<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: User-ID Agent - Failed to validate client certificate in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-failed-to-validate-client-certificate/m-p/173669#M54637</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/69584"&gt;@luke.lloyd-jones&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have not tested versions that far apart but will this even work ?&lt;/P&gt;
&lt;P&gt;Just asking because the UID agent release notes say it'll only work with supported releases :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;The User‐ID agent is compatible with PAN‐OS 8.0 and earlier PAN‐OS releases that are still supported by Palo Alto Networks.&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That said, PAN-OS 6.0 was end-of-life&amp;nbsp;&lt;SPAN&gt;March 19, 2017.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;It might work if you fix the certs as mentioned earlier but I'd go and upgrade to a supported version.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Cheers,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;-Kiwi.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 29 Aug 2017 14:53:25 GMT</pubDate>
    <dc:creator>kiwi</dc:creator>
    <dc:date>2017-08-29T14:53:25Z</dc:date>
    <item>
      <title>User-ID Agent - Failed to validate client certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-failed-to-validate-client-certificate/m-p/173588#M54617</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am running a v6.0 Palo virtual firewall and trying to connect to a user-id agent on a Windows 2k8r2 server. I am running version 8.0.4-5 of the UID agent.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have configured as per all documentation however I am getting the following log messages popping up in the agent software:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Failed to validate client certificate, thread : 1, 1-0!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I check the logs on the firewall itself I have following log messages popping up every 5 seconds:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;pan_ssl_conn_open(pan_ssl_utils.c:464): Error: Failed to Connect to 192.168.5.100(source: 192.168.5.11), SSL error: error:00000000:lib(0):func(0):reason(0)(5)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am truly at my wits end, cannot seem to find anything useful about this online and not sure how to troubleshoot this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does anyone have any suggestions?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Tue, 29 Aug 2017 10:57:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-failed-to-validate-client-certificate/m-p/173588#M54617</guid>
      <dc:creator>luke.lloyd-jones</dc:creator>
      <dc:date>2017-08-29T10:57:43Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Agent - Failed to validate client certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-failed-to-validate-client-certificate/m-p/173661#M54632</link>
      <description>&lt;P&gt;Do you have an SSL/TSL profile?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There's a cert issue for sure with the SSL connection. So either the agent or the firewall are using out of date certs or some other mismatch.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Aug 2017 14:34:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-failed-to-validate-client-certificate/m-p/173661#M54632</guid>
      <dc:creator>ChrisRussell</dc:creator>
      <dc:date>2017-08-29T14:34:59Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Agent - Failed to validate client certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-failed-to-validate-client-certificate/m-p/173669#M54637</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/69584"&gt;@luke.lloyd-jones&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have not tested versions that far apart but will this even work ?&lt;/P&gt;
&lt;P&gt;Just asking because the UID agent release notes say it'll only work with supported releases :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;The User‐ID agent is compatible with PAN‐OS 8.0 and earlier PAN‐OS releases that are still supported by Palo Alto Networks.&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That said, PAN-OS 6.0 was end-of-life&amp;nbsp;&lt;SPAN&gt;March 19, 2017.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;It might work if you fix the certs as mentioned earlier but I'd go and upgrade to a supported version.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Cheers,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;-Kiwi.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Aug 2017 14:53:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-failed-to-validate-client-certificate/m-p/173669#M54637</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2017-08-29T14:53:25Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Agent - Failed to validate client certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-failed-to-validate-client-certificate/m-p/174860#M54863</link>
      <description>&lt;P&gt;Thanks for the tip, I thought those two would be compatible but turns out not. I actually just removed my v8 UID agent and installed the v6 version (had to remove the service first though with a "&lt;SPAN&gt;sc delete "UserIDService&lt;/SPAN&gt;" command, super annoying) and all working now.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Sep 2017 08:31:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-failed-to-validate-client-certificate/m-p/174860#M54863</guid>
      <dc:creator>luke.lloyd-jones</dc:creator>
      <dc:date>2017-09-05T08:31:52Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Agent - Failed to validate client certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-failed-to-validate-client-certificate/m-p/179593#M55709</link>
      <description>&lt;P&gt;I'm using PAN-OS 6.1 and have the same problem. Unfortuntely I have to use the latest version because this is the only version supported on my 2016 DC.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Certificates should be fine on both sides. Is there any other thing I can check?&lt;/P&gt;&lt;P&gt;Is it possible to disable the certificate check in User-ID Agent 8.0.4?&lt;/P&gt;</description>
      <pubDate>Mon, 02 Oct 2017 13:59:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-failed-to-validate-client-certificate/m-p/179593#M55709</guid>
      <dc:creator>Tobi</dc:creator>
      <dc:date>2017-10-02T13:59:52Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Agent - Failed to validate client certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-failed-to-validate-client-certificate/m-p/187706#M57076</link>
      <description>&lt;P&gt;This was a bug. Fixed with User-ID Agent 8.0.5!&lt;/P&gt;</description>
      <pubDate>Fri, 17 Nov 2017 15:07:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-failed-to-validate-client-certificate/m-p/187706#M57076</guid>
      <dc:creator>Tobi</dc:creator>
      <dc:date>2017-11-17T15:07:43Z</dc:date>
    </item>
  </channel>
</rss>

