<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Certificate failed to load in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/certificate-failed-to-load/m-p/40869#M30038</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We are actually seeing similar behaviour on Pan 6.1.2 on our PA-3020's. We try to sync from the primary to the secondary and it fails with that same error.&amp;nbsp; It has caused us no end of problems because effectively, the only way for us to get the sync to work is remove the global protect configuration which makes use of the certificates and then delete the certificates.&amp;nbsp; I'm wondering if anyone else has seen this and has an idea of why it may be happening?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 02 Mar 2015 02:01:30 GMT</pubDate>
    <dc:creator>Kevin.lane</dc:creator>
    <dc:date>2015-03-02T02:01:30Z</dc:date>
    <item>
      <title>Certificate failed to load</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/certificate-failed-to-load/m-p/40867#M30036</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;We have two PA-4060 in active/passive mode with PAN-OS 4.1.12 (I know, old..).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;Yesterday, after rebooting passive device auto commit failed with:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Error: Certificate 'XYZ' failed to load: failed to parse key&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;and device went to not-ready state.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After deleting problematic certificate and with commit force device become functional again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We then tried synchronize configurations manually but HA-Sync fail with the same error&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Error: Certificate 'XYZ' failed to load: failed to parse key&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;The last time the device was rebooted in March 2014 without problems and with the now problematic certificate on it.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does anyone have any solution why this error occurred?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;Tnx and regards, &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Vesna.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Feb 2015 10:41:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/certificate-failed-to-load/m-p/40867#M30036</guid>
      <dc:creator>vesna.djukic</dc:creator>
      <dc:date>2015-02-16T10:41:29Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate failed to load</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/certificate-failed-to-load/m-p/40868#M30037</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Vesna,&lt;/P&gt;&lt;P&gt;1. upgrade&lt;/P&gt;&lt;P&gt;2. It looks like your certificate isn't supported: What's the key size and signature algorithm of the certificate?&lt;/P&gt;&lt;P&gt;What is the certificate used for on your PA?&lt;/P&gt;&lt;P&gt;-&amp;gt; try to use a certificate that has the same options as the ones you get when creating a certificate on the PA itself.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tijl&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Feb 2015 14:12:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/certificate-failed-to-load/m-p/40868#M30037</guid>
      <dc:creator>Tijl</dc:creator>
      <dc:date>2015-02-19T14:12:55Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate failed to load</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/certificate-failed-to-load/m-p/40869#M30038</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We are actually seeing similar behaviour on Pan 6.1.2 on our PA-3020's. We try to sync from the primary to the secondary and it fails with that same error.&amp;nbsp; It has caused us no end of problems because effectively, the only way for us to get the sync to work is remove the global protect configuration which makes use of the certificates and then delete the certificates.&amp;nbsp; I'm wondering if anyone else has seen this and has an idea of why it may be happening?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 Mar 2015 02:01:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/certificate-failed-to-load/m-p/40869#M30038</guid>
      <dc:creator>Kevin.lane</dc:creator>
      <dc:date>2015-03-02T02:01:30Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate failed to load</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/certificate-failed-to-load/m-p/40870#M30039</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Tijl, thank you for answer. Yes, I agree that upgrade is a must.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;According to the information I received from the user, signature algorithm is SHA1RSA and public key size is 2048.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It's funny that this error didn't not occur last time device was rebooted and it is mystery why did it happened this time.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 Mar 2015 07:41:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/certificate-failed-to-load/m-p/40870#M30039</guid>
      <dc:creator>vesna.djukic</dc:creator>
      <dc:date>2015-03-02T07:41:31Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate failed to load</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/certificate-failed-to-load/m-p/40871#M30040</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;smells like a bug &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Mar 2015 12:55:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/certificate-failed-to-load/m-p/40871#M30040</guid>
      <dc:creator>Tijl</dc:creator>
      <dc:date>2015-03-11T12:55:52Z</dc:date>
    </item>
  </channel>
</rss>

