<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Problem renewing ssl certificates with global protect portal in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/problem-renewing-ssl-certificates-with-global-protect-portal/m-p/101359#M44488</link>
    <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="certificates2.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/5104i812578C6E8158460/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="certificates2.png" alt="certificates2.png" /&gt;&lt;/span&gt;﻿&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="config.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/5107i5D5573C4AD479566/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="config.png" alt="config.png" /&gt;&lt;/span&gt;﻿&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="error2.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/5105i8F00F7B87C76CC13/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="error2.png" alt="error2.png" /&gt;&lt;/span&gt;﻿Hi all,&lt;/P&gt;&lt;P&gt;I have the following problem. We have an ssl certificate (public ca) and this renews end of this month. We use ssl.domain.xx as gateway. Since we have to renew our certificate I ordered Networksolutions certificate and installed this within the certificates 'device/certificates' with the complete chain, according the normal procedure. Root certificate and intermediaire certificate give ca indicates. All well till here. Now I try to configure the portal configuration for globalprotect, where I have to provide the agent configuration. I install the root certificate under root-ca which goes well , but when I add the intermediairy certificates trusted by the root certificates, it gives the error "client-config is invalid" and "root-ca is invalid.&lt;/P&gt;&lt;P&gt;The only thing I can imagine, is that those are not indicated under "Default Trusted Certificate Authorities". It concerns the following ca's&amp;nbsp; :&lt;/P&gt;&lt;P&gt;OV_NetworkSolutionsOVServerCA2 and OV_USERTrustRSACertificationAuthority.&lt;/P&gt;&lt;P&gt;Anybody has an idea why those errors appear and how this can be fixed ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sat, 06 Aug 2016 13:36:35 GMT</pubDate>
    <dc:creator>johan.boeckx</dc:creator>
    <dc:date>2016-08-06T13:36:35Z</dc:date>
    <item>
      <title>Problem renewing ssl certificates with global protect portal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-renewing-ssl-certificates-with-global-protect-portal/m-p/101359#M44488</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="certificates2.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/5104i812578C6E8158460/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="certificates2.png" alt="certificates2.png" /&gt;&lt;/span&gt;﻿&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="config.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/5107i5D5573C4AD479566/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="config.png" alt="config.png" /&gt;&lt;/span&gt;﻿&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="error2.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/5105i8F00F7B87C76CC13/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="error2.png" alt="error2.png" /&gt;&lt;/span&gt;﻿Hi all,&lt;/P&gt;&lt;P&gt;I have the following problem. We have an ssl certificate (public ca) and this renews end of this month. We use ssl.domain.xx as gateway. Since we have to renew our certificate I ordered Networksolutions certificate and installed this within the certificates 'device/certificates' with the complete chain, according the normal procedure. Root certificate and intermediaire certificate give ca indicates. All well till here. Now I try to configure the portal configuration for globalprotect, where I have to provide the agent configuration. I install the root certificate under root-ca which goes well , but when I add the intermediairy certificates trusted by the root certificates, it gives the error "client-config is invalid" and "root-ca is invalid.&lt;/P&gt;&lt;P&gt;The only thing I can imagine, is that those are not indicated under "Default Trusted Certificate Authorities". It concerns the following ca's&amp;nbsp; :&lt;/P&gt;&lt;P&gt;OV_NetworkSolutionsOVServerCA2 and OV_USERTrustRSACertificationAuthority.&lt;/P&gt;&lt;P&gt;Anybody has an idea why those errors appear and how this can be fixed ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 06 Aug 2016 13:36:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-renewing-ssl-certificates-with-global-protect-portal/m-p/101359#M44488</guid>
      <dc:creator>johan.boeckx</dc:creator>
      <dc:date>2016-08-06T13:36:35Z</dc:date>
    </item>
    <item>
      <title>Re: Problem renewing ssl certificates with global protect portal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-renewing-ssl-certificates-with-global-protect-portal/m-p/329008#M83566</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/34337"&gt;@johan.boeckx&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I know it's been quite a while since you've posted this, but I hope this finds you well.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the past we started noticing issues quite similar to this in the now EOL 8.0 version. The fix to resolved this was included and confirmed in the latter 8.1.0 release.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If this doesn't (or did not) help, I would suggest calling into Support for further assistance from a TAC engineer.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope this helps!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;</description>
      <pubDate>Wed, 20 May 2020 15:18:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-renewing-ssl-certificates-with-global-protect-portal/m-p/329008#M83566</guid>
      <dc:creator>trivers01</dc:creator>
      <dc:date>2020-05-20T15:18:20Z</dc:date>
    </item>
  </channel>
</rss>

