoder.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;+++ Once done, import the FW certificate first, then intermediate, then root.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if this works.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Rahul&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Apr 2015 15:49:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/error-certificate-failed-to-load-invalid-certificate-chain/m-p/37985#M27805</guid>
      <dc:creator>rsingh</dc:creator>
      <dc:date>2015-04-14T15:49:31Z</dc:date>
    </item>
    <item>
      <title>Re: Error: Certificate failed to load: invalid certificate chain</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/error-certificate-failed-to-load-invalid-certificate-chain/m-p/37986#M27806</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for all your help, this is what finally did the job:&lt;/P&gt;&lt;P&gt;Remove all certificate functions to another (I had the original selfsigned still on the box) and commit.&lt;/P&gt;&lt;P&gt;Export the new certificates with private keys.&lt;/P&gt;&lt;P&gt;Delete the whole chain of the new certificate and commit.&lt;/P&gt;&lt;P&gt;Add the SubCA and then go up the chain and add the other ones and commit&lt;/P&gt;&lt;P&gt;Add the needed functions back to the SubCA and remove them from the (temporary) selfsigned and commit.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just replacing the originals seemed to be what didn't work. A complete removal and readding did the trick&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Christian&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Apr 2015 06:06:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/error-certificate-failed-to-load-invalid-certificate-chain/m-p/37986#M27806</guid>
      <dc:creator>cale</dc:creator>
      <dc:date>2015-04-15T06:06:38Z</dc:date>
    </item>
  </channel>
</rss>

