<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Global Protect config problem: The server certificate is invalid. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-config-problem-the-server-certificate-is-invalid/m-p/217494#M62914</link>
    <description>&lt;P&gt;Hello Luke, thank you for your reply.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. On the GP portal website we get a warning (issuer of the certificate is unknown). But this is always happening and there are no problems with GP gateways in other locations wich are also configured with this portal.&lt;/P&gt;&lt;P&gt;1.1 That is correct. It was just filtered out. Here a screenshot with all certificates of the gw:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1.JPG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/15463iA6CB7BB78E0878DA/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="1.JPG" alt="1.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2. IP and CN are exactly the same. It was working with this configuration over months without problems before.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;3. I will activate this setting and check again &lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1.JPG" style="width: 340px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/15464i488AA18EBEAB3C86/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="1.JPG" alt="1.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 12 Jun 2018 09:04:58 GMT</pubDate>
    <dc:creator>Clermont</dc:creator>
    <dc:date>2018-06-12T09:04:58Z</dc:date>
    <item>
      <title>Global Protect config problem: The server certificate is invalid.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-config-problem-the-server-certificate-is-invalid/m-p/217157#M62836</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;we are not able to connect to one of our Gateways anymore. We get the error: The server certificate is invalid.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I checked the following but this looks correct:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Incorrect time settings on the firewall.&lt;/LI&gt;
&lt;LI&gt;Check the certificate's validation dates (valid from and valid until) to make sure the date range is correct.&lt;/LI&gt;
&lt;LI&gt;Check the Time Setting on the firewall. Use NTP if the time stamp isn't accurate.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;We have a certificate with an IP adress, no FQDN.&lt;/P&gt;
&lt;P&gt;Here is the log of the client:&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="GP-log.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/15436i614C55C30AA6F79A/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="GP-log.png" alt="GP-log.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;The Gateway was wortking normally until today.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Anybody that can help me out with this?&lt;/P&gt;</description>
      <pubDate>Fri, 20 Mar 2020 14:19:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-config-problem-the-server-certificate-is-invalid/m-p/217157#M62836</guid>
      <dc:creator>Clermont</dc:creator>
      <dc:date>2020-03-20T14:19:44Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect config problem: The server certificate is invalid.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-config-problem-the-server-certificate-is-invalid/m-p/217191#M62843</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/64981"&gt;@Clermont&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Are you positive that the server certificate is actually valid and wasn't pulled by whoever issued it to you? Do you connect via the IP address or an FQDN that you've configured?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Jun 2018 15:03:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-config-problem-the-server-certificate-is-invalid/m-p/217191#M62843</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-06-08T15:03:47Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect config problem: The server certificate is invalid.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-config-problem-the-server-certificate-is-invalid/m-p/217317#M62876</link>
      <description>&lt;P&gt;Thank you very much for your reply.&lt;/P&gt;&lt;P&gt;The certificate is self issued from our local root-ca.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The local firewall and the portal-firewall show it as valid:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Unbenannt.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/15442i1D8C8B7C9B62C137/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Unbenannt.png" alt="Unbenannt.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We caonnect to the IP-adress, FQDN is not used in this case.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jun 2018 08:05:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-config-problem-the-server-certificate-is-invalid/m-p/217317#M62876</guid>
      <dc:creator>Clermont</dc:creator>
      <dc:date>2018-06-11T08:05:59Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect config problem: The server certificate is invalid.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-config-problem-the-server-certificate-is-invalid/m-p/217340#M62879</link>
      <description>&lt;P&gt;Did you tried to add this certificate as trusted in portal configuraion? Portal will send this certificate to agent as trusted. It helps a lot if there is an issue with verification of root certificate on client.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you have IP address of gateway configured on portal configuration?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jun 2018 11:48:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-config-problem-the-server-certificate-is-invalid/m-p/217340#M62879</guid>
      <dc:creator>jarbu</dc:creator>
      <dc:date>2018-06-11T11:48:19Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect config problem: The server certificate is invalid.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-config-problem-the-server-certificate-is-invalid/m-p/217377#M62887</link>
      <description>&lt;P&gt;1. If you browse to the GP portal address, do you receive any certificate errors?&lt;/P&gt;&lt;P&gt;1.1 If yes, and this is a publically signed certificate, there is an issue with the certificate chain. From the screenshot you sent there is only one root certificate, when I would expect one more, the intermediate certificate.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1.2 If yes, and its a self signed certificate, no issue we will get to this next.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2. The common name of the certificate needs to match the IP address of the GP gateway as specified in Network -&amp;gt; Portals -&amp;gt; Portal name -&amp;gt; Agent -&amp;gt; Agent name -&amp;gt; External/internal -&amp;gt; Gateways -&amp;gt; "IP Address"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;3. If yes to 1.2 then you can get the GP client to automatically import the root certificates to the machines trusted root store as per the below configuration. However as per point 1.1 I believe not all root certificates are present on the firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Network -&amp;gt; Portals -&amp;gt; Portal name -&amp;gt; Agent -&amp;gt; Trusted Root CA&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Select the boxes "Install in Local Root Certificate Store"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Luke.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jun 2018 15:39:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-config-problem-the-server-certificate-is-invalid/m-p/217377#M62887</guid>
      <dc:creator>LukeBullimore</dc:creator>
      <dc:date>2018-06-11T15:39:35Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect config problem: The server certificate is invalid.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-config-problem-the-server-certificate-is-invalid/m-p/217489#M62911</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Thank you for the advice. Can you tell me please where I can find ths point (add this certificate as trusted in portal configuraion)?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is it unbder Network --&amp;gt; Global Protect --&amp;gt; Portals --&amp;gt; &amp;lt;Portal_Name&amp;gt; (GlobalProtect Portal Configuration) --&amp;gt; Agent&amp;nbsp; ?&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1.JPG" style="width: 302px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/15462iA8F86D139289FB1A/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="1.JPG" alt="1.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm sorry, I'm not that familier with the GlobalProtect Configuration, because I have not setup iut by myself&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the portal configuration we use the IP-adress&amp;nbsp; (not FQDN)&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jun 2018 08:45:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-config-problem-the-server-certificate-is-invalid/m-p/217489#M62911</guid>
      <dc:creator>Clermont</dc:creator>
      <dc:date>2018-06-12T08:45:59Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect config problem: The server certificate is invalid.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-config-problem-the-server-certificate-is-invalid/m-p/217491#M62912</link>
      <description>&lt;P&gt;Hi.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This step is only necessary if the certs are self signed. If you check both check boxes "Install in Local Root Certificate Store" the GP client will install the certs in the trusted root CA store so the client trusts the certs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are your certs publically signed? If yes, this isn''t necessary. If you browse to GP portal do you get cert errors? If yes there is something wrong with chain.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Luke.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jun 2018 08:58:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-config-problem-the-server-certificate-is-invalid/m-p/217491#M62912</guid>
      <dc:creator>LukeBullimore</dc:creator>
      <dc:date>2018-06-12T08:58:33Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect config problem: The server certificate is invalid.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-config-problem-the-server-certificate-is-invalid/m-p/217494#M62914</link>
      <description>&lt;P&gt;Hello Luke, thank you for your reply.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. On the GP portal website we get a warning (issuer of the certificate is unknown). But this is always happening and there are no problems with GP gateways in other locations wich are also configured with this portal.&lt;/P&gt;&lt;P&gt;1.1 That is correct. It was just filtered out. Here a screenshot with all certificates of the gw:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1.JPG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/15463iA6CB7BB78E0878DA/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="1.JPG" alt="1.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2. IP and CN are exactly the same. It was working with this configuration over months without problems before.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;3. I will activate this setting and check again &lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1.JPG" style="width: 340px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/15464i488AA18EBEAB3C86/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="1.JPG" alt="1.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jun 2018 09:04:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-config-problem-the-server-certificate-is-invalid/m-p/217494#M62914</guid>
      <dc:creator>Clermont</dc:creator>
      <dc:date>2018-06-12T09:04:58Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect config problem: The server certificate is invalid.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-config-problem-the-server-certificate-is-invalid/m-p/217496#M62916</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There is definitely something wrong with the certificate chain. The primary certificate looks to be signed by the root CA and not the intermediate. The primary certificate also marked as "certificate authority".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What I would expect&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Root CA (Common name can be anything), marked as Certificate Authority&lt;/P&gt;&lt;P&gt;Intermediate CA (Common name can be anything), marked as Certificate Authority, signed by root CA&lt;/P&gt;&lt;P&gt;Primary Certificate (Common name is IP address), not marked as Certificate Authority, signed by intermediate CA.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Then attach the primary certificate to a SSL/TLS profile; attach this profile to the "authentication" tab of any relevant portals and gateways.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Luke.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jun 2018 09:08:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-config-problem-the-server-certificate-is-invalid/m-p/217496#M62916</guid>
      <dc:creator>LukeBullimore</dc:creator>
      <dc:date>2018-06-12T09:08:59Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect config problem: The server certificate is invalid.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-config-problem-the-server-certificate-is-invalid/m-p/217500#M62919</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the strange thing is that it was wortking with this configuration for a long time before.&lt;/P&gt;&lt;P&gt;We have other similar configured gateways, that are still working now without this issue:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1.JPG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/15465iE4271157D8EA9B5F/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="1.JPG" alt="1.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Here an example from another gw.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jun 2018 09:49:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-config-problem-the-server-certificate-is-invalid/m-p/217500#M62919</guid>
      <dc:creator>Clermont</dc:creator>
      <dc:date>2018-06-12T09:49:28Z</dc:date>
    </item>
  </channel>
</rss>

