<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ssl sever certificat can't be verified in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-sever-certificat-can-t-be-verified/m-p/69541#M40328</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This issue is on a&amp;nbsp;Palo-Alto PA-500.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've renewed my SSL certificate from my provider and updated it in the Palo-alto / Device / Certificates.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It tells me that this certificate is valid.&lt;/P&gt;
&lt;P&gt;Ok. thanls.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But now that the date it should have expire is gone, my Global Protect clients have an error about the certificate that tells them that it's no more valid.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Where do I need to update the certificate, as I thought that it was stored on the Palo-Alto and&amp;nbsp;checked&amp;nbsp;by the client before any connection.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If anybody have any clue on how it worked, that would be nice to share.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you.&lt;/P&gt;</description>
    <pubDate>Wed, 16 Dec 2015 15:08:03 GMT</pubDate>
    <dc:creator>fcorvaisier</dc:creator>
    <dc:date>2015-12-16T15:08:03Z</dc:date>
    <item>
      <title>ssl sever certificat can't be verified</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-sever-certificat-can-t-be-verified/m-p/69541#M40328</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This issue is on a&amp;nbsp;Palo-Alto PA-500.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've renewed my SSL certificate from my provider and updated it in the Palo-alto / Device / Certificates.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It tells me that this certificate is valid.&lt;/P&gt;
&lt;P&gt;Ok. thanls.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But now that the date it should have expire is gone, my Global Protect clients have an error about the certificate that tells them that it's no more valid.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Where do I need to update the certificate, as I thought that it was stored on the Palo-Alto and&amp;nbsp;checked&amp;nbsp;by the client before any connection.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If anybody have any clue on how it worked, that would be nice to share.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Dec 2015 15:08:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-sever-certificat-can-t-be-verified/m-p/69541#M40328</guid>
      <dc:creator>fcorvaisier</dc:creator>
      <dc:date>2015-12-16T15:08:03Z</dc:date>
    </item>
    <item>
      <title>Re: ssl sever certificat can't be verified</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-sever-certificat-can-t-be-verified/m-p/69550#M40332</link>
      <description>&lt;P&gt;When you installed the updated cert, did you install the full chain (cert + intermediate) as per this article:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/How-to-Install-a-Chained-Certificate-Signed-by-a-Public-CA/ta-p/55523" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/How-to-Install-a-Chained-Certificate-Signed-by-a-Public-CA/ta-p/55523&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If not, that's the most likely cause. The cert must be installed with the chain, or else all your clients must already trust the intermediate CA (or multiple intermediate CAs, if needed).&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you did just the server certificate itself and not the full chain, try doing the chain install to see if that solves it for you.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;Greg&lt;/P&gt;</description>
      <pubDate>Wed, 16 Dec 2015 17:54:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-sever-certificat-can-t-be-verified/m-p/69550#M40332</guid>
      <dc:creator>gwesson</dc:creator>
      <dc:date>2015-12-16T17:54:00Z</dc:date>
    </item>
    <item>
      <title>Re: ssl sever certificat can't be verified</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-sever-certificat-can-t-be-verified/m-p/69728#M40373</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I've added the certfile then the intermediate file, but it didn't resolve so I tried to add a file with cert+interm. but it didn"t change anything.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The&amp;nbsp;state is still "valid" on the PA but the client still have a message about the validity of the certificate.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Should I try to revoke the certificate on the PA and import it again ?&lt;/P&gt;</description>
      <pubDate>Tue, 22 Dec 2015 08:47:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-sever-certificat-can-t-be-verified/m-p/69728#M40373</guid>
      <dc:creator>fcorvaisier</dc:creator>
      <dc:date>2015-12-22T08:47:11Z</dc:date>
    </item>
    <item>
      <title>Re: ssl sever certificat can't be verified</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-sever-certificat-can-t-be-verified/m-p/69791#M40389</link>
      <description>&lt;P&gt;Are you using the same certificate in the portal and the Gateway?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please verify if you are getting the same error when you trying to access the portal.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Dec 2015 01:50:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-sever-certificat-can-t-be-verified/m-p/69791#M40389</guid>
      <dc:creator>amittal</dc:creator>
      <dc:date>2015-12-23T01:50:40Z</dc:date>
    </item>
  </channel>
</rss>

