<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Global Protect Client, portal error message: Client Certificate Error in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-client-portal-error-message-client-certificate/m-p/46712#M34337</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Ralph,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What version of GP-agent running on the client machine.?&lt;/P&gt;&lt;P&gt;Is this behavior observed in all machines including MAC and windows..?&lt;/P&gt;&lt;P&gt;Is there any special-character exists on your GP certificate..?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 28 Jul 2014 15:21:24 GMT</pubDate>
    <dc:creator>HULK</dc:creator>
    <dc:date>2014-07-28T15:21:24Z</dc:date>
    <item>
      <title>Global Protect Client, portal error message: Client Certificate Error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-client-portal-error-message-client-certificate/m-p/46711#M34336</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Times New Roman; font-size: 10pt;"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0px 0px 10pt;"&gt;&lt;SPAN style="color: #000000; font-size: 10pt; font-family: arial,helvetica,sans-serif;"&gt;We have upgraded 5 of our BranchOffice firewalls from 6.02 to 6.03 yesterday. All updates went fine except one:&lt;/SPAN&gt;&lt;SPAN style="color: #000000; font-family: arial,helvetica,sans-serif; font-size: 10pt;"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0px 0px 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: arial,helvetica,sans-serif; font-size: 10pt;"&gt;We are going to get an issue as soon as we want to connect via Global Protect to the Gateway. The window "Client Certificate Error" pops up:&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0px 0px 10pt;"&gt;&lt;SPAN style="color: #000000; font-size: 10pt; font-family: Times New Roman;"&gt;&lt;IMG alt="portal error message_Client Certificate Error.png" class="image-0 jive-image jiveImage" height="466" src="https://live.paloaltonetworks.com/legacyfs/online/14709_portal error message_Client Certificate Error.png" style="width: 430px; height: 256px;" width="781" /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0px 0px 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: arial,helvetica,sans-serif; font-size: 10pt;"&gt;The error log shows:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: arial,helvetica,sans-serif; font-size: 10pt;"&gt; &lt;/SPAN&gt;&lt;SPAN style="color: #000000; font-size: 10pt; font-family: arial,helvetica,sans-serif;"&gt;(T1636) 07/28/14 11:56:52:382 Error(8377): pan_obj_get_value() failed with tag client-cert. Returns false.&lt;/SPAN&gt;&lt;SPAN style="color: #000000; font-family: arial,helvetica,sans-serif; font-size: 10pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 10pt; font-family: arial,helvetica,sans-serif;"&gt;(T1636) 07/28/14 11:56:52:382 Error(11081): Failed to export client cert.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 10pt; font-family: arial,helvetica,sans-serif;"&gt;(T580) 07/28/14 11:56:52:414 Error(1813): UnsetRoutes: No route installed before&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 10pt; font-family: arial,helvetica,sans-serif;"&gt;(T1500) 07/28/14 11:56:57:883 Error(13454): Wait timeout for process PanGpHip.exe&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 10pt; font-family: arial,helvetica,sans-serif;"&gt;(T580) 07/28/14 11:57:25:242 Error(6122): pre-login error message: GlobalProtect gateway does not exist&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 10pt; font-family: arial,helvetica,sans-serif;"&gt;(T580) 07/28/14 11:57:25:554 Error(6350): unexpected response from server.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 10pt; font-family: arial,helvetica,sans-serif;"&gt;(T580) 07/28/14 11:57:25:554 Error(5858): Failed to retrieve info for gateway 77.xxx.xxx.xxx&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 10pt; font-family: arial,helvetica,sans-serif;"&gt;(T580) 07/28/14 11:57:25:554 Error(9094): NetworkDiscoverThread: failed to discover external network.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 10pt; font-family: arial,helvetica,sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0px 0px 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: arial,helvetica,sans-serif; font-size: 10pt;"&gt;The only difference to the others is that we have Dynamic DHCP Client active on the Untrust Interface. However with 6.02 it still worked with this configuration. The Root and GP Certificates are valid and still the same as before we have updated to 6.03.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0px 0px 10pt;"&gt;&lt;SPAN lang="DE" style="color: #3b3b3b; line-height: 115%; font-family: arial,helvetica,sans-serif; font-size: 10pt; mso-ansi-language: DE;"&gt;Does anyone know what the problem could be? Can't find anything in the knowledgebase so far.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0px 0px 10pt;"&gt;&lt;SPAN lang="DE" style="color: #3b3b3b; line-height: 115%; font-family: arial,helvetica,sans-serif; font-size: 10pt; mso-ansi-language: DE;"&gt;Thanks,&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0px 0px 10pt;"&gt;&lt;SPAN style="line-height: 115%; color: #3b3b3b; font-size: 10pt; mso-ansi-language: DE; font-family: arial,helvetica,sans-serif;"&gt;Ralph&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Times New Roman; font-size: 12pt;"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Jul 2014 11:03:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-client-portal-error-message-client-certificate/m-p/46711#M34336</guid>
      <dc:creator>relsener</dc:creator>
      <dc:date>2014-07-28T11:03:45Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect Client, portal error message: Client Certificate Error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-client-portal-error-message-client-certificate/m-p/46712#M34337</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Ralph,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What version of GP-agent running on the client machine.?&lt;/P&gt;&lt;P&gt;Is this behavior observed in all machines including MAC and windows..?&lt;/P&gt;&lt;P&gt;Is there any special-character exists on your GP certificate..?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Jul 2014 15:21:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-client-portal-error-message-client-certificate/m-p/46712#M34337</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-07-28T15:21:24Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect Client, portal error message: Client Certificate Error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-client-portal-error-message-client-certificate/m-p/46713#M34338</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Hulk&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your answer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We found the issue. Somehow on this box was an override on the Issunig CA Certifcate in Certificate Management/Certifcates set. After we removed the overrided Global Protect worked again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;BR /&gt;Ralph&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Jul 2014 06:34:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-client-portal-error-message-client-certificate/m-p/46713#M34338</guid>
      <dc:creator>relsener</dc:creator>
      <dc:date>2014-07-29T06:34:37Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect Client, portal error message: Client Certificate Error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-client-portal-error-message-client-certificate/m-p/46714#M34339</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Any chance you could explain what you mean by "override"?&amp;nbsp; I'm experiencing a similar issue and nothing's changed so far as I can see but when I check the certificates under Device &amp;gt; Certificate Management &amp;gt; Certificates there is no "override" option as a setting on any of them?&amp;nbsp; I should also mention the hardware is a 2050 with PANOS 5.0.11 - maybe the version &amp;amp; hardware make a difference?&amp;nbsp; Clients receive the Client Certificate Error but the VPN still gets created and resources are still accessible, not sure if this is relevant?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Sep 2014 13:54:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-client-portal-error-message-client-certificate/m-p/46714#M34339</guid>
      <dc:creator>cafowler</dc:creator>
      <dc:date>2014-09-05T13:54:26Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect Client, portal error message: Client Certificate Error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-client-portal-error-message-client-certificate/m-p/46715#M34340</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I believe he is talking about Trusted CA&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-weight: bold;"&gt;&lt;A name="1977412"&gt;&lt;/A&gt;Trusted Root CA&lt;/SPAN&gt;—The certificate is marked as a trusted CA for forward decryption purposes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think he had this checked off.&amp;nbsp; when he removed it, his GP worked.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This would make sense.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Sep 2014 14:29:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-client-portal-error-message-client-certificate/m-p/46715#M34340</guid>
      <dc:creator>scantwell</dc:creator>
      <dc:date>2014-09-05T14:29:24Z</dc:date>
    </item>
  </channel>
</rss>

