<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Global Protect config problem: The server certificate is invalid. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-config-problem-the-server-certificate-is-invalid/m-p/329513#M83647</link>
    <description>&lt;P&gt;hey&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/84363"&gt;@GOMEZZZ&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I know it's been a while since you'v made this post, but I hope this message finds you well.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Based on the PanGPS logs you've previously posted, the Agent is unable to verify the server certificate used for the Gateway SSL/TLS profile.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Common issues for this would include CN mismatch, as mentioned before by other community members, and incorrect certificate deployment: eg the Agent is unable to follow the full chain. A quick way to test this is using your local browser to connect and reviewing the output messages.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could you please confirm the following:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. The root (and intermediate if applicable) CA(s) used to sign the imported Portal/Gateway certificate are deployed in the correct directories on the endpoint&lt;/P&gt;&lt;P&gt;2. The server certificate used for the Portal/Gateway has the correct CN (and SAN if applicable) attribute&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've included documentation discussing the certificate deployment options for GlobalProtect below for your reference also.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/globalprotect/9-1/globalprotect-admin/get-started/enable-ssl-between-globalprotect-components/deploy-server-certificates-to-the-globalprotect-components.html" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/globalprotect/9-1/globalprotect-admin/get-started/enable-ssl-between-globalprotect-components/deploy-server-certificates-to-the-globalprotect-components.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;-Cheers&lt;/P&gt;</description>
    <pubDate>Sat, 23 May 2020 00:02:47 GMT</pubDate>
    <dc:creator>trivers01</dc:creator>
    <dc:date>2020-05-23T00:02:47Z</dc:date>
    <item>
      <title>Global Protect config problem: The server certificate is invalid.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-config-problem-the-server-certificate-is-invalid/m-p/204513#M60147</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;In lab i am trying to setup a simple global protect configuration where the gateway and portal are on the same IP and just using local user authentication. &amp;nbsp;I have a certificate for my my public IP from let's ecnrypt and &amp;nbsp;have imported this into palo alto.&lt;/P&gt;
&lt;P&gt;I am able to connect to the portal without any certificate issues. &amp;nbsp;But when connecting through the gateway i am getting the server certficate is invalid.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My config looks like this:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Portal config:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;GPP-Portal {&lt;BR /&gt;portal-config {&lt;BR /&gt;client-auth {&lt;BR /&gt;GPP-AUTH {&lt;BR /&gt;os Any;&lt;BR /&gt;authentication-profile "Local-Database Authentication";&lt;BR /&gt;authentication-message "Enter login credentials";&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;local-address {&lt;BR /&gt;interface loopback;&lt;BR /&gt;ip {&lt;BR /&gt;ipv4 10.1.1.1;&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;custom-login-page factory-default;&lt;BR /&gt;custom-home-page factory-default;&lt;BR /&gt;custom-help-page factory-default;&lt;BR /&gt;ssl-tls-service-profile PORTAL-SSL-SERVICE-PROFILE;&lt;BR /&gt;}&lt;BR /&gt;client-config {&lt;BR /&gt;configs {&lt;BR /&gt;AUTH-PORTAL {&lt;BR /&gt;hip-collection {&lt;BR /&gt;max-wait-time 20;&lt;BR /&gt;collect-hip-data yes;&lt;BR /&gt;}&lt;BR /&gt;gateways {&lt;BR /&gt;external {&lt;BR /&gt;list {&lt;BR /&gt;fw.relianet.be {&lt;BR /&gt;fqdn fw.relianet.be;&lt;BR /&gt;priority-rule {&lt;BR /&gt;Any {&lt;BR /&gt;priority 1;&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;manual yes;&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;cutoff-time 5;&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;authentication-override {&lt;BR /&gt;generate-cookie no;&lt;BR /&gt;}&lt;BR /&gt;source-user any;&lt;BR /&gt;os Windows;&lt;BR /&gt;agent-ui {&lt;BR /&gt;max-agent-user-overrides 0;&lt;BR /&gt;agent-user-override-timeout 0;&lt;BR /&gt;}&lt;BR /&gt;gp-app-config {&lt;BR /&gt;config {&lt;BR /&gt;connect-method {&lt;BR /&gt;value on-demand;&lt;BR /&gt;}&lt;BR /&gt;refresh-config-interval {&lt;BR /&gt;value 24;&lt;BR /&gt;}&lt;BR /&gt;agent-user-override {&lt;BR /&gt;value allowed;&lt;BR /&gt;}&lt;BR /&gt;client-upgrade {&lt;BR /&gt;value prompt;&lt;BR /&gt;}&lt;BR /&gt;use-sso {&lt;BR /&gt;value no;&lt;BR /&gt;}&lt;BR /&gt;logout-remove-sso {&lt;BR /&gt;value yes;&lt;BR /&gt;}&lt;BR /&gt;krb-auth-fail-fallback {&lt;BR /&gt;value yes;&lt;BR /&gt;}&lt;BR /&gt;retry-tunnel {&lt;BR /&gt;value 30;&lt;BR /&gt;}&lt;BR /&gt;retry-timeout {&lt;BR /&gt;value 5;&lt;BR /&gt;}&lt;BR /&gt;enforce-globalprotect {&lt;BR /&gt;value no;&lt;BR /&gt;}&lt;BR /&gt;captive-portal-exception-timeout {&lt;BR /&gt;value 0;&lt;BR /&gt;}&lt;BR /&gt;traffic-blocking-notification-delay {&lt;BR /&gt;value 15;&lt;BR /&gt;}&lt;BR /&gt;display-traffic-blocking-notification-msg {&lt;BR /&gt;value yes;&lt;BR /&gt;}&lt;BR /&gt;traffic-blocking-notification-msg {&lt;BR /&gt;value '&amp;lt;div style="font-family:'Helvetica Neue';"&amp;gt;&amp;lt;h1 style="color:red;text-align:center; margin: 0; font-size: 30px;"&amp;gt;Notice&amp;lt;/h1&amp;gt;&amp;lt;p style="margin: 0;font-size: 15px; line-heigh&lt;BR /&gt;t: 1.2em;"&amp;gt;To access the network, you must first connect to GlobalProtect.&amp;lt;/p&amp;gt;&amp;lt;/div&amp;gt;';&lt;BR /&gt;}&lt;BR /&gt;allow-traffic-blocking-notification-dismissal {&lt;BR /&gt;value yes;&lt;BR /&gt;}&lt;BR /&gt;display-captive-portal-detection-msg {&lt;BR /&gt;value no;&lt;BR /&gt;}&lt;BR /&gt;captive-portal-detection-msg {&lt;BR /&gt;value '&amp;lt;div style="font-family:'Helvetica Neue';"&amp;gt;&amp;lt;h1 style="color:red;text-align:center; margin: 0; font-size: 30px;"&amp;gt;Captive Portal Detected&amp;lt;/h1&amp;gt;&amp;lt;p style="margin: 0; font-size&lt;BR /&gt;: 15px; line-height: 1.2em;"&amp;gt;GlobalProtect has temporarily permitted network access for you to connect to the Internet. Follow instructions from your internet provider.&amp;lt;/p&amp;gt;&amp;lt;p style="margin: 0&lt;BR /&gt;; font-size: 15px; line-height: 1.2em;"&amp;gt;If you let the connection time out, open GlobalProtect and click Connect to try again.&amp;lt;/p&amp;gt;&amp;lt;/div&amp;gt;';&lt;BR /&gt;}&lt;BR /&gt;certificate-store-lookup {&lt;BR /&gt;value user-and-machine;&lt;BR /&gt;}&lt;BR /&gt;scep-certificate-renewal-period {&lt;BR /&gt;value 7;&lt;BR /&gt;}&lt;BR /&gt;retain-connection-smartcard-removal {&lt;BR /&gt;value yes;&lt;BR /&gt;}&lt;BR /&gt;enable-advanced-view {&lt;BR /&gt;value yes;&lt;BR /&gt;}&lt;BR /&gt;enable-do-not-display-this-welcome-page-again {&lt;BR /&gt;value yes;&lt;BR /&gt;}&lt;BR /&gt;rediscover-network {&lt;BR /&gt;value yes;&lt;BR /&gt;}&lt;BR /&gt;resubmit-host-info {&lt;BR /&gt;value yes;&lt;BR /&gt;}&lt;BR /&gt;can-change-portal {&lt;BR /&gt;value yes;&lt;BR /&gt;}&lt;BR /&gt;can-continue-if-portal-cert-invalid {&lt;BR /&gt;value yes;&lt;BR /&gt;}&lt;BR /&gt;show-agent-icon {&lt;BR /&gt;value yes;&lt;BR /&gt;}&lt;BR /&gt;user-switch-tunnel-rename-timeout {&lt;BR /&gt;value 0;&lt;BR /&gt;}&lt;BR /&gt;pre-logon-tunnel-rename-timeout {&lt;BR /&gt;value -1;&lt;BR /&gt;}&lt;BR /&gt;show-system-tray-notifications {&lt;BR /&gt;value no;&lt;BR /&gt;}&lt;BR /&gt;max-internal-gateway-connection-attempts {&lt;BR /&gt;value 0;&lt;BR /&gt;}&lt;BR /&gt;portal-timeout {&lt;BR /&gt;value 5;&lt;BR /&gt;}&lt;BR /&gt;connect-timeout {&lt;BR /&gt;value 5;&lt;BR /&gt;}&lt;BR /&gt;receive-timeout {&lt;BR /&gt;value 30;&lt;BR /&gt;}&lt;BR /&gt;enforce-dns {&lt;BR /&gt;value yes;&lt;BR /&gt;}&lt;BR /&gt;flush-dns {&lt;BR /&gt;value no;&lt;BR /&gt;}&lt;BR /&gt;proxy-multiple-autodetect {&lt;BR /&gt;value no;&lt;BR /&gt;}&lt;BR /&gt;wsc-autodetect {&lt;BR /&gt;value yes;&lt;BR /&gt;}&lt;BR /&gt;mfa-enabled {&lt;BR /&gt;value no;&lt;BR /&gt;}&lt;BR /&gt;mfa-listening-port {&lt;BR /&gt;value 4501;&lt;BR /&gt;}&lt;BR /&gt;mfa-notification-msg {&lt;BR /&gt;value "You have attempted to access a protected resource that requires additional authentication. Proceed to authenticate at";&lt;BR /&gt;}&lt;BR /&gt;ipv6-preferred {&lt;BR /&gt;value yes;&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;save-user-credentials 2;&lt;BR /&gt;portal-2fa no;&lt;BR /&gt;manual-only-gateway-2fa no;&lt;BR /&gt;internal-gateway-2fa no;&lt;BR /&gt;auto-discovery-external-gateway-2fa no;&lt;BR /&gt;mdm-enrollment-port 443;&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;satellite-config {&lt;BR /&gt;client-certificate {&lt;BR /&gt;local;&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;}&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;GATEWAY:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;GP-GATEWAY {&lt;BR /&gt;roles {&lt;BR /&gt;default {&lt;BR /&gt;login-lifetime {&lt;BR /&gt;days 30;&lt;BR /&gt;}&lt;BR /&gt;inactivity-logout {&lt;BR /&gt;hours 3;&lt;BR /&gt;}&lt;BR /&gt;disconnect-on-idle {&lt;BR /&gt;minutes 180;&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;client-auth {&lt;BR /&gt;GPG-CLIENT-AUTH {&lt;BR /&gt;authentication-profile "Local-Database Authentication";&lt;BR /&gt;os Any;&lt;BR /&gt;authentication-message "Enter login credentials";&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;remote-user-tunnel-configs {&lt;BR /&gt;GPG-Agent {&lt;BR /&gt;authentication-override {&lt;BR /&gt;generate-cookie no;&lt;BR /&gt;}&lt;BR /&gt;split-tunneling {&lt;BR /&gt;access-route 192.168.1.0/24;&lt;BR /&gt;exclude-access-route;&lt;BR /&gt;}&lt;BR /&gt;source-user any;&lt;BR /&gt;authentication-server-ip-pool;&lt;BR /&gt;ip-pool 192.168.250.0/24;&lt;BR /&gt;os any;&lt;BR /&gt;retrieve-framed-ip-address no;&lt;BR /&gt;no-direct-access-to-local-network no;&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;ssl-tls-service-profile PORTAL-SSL-SERVICE-PROFILE;&lt;BR /&gt;tunnel-mode yes;&lt;BR /&gt;remote-user-tunnel tunnel.3;&lt;BR /&gt;}&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Anybody that can help me out with this.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Mar 2020 14:21:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-config-problem-the-server-certificate-is-invalid/m-p/204513#M60147</guid>
      <dc:creator>GOMEZZZ</dc:creator>
      <dc:date>2020-03-20T14:21:22Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect config problem: The server certificate is invalid.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-config-problem-the-server-certificate-is-invalid/m-p/204521#M60148</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/84363"&gt;@GOMEZZZ&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You might be running into the following issue :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/GlobalProtect-Gateway-Certificate-Error-When-Trying-to-connect/ta-p/57043" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/GlobalProtect-Gateway-Certificate-Error-When-Trying-to-connect/ta-p/57043&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps.&lt;/P&gt;
&lt;P&gt;Cheers !&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;</description>
      <pubDate>Fri, 09 Mar 2018 08:19:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-config-problem-the-server-certificate-is-invalid/m-p/204521#M60148</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2018-03-09T08:19:45Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect config problem: The server certificate is invalid.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-config-problem-the-server-certificate-is-invalid/m-p/205342#M60294</link>
      <description>&lt;P&gt;Hi Kiwi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It doesnet seem to be related to this issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Frederik.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Mar 2018 07:53:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-config-problem-the-server-certificate-is-invalid/m-p/205342#M60294</guid>
      <dc:creator>GOMEZZZ</dc:creator>
      <dc:date>2018-03-14T07:53:49Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect config problem: The server certificate is invalid.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-config-problem-the-server-certificate-is-invalid/m-p/205592#M60344</link>
      <description>&lt;P&gt;If you have a certificate on your IP; instead of your hostname; you need to change the external gateway FQDN name to the IP and not use&amp;nbsp;&lt;SPAN&gt;fw.relianet.be&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So change this:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;gateways {external {list {fw.relianet.be {fqdn fw.relianet.be;priority-rule {Any {priority 1;}}&lt;/PRE&gt;&lt;P&gt;To this:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;gateways {external {list {fw.relianet.be {fqdn &amp;lt;your IP address&amp;gt;;priority-rule {Any {priority 1;}}&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A-&lt;/P&gt;</description>
      <pubDate>Thu, 15 Mar 2018 08:23:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-config-problem-the-server-certificate-is-invalid/m-p/205592#M60344</guid>
      <dc:creator>AndyC_234</dc:creator>
      <dc:date>2018-03-15T08:23:26Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect config problem: The server certificate is invalid.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-config-problem-the-server-certificate-is-invalid/m-p/205669#M60374</link>
      <description>&lt;P&gt;Hi andy,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a certificate with subject and SAN set to fw.relianet.be&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="cert.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/14255iF246E302835DD763/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="cert.PNG" alt="cert.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I modified it as you suggest for testing but still have the same result:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;gateways {&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; external {&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; list {&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; fw.relianet.be {&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ip {&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ipv4 81.83.18.57;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; }&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; priority-rule {&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Any {&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; priority 1;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; }&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If&amp;nbsp; you need any other output screenshots please let me know.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tnx,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Frederik.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Mar 2018 15:06:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-config-problem-the-server-certificate-is-invalid/m-p/205669#M60374</guid>
      <dc:creator>GOMEZZZ</dc:creator>
      <dc:date>2018-03-15T15:06:45Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect config problem: The server certificate is invalid.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-config-problem-the-server-certificate-is-invalid/m-p/205672#M60377</link>
      <description>&lt;P&gt;I would enable the debugger on the client, and see why it's not accepting your cerftificate, it will tell you exactly what is wrong.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you right click on your client, you can choose "Collect Logs", open that zipfile and open PanGPS.log.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Look for anything related to SSL:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;(T21656) 03/12/18 15:19:20:667 Debug( 322): Open_SSL_connection: subject '/C=US/ST=West Virginia/L=Charleston/O=xxxxxxxxx (US) Inc./OU=IS/CN=*.xxxxxxx.com'
(T21656) 03/12/18 15:19:20:667 Debug( 326): Open_SSL_connection: issuer '/C=US/O=DigiCert Inc/CN=DigiCert SHA2 Secure Server CA'
(T21656) 03/12/18 15:19:20:667 Debug(1006): Name vpn.xxxxxxxxx.com matches pattern *.xxxxxxx.com
(T21656) 03/12/18 15:19:20:667 Debug( 923): Cert name check of *.xxxxxxx.com succeeded&lt;/PRE&gt;</description>
      <pubDate>Thu, 15 Mar 2018 15:26:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-config-problem-the-server-certificate-is-invalid/m-p/205672#M60377</guid>
      <dc:creator>AndyC_234</dc:creator>
      <dc:date>2018-03-15T15:26:17Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect config problem: The server certificate is invalid.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-config-problem-the-server-certificate-is-invalid/m-p/205685#M60379</link>
      <description>&lt;P&gt;6:39:52:897 Debug( 545): Failed to connect to 81.83.18.57 on 443 with return error -1 and socket error 0(The operation completed successfully.)&lt;BR /&gt;(T5540) 03/15/18 16:39:52:897 Debug( 697): do_tcp_connect() failed&lt;BR /&gt;(T5540) 03/15/18 16:39:52:897 Error(7700): ConnectSSL: Failed to connect to '81.83.18.57:443'. Disconnect ssl.&lt;BR /&gt;(T5540) 03/15/18 16:39:52:897 Debug(7711): Cannot get server cert of 81.83.18.57&lt;BR /&gt;(T5540) 03/15/18 16:39:52:897 Debug(5145): Already tried both ipv4 and ipv6 for gateway fw.relianet.be&lt;BR /&gt;(T5540) 03/15/18 16:39:52:897 Error(2845): Failed to verify server certificate of gateway fw.relianet.be.&lt;BR /&gt;(T5540) 03/15/18 16:39:52:897 Debug(4576): Show Gateway fw.relianet.be: The server certificate is invalid. Please contact your IT administrator.&lt;BR /&gt;(T5540) 03/15/18 16:39:52:897 Info (2148): Failed to retrieve info for gateway fw.relianet.be.&lt;BR /&gt;(T5540) 03/15/18 16:39:52:897 Debug(2155): tunnel to fw.relianet.be is not created.&lt;BR /&gt;(T5540) 03/15/18 16:39:52:897 Error(3876): NetworkDiscoverThread: failed to discover external network.&lt;BR /&gt;(T5540) 03/15/18 16:39:52:897 Debug(4733): --Set state to Disconnected&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I also remove the global protect client and clear the folders in C:\Users\username\appddata\local\Palo alto\...&lt;/P&gt;&lt;P&gt;Everytime i change something.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Mar 2018 15:50:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-config-problem-the-server-certificate-is-invalid/m-p/205685#M60379</guid>
      <dc:creator>GOMEZZZ</dc:creator>
      <dc:date>2018-03-15T15:50:03Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect config problem: The server certificate is invalid.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-config-problem-the-server-certificate-is-invalid/m-p/296832#M78004</link>
      <description>&lt;P&gt;Was this ever resolved? - I see the exact type errors in my log and its not clear where to go from here.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Nov 2019 19:40:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-config-problem-the-server-certificate-is-invalid/m-p/296832#M78004</guid>
      <dc:creator>SturgisIT</dc:creator>
      <dc:date>2019-11-06T19:40:02Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect config problem: The server certificate is invalid.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-config-problem-the-server-certificate-is-invalid/m-p/296858#M78006</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/84363"&gt;@GOMEZZZ&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please check the following.&lt;/P&gt;&lt;P&gt;- Try with a different version of GP.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;- It can happen if you have external root CA.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;Please try to install a client certificate issued by your domain server(Root CA).&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Also make sure two things below.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;- Add Root CA, PAN Forward Trust certificate in CA certificates under Certificate Profile&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;- Add Root CA, PAN Forward Trust certificate in Trusted Root CA under GP portal config.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Nov 2019 22:38:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-config-problem-the-server-certificate-is-invalid/m-p/296858#M78006</guid>
      <dc:creator>FarzanaMustafa</dc:creator>
      <dc:date>2019-11-06T22:38:55Z</dc:date>
    </item>
    <item>
      <title>Invalid http response</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-config-problem-the-server-certificate-is-invalid/m-p/324847#M82880</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hello Team,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I am having the below issue and I do enter my&amp;nbsp; "Local Credentials" but nothing happens. Please help me.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;invalid http response. return error(Credential authentication failed; Retry authentication). - 04/24/2020 21:42:09&amp;nbsp;&amp;nbsp;(&lt;/SPAN&gt;&lt;A title="Click to refresh portal configuration." target="_blank"&gt;enter credentials&lt;/A&gt;&lt;SPAN&gt;)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thank you,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Mohammad Rahman&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 25 Apr 2020 03:34:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-config-problem-the-server-certificate-is-invalid/m-p/324847#M82880</guid>
      <dc:creator>Mrahman1</dc:creator>
      <dc:date>2020-04-25T03:34:13Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect config problem: The server certificate is invalid.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-config-problem-the-server-certificate-is-invalid/m-p/329513#M83647</link>
      <description>&lt;P&gt;hey&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/84363"&gt;@GOMEZZZ&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I know it's been a while since you'v made this post, but I hope this message finds you well.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Based on the PanGPS logs you've previously posted, the Agent is unable to verify the server certificate used for the Gateway SSL/TLS profile.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Common issues for this would include CN mismatch, as mentioned before by other community members, and incorrect certificate deployment: eg the Agent is unable to follow the full chain. A quick way to test this is using your local browser to connect and reviewing the output messages.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could you please confirm the following:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. The root (and intermediate if applicable) CA(s) used to sign the imported Portal/Gateway certificate are deployed in the correct directories on the endpoint&lt;/P&gt;&lt;P&gt;2. The server certificate used for the Portal/Gateway has the correct CN (and SAN if applicable) attribute&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've included documentation discussing the certificate deployment options for GlobalProtect below for your reference also.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/globalprotect/9-1/globalprotect-admin/get-started/enable-ssl-between-globalprotect-components/deploy-server-certificates-to-the-globalprotect-components.html" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/globalprotect/9-1/globalprotect-admin/get-started/enable-ssl-between-globalprotect-components/deploy-server-certificates-to-the-globalprotect-components.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;-Cheers&lt;/P&gt;</description>
      <pubDate>Sat, 23 May 2020 00:02:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-config-problem-the-server-certificate-is-invalid/m-p/329513#M83647</guid>
      <dc:creator>trivers01</dc:creator>
      <dc:date>2020-05-23T00:02:47Z</dc:date>
    </item>
  </channel>
</rss>

