<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Global Protect 3.0.0 Gateway Certificate Error &amp;quot;Server Certificate verification failed&amp;amp;quot in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-3-0-0-gateway-certificate-error-quot-server/m-p/78138#M42843</link>
    <description>&lt;P&gt;Thanks for the info Jack. This also applies to internally signed certs managed by an&amp;nbsp;internal certificate authority.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 16 May 2016 15:38:14 GMT</pubDate>
    <dc:creator>DavidNestler</dc:creator>
    <dc:date>2016-05-16T15:38:14Z</dc:date>
    <item>
      <title>Global Protect 3.0.0 Gateway Certificate Error "Server Certificate verification failed" *FIX*</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-3-0-0-gateway-certificate-error-quot-server/m-p/75641#M42049</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Recently had a client upgrade their Global Protect Agent to 3.0.0 from 2.2.2.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;When connecting to the Gateway they would encounter the following message - "Server Certificate verification failed".&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;From 2.1.0 you had to ensure the External Gateway address in the Agent/Client configuration of the Portal is the CN of the Certificate you are using, but this was not the case as he upgraded from 2.2.2 and would have already had this implemented.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As he's jumped from 2.2 to 3.0 I thought I would look into the release notes and default behaviour changes to the GP agents and found the following document for 2.3.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/23/globalprotect-agent-rns/globalprotect-agent-2-3-release-information/changes-to-default-behavior.html" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/23/globalprotect-agent-rns/globalprotect-agent-2-3-release-information/changes-to-default-behavior.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;From 2.3 and onwards, you would need to ensure the self-signed certificate you have generated is marked as a Trusted Root CA in the certificates options and/or add the CA to the Trusted Root CA in Network &amp;gt; Global Protect Portals &amp;gt; Portal you're using &amp;gt; Agent Configuration &amp;gt; Add self-signed certificate to the Trusted Root CA list.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is an easy thing to miss, as when following Palo's document on how to create a self-signed certificate, it doesn't mention having to create this certificate as a Trusted Root CA, as this wasn't the case before 2.3.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/61/pan-os/pan-os/certificate-management/create-a-self-signed-root-ca-certificate.html" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/61/pan-os/pan-os/certificate-management/create-a-self-signed-root-ca-certificate.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also ensure the certificate that has been marked as a Trusted Root is pushed out.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This resolved the issue and a connection to the gateway is now successful.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind regards&lt;/P&gt;
&lt;P&gt;Jack&lt;/P&gt;</description>
      <pubDate>Fri, 01 Apr 2016 15:36:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-3-0-0-gateway-certificate-error-quot-server/m-p/75641#M42049</guid>
      <dc:creator>Jack_Howells</dc:creator>
      <dc:date>2016-04-01T15:36:52Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect 3.0.0 Gateway Certificate Error "Server Certificate verification failed&amp;quot</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-3-0-0-gateway-certificate-error-quot-server/m-p/78138#M42843</link>
      <description>&lt;P&gt;Thanks for the info Jack. This also applies to internally signed certs managed by an&amp;nbsp;internal certificate authority.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 16 May 2016 15:38:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-3-0-0-gateway-certificate-error-quot-server/m-p/78138#M42843</guid>
      <dc:creator>DavidNestler</dc:creator>
      <dc:date>2016-05-16T15:38:14Z</dc:date>
    </item>
  </channel>
</rss>

