<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Web interface connection refused  probably due to expired certificate. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/web-interface-connection-refused-probably-due-to-expired/m-p/218417#M63137</link>
    <description>&lt;P&gt;Hi again,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks a lot!&amp;nbsp; The restarting of the management plane did the trick.&amp;nbsp; After that we were able to relogin to the webinterface and I created a new cert and now all is well.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The 'disconnection' occurred at about same time as the https cert expired.&amp;nbsp; I'm on version 8.1.1.&amp;nbsp; Is it possible that the cert expiration caused the management plane to 'hang' so web interface access was disabled..?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyway, I'm just glad to be up and running again.&amp;nbsp; Thanks again &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tor&lt;/P&gt;</description>
    <pubDate>Tue, 19 Jun 2018 20:08:43 GMT</pubDate>
    <dc:creator>LCMember4427</dc:creator>
    <dc:date>2018-06-19T20:08:43Z</dc:date>
    <item>
      <title>Web interface connection refused  probably due to expired certificate.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/web-interface-connection-refused-probably-due-to-expired/m-p/218038#M63039</link>
      <description>&lt;P&gt;Hey,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The subject says it all...&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is a VM-100 with latest updates.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can log in to CLI and I wonder how can I list all certificates, identify the expired cert and if possible renew it, all through CLI.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for any comments and a list of my options in this situation &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;best regards Tor&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jun 2018 12:20:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/web-interface-connection-refused-probably-due-to-expired/m-p/218038#M63039</guid>
      <dc:creator>LCMember4427</dc:creator>
      <dc:date>2018-06-15T12:20:04Z</dc:date>
    </item>
    <item>
      <title>Re: Web interface connection refused  probably due to expired certificate.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/web-interface-connection-refused-probably-due-to-expired/m-p/218054#M63046</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/12561"&gt;@LCMember4427&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Pull the running configuration from the CLI, identify the cert in question and update it directly through the CLI and push it back to the box, load it and commit.&amp;nbsp;&lt;/P&gt;&lt;P&gt;FYI, an expired cert shouldn't block you from accessing the web interface; you should be able to bypass the warning and still access the GUI.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jun 2018 14:25:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/web-interface-connection-refused-probably-due-to-expired/m-p/218054#M63046</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-06-15T14:25:49Z</dc:date>
    </item>
    <item>
      <title>Re: Web interface connection refused  probably due to expired certificate.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/web-interface-connection-refused-probably-due-to-expired/m-p/218215#M63087</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the advice.&amp;nbsp; I got the config and found the properties of the expired certificate, see below.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There are a total of 6 certificate entries (but only this is expired).&amp;nbsp; Does it exist an how-to to renew or create a new cert?&amp;nbsp;&amp;nbsp; Thanks for comments on how I can proceed further by the CLI...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;regards Tor&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;CAUw7C29C79Fv1C5qfPrmAESrciIxpg0X40KPMbp1ZWVbd4=&lt;BR /&gt;-----END CERTIFICATE-----&lt;BR /&gt;&amp;lt;/public-key&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;algorithm&amp;gt;RSA&amp;lt;/algorithm&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;/entry&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;entry name="MyCompanys CA 2017"&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;subject-hash&amp;gt;c16a5de3&amp;lt;/subject-hash&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;issuer-hash&amp;gt;94d7a06a&amp;lt;/issuer-hash&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;not-valid-before&amp;gt;Jan 26 20:02:51 2017 GMT&amp;lt;/not-valid-before&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;issuer&amp;gt;/C=NO/ST=Some-State/O=MyCompany VGS&amp;lt;/issuer&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;not-valid-after&amp;gt;Jun 10 20:02:51 2018 GMT&amp;lt;/not-valid-after&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;common-name&amp;gt;172.23.10.2&amp;lt;/common-name&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;expiry-epoch&amp;gt;1528660971&amp;lt;/expiry-epoch&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;ca&amp;gt;no&amp;lt;/ca&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;subject&amp;gt;/C=NO/ST=Some-State/O=MyCompany VGS/OU=Firewall/CN=172.23.10.2&amp;lt;/subject&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;public-key&amp;gt;-----BEGIN CERTIFICATE-----&lt;BR /&gt;MIIDFjCCAf4CCQCYA5DXj+1MWDANBgkqhkiG9w0BAQsFADA4MQswCQYDVQQGEwJO&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jun 2018 08:27:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/web-interface-connection-refused-probably-due-to-expired/m-p/218215#M63087</guid>
      <dc:creator>LCMember4427</dc:creator>
      <dc:date>2018-06-18T08:27:47Z</dc:date>
    </item>
    <item>
      <title>Re: Web interface connection refused  probably due to expired certificate.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/web-interface-connection-refused-probably-due-to-expired/m-p/218225#M63089</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From the CLI:&lt;/P&gt;&lt;P&gt;&amp;gt; request certificate renew days-till-expiry &amp;lt;days&amp;gt; certificate-name &amp;lt;certname&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;gt; request certificate generate&lt;BR /&gt;+ ca&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Make this a signing certificate&lt;BR /&gt;+ country-code&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Country code&lt;BR /&gt;+ days-till-expiry&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Number of days till expiry&lt;BR /&gt;+ digest&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Digest Algorithm&lt;BR /&gt;+ email&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Email address of the contact person&lt;BR /&gt;+ filename&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; file name for the certificate&lt;BR /&gt;+ locality&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Locality&lt;BR /&gt;+ ocsp-responder-url&amp;nbsp;&amp;nbsp; ocsp-responder-url&lt;BR /&gt;+ organization&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Organization&lt;BR /&gt;+ signed-by&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; signed-by&lt;BR /&gt;+ state&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; State/province&lt;BR /&gt;* algorithm&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; algorithm&lt;BR /&gt;* certificate-name&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Name of the certificate object&lt;BR /&gt;* name&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; IP or FQDN to appear on the certificate&lt;BR /&gt;&amp;gt; alt-email&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Subject alternate Email type&lt;BR /&gt;&amp;gt; hostname&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Subject alternate name DNS type&lt;BR /&gt;&amp;gt; ip&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Subject alternate name IP type&lt;BR /&gt;&amp;gt; organization-unit&amp;nbsp;&amp;nbsp;&amp;nbsp; Department&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Seconding what &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt; has said - you should still be able to login to the webUI -even with an expired cert.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Luke.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jun 2018 11:59:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/web-interface-connection-refused-probably-due-to-expired/m-p/218225#M63089</guid>
      <dc:creator>LukeBullimore</dc:creator>
      <dc:date>2018-06-18T11:59:18Z</dc:date>
    </item>
    <item>
      <title>Re: Web interface connection refused  probably due to expired certificate.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/web-interface-connection-refused-probably-due-to-expired/m-p/218234#M63091</link>
      <description>&lt;P&gt;Hi again,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for all help.&amp;nbsp; I see your last comment both of you, however our webinterface ceased to respond at the day the CA cert expired and I read about it here:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/Unable-to-Access-Web-Console-via-HTTP-or-HTTPS/ta-p/53251" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/Unable-to-Access-Web-Console-via-HTTP-or-HTTPS/ta-p/53251&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you have other suggestions as to why our webinterface ceased to respond, I'm of course open to any help or troubleshooting tips.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyway, I tried to renew our current CA cert by this command:&lt;/P&gt;&lt;P&gt;VM-100&amp;gt; request certificate renew days-till-expiry 400 certificate-name "MyCompany CA 2017"&lt;BR /&gt;.. but got this error:&lt;BR /&gt;Server error : Failed to determine the issuer of certificate&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is a self signed cert, so which parameters do I apply to make it content ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks again &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;best regards Tor&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jun 2018 13:44:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/web-interface-connection-refused-probably-due-to-expired/m-p/218234#M63091</guid>
      <dc:creator>LCMember4427</dc:creator>
      <dc:date>2018-06-18T13:44:50Z</dc:date>
    </item>
    <item>
      <title>Re: Web interface connection refused  probably due to expired certificate.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/web-interface-connection-refused-probably-due-to-expired/m-p/218235#M63092</link>
      <description>&lt;P&gt;Hi Tor,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The article you sent actually mentions about the absence of a certificate entirely - rather than an expired one.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As per the article's recommendations, have you tried to assign the primary certificate from you chain to the webserver?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;gt; configure&lt;BR /&gt;# set deviceconfig system web-server-certificate &amp;lt;certname&amp;gt;&lt;BR /&gt;# commit&lt;BR /&gt;# exit&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regarding this error, I have not seen this before and the steps you took to renew the self signed-CA via CLI command are correct. If trying the above is unsuccessful, could you give the management server a reboot? (debug software restart process management-server) What Pan-OS version are you running also?&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jun 2018 13:53:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/web-interface-connection-refused-probably-due-to-expired/m-p/218235#M63092</guid>
      <dc:creator>LukeBullimore</dc:creator>
      <dc:date>2018-06-18T13:53:22Z</dc:date>
    </item>
    <item>
      <title>Re: Web interface connection refused  probably due to expired certificate.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/web-interface-connection-refused-probably-due-to-expired/m-p/218417#M63137</link>
      <description>&lt;P&gt;Hi again,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks a lot!&amp;nbsp; The restarting of the management plane did the trick.&amp;nbsp; After that we were able to relogin to the webinterface and I created a new cert and now all is well.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The 'disconnection' occurred at about same time as the https cert expired.&amp;nbsp; I'm on version 8.1.1.&amp;nbsp; Is it possible that the cert expiration caused the management plane to 'hang' so web interface access was disabled..?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyway, I'm just glad to be up and running again.&amp;nbsp; Thanks again &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tor&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jun 2018 20:08:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/web-interface-connection-refused-probably-due-to-expired/m-p/218417#M63137</guid>
      <dc:creator>LCMember4427</dc:creator>
      <dc:date>2018-06-19T20:08:43Z</dc:date>
    </item>
  </channel>
</rss>

