<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: User-ID Connection Security Won't Work in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-connection-security-won-t-work/m-p/352187#M87149</link>
    <description>&lt;P&gt;Hello TylerHay,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There are really no tricks...&lt;/P&gt;&lt;P&gt;Here's a working config I just did in my lab. It might give you an idea of what went wrong with your setup.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On the PA Firewall:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Create a CA root:&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Rievax_0-1601050933302.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/27939i573E2FCC63B32783/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Rievax_0-1601050933302.png" alt="Rievax_0-1601050933302.png" /&gt;&lt;/span&gt;&lt;P&gt;No need to enter any other information as this is to create a self signed cert later&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;Now, create the self signed certificate. Make sure you signed it with the CA we just created. Enter at least the valid IP in the attributes to make this certificate valid:&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Rievax_1-1601051133513.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/27940i318545CBC7585D33/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Rievax_1-1601051133513.png" alt="Rievax_1-1601051133513.png" /&gt;&lt;/span&gt;&lt;/LI&gt;&lt;LI&gt;You will end up with something similar:&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Rievax_2-1601051191317.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/27941i77D47DD3D5FBD98A/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Rievax_2-1601051191317.png" alt="Rievax_2-1601051191317.png" /&gt;&lt;/span&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;Now, select the self-signed certificate (PA-UID-Cert in this case) and export it with the private key:&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Rievax_4-1601051308004.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/27943iF729CDABA65D6F9A/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Rievax_4-1601051308004.png" alt="Rievax_4-1601051308004.png" /&gt;&lt;/span&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;Now, create a certificate profile with no other information than the CA root that has been created:&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Rievax_5-1601051424446.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/27944iC82ECB3D7DC20D4F/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Rievax_5-1601051424446.png" alt="Rievax_5-1601051424446.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;&lt;LI&gt;Assign this Certificate profile too the "Connection Security" tab:&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Rievax_6-1601051530439.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/27945iFF2815C7605E837B/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Rievax_6-1601051530439.png" alt="Rievax_6-1601051530439.png" /&gt;&lt;/span&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;You can now add the user ID agent configuration:&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Rievax_7-1601051658048.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/27946iBF4CF617E0FEDEF9/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Rievax_7-1601051658048.png" alt="Rievax_7-1601051658048.png" /&gt;&lt;/span&gt;&lt;/LI&gt;&lt;LI&gt;Commit the changes.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On the UserID server:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Add the certificate :&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Rievax_8-1601051838947.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/27947i79F20C28EAE3F766/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Rievax_8-1601051838947.png" alt="Rievax_8-1601051838947.png" /&gt;&lt;/span&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;Save and commit the changes...&lt;/LI&gt;&lt;LI&gt;Go to "User Identification". After a few seconds, it should change the status to connected:&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Rievax_9-1601051944044.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/27948i804A4D5D5FC5CB73/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Rievax_9-1601051944044.png" alt="Rievax_9-1601051944044.png" /&gt;&lt;/span&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;On the PA side, it says the same:&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Rievax_10-1601052001004.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/27949iC7EC63F3E2C07E03/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Rievax_10-1601052001004.png" alt="Rievax_10-1601052001004.png" /&gt;&lt;/span&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Hope that helps!&lt;/P&gt;&lt;P&gt;R.&lt;/P&gt;</description>
    <pubDate>Fri, 25 Sep 2020 16:40:23 GMT</pubDate>
    <dc:creator>Rievax</dc:creator>
    <dc:date>2020-09-25T16:40:23Z</dc:date>
    <item>
      <title>User-ID Connection Security Won't Work</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-connection-security-won-t-work/m-p/352137#M87139</link>
      <description>&lt;P&gt;UserID Agent version 9.0.5-8&lt;BR /&gt;Firewall 9.0.8&lt;/P&gt;&lt;P&gt;Windows Server 2016 UserID Agent Servers x2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've tried following this guide and numerous others (&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClGFCA0" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClGFCA0&lt;/A&gt;)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Keep getting 'Failed to validate client certificate, thread : 1 , 5-10054!' as shown at the very bottom of the aforementioned support article and seeing SSL failures in the system log of the firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've tried generating the cert about a hundred different ways and formats on the server/firewall, and I still get the issue. I've tried using IP, FQDN, Subject-Alternative-Name including IP, Hostname, FQDN, one all or any. Port 5007 is open and the server worked previously. Now my certificate is stuck in the User-ID software and I cant delete it or use the server any longer with the firewall for regular user ID which is annoying. There is no delete/remove button to take the cert back out of the software so I pretty much have to get this working now as I'm down to 1 User-ID box.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;At this point I'm missing something fundamental, like a check box on the firewall or some hidden thing. I've installed certificates for Decrypt in and out, Management address, and all sorts of certificates and never had any problems until this. Has anyone successfully set this up and they can walk me through how you did it and maybe I can see my error? I have heard that IP address must be used in the SAN attribute, but that didn't work either.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Sep 2020 13:44:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-connection-security-won-t-work/m-p/352137#M87139</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2020-09-25T13:44:22Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Connection Security Won't Work</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-connection-security-won-t-work/m-p/352187#M87149</link>
      <description>&lt;P&gt;Hello TylerHay,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There are really no tricks...&lt;/P&gt;&lt;P&gt;Here's a working config I just did in my lab. It might give you an idea of what went wrong with your setup.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On the PA Firewall:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Create a CA root:&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Rievax_0-1601050933302.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/27939i573E2FCC63B32783/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Rievax_0-1601050933302.png" alt="Rievax_0-1601050933302.png" /&gt;&lt;/span&gt;&lt;P&gt;No need to enter any other information as this is to create a self signed cert later&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;Now, create the self signed certificate. Make sure you signed it with the CA we just created. Enter at least the valid IP in the attributes to make this certificate valid:&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Rievax_1-1601051133513.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/27940i318545CBC7585D33/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Rievax_1-1601051133513.png" alt="Rievax_1-1601051133513.png" /&gt;&lt;/span&gt;&lt;/LI&gt;&lt;LI&gt;You will end up with something similar:&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Rievax_2-1601051191317.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/27941i77D47DD3D5FBD98A/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Rievax_2-1601051191317.png" alt="Rievax_2-1601051191317.png" /&gt;&lt;/span&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;Now, select the self-signed certificate (PA-UID-Cert in this case) and export it with the private key:&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Rievax_4-1601051308004.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/27943iF729CDABA65D6F9A/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Rievax_4-1601051308004.png" alt="Rievax_4-1601051308004.png" /&gt;&lt;/span&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;Now, create a certificate profile with no other information than the CA root that has been created:&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Rievax_5-1601051424446.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/27944iC82ECB3D7DC20D4F/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Rievax_5-1601051424446.png" alt="Rievax_5-1601051424446.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;&lt;LI&gt;Assign this Certificate profile too the "Connection Security" tab:&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Rievax_6-1601051530439.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/27945iFF2815C7605E837B/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Rievax_6-1601051530439.png" alt="Rievax_6-1601051530439.png" /&gt;&lt;/span&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;You can now add the user ID agent configuration:&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Rievax_7-1601051658048.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/27946iBF4CF617E0FEDEF9/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Rievax_7-1601051658048.png" alt="Rievax_7-1601051658048.png" /&gt;&lt;/span&gt;&lt;/LI&gt;&lt;LI&gt;Commit the changes.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On the UserID server:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Add the certificate :&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Rievax_8-1601051838947.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/27947i79F20C28EAE3F766/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Rievax_8-1601051838947.png" alt="Rievax_8-1601051838947.png" /&gt;&lt;/span&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;Save and commit the changes...&lt;/LI&gt;&lt;LI&gt;Go to "User Identification". After a few seconds, it should change the status to connected:&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Rievax_9-1601051944044.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/27948i804A4D5D5FC5CB73/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Rievax_9-1601051944044.png" alt="Rievax_9-1601051944044.png" /&gt;&lt;/span&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;On the PA side, it says the same:&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Rievax_10-1601052001004.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/27949iC7EC63F3E2C07E03/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Rievax_10-1601052001004.png" alt="Rievax_10-1601052001004.png" /&gt;&lt;/span&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Hope that helps!&lt;/P&gt;&lt;P&gt;R.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Sep 2020 16:40:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-connection-security-won-t-work/m-p/352187#M87149</guid>
      <dc:creator>Rievax</dc:creator>
      <dc:date>2020-09-25T16:40:23Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Connection Security Won't Work</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-connection-security-won-t-work/m-p/352268#M87159</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;If this is mission critical I would say call TAC and get their assistance. While I have never set this up myself, I have setup other things and usually missed something simple, not saying you haven't gone over this a bunch of times.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Fri, 25 Sep 2020 20:08:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-connection-security-won-t-work/m-p/352268#M87159</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2020-09-25T20:08:59Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Connection Security Won't Work</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-connection-security-won-t-work/m-p/352287#M87163</link>
      <description>&lt;P&gt;Hi TylerHay,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I posted a full how-to earlier but it has never been published... There might be a delay or a bug somewhere in the forum...&lt;/P&gt;&lt;P&gt;Anyways, it should not be a issue.&lt;/P&gt;&lt;P&gt;Make sure the certificate you import in the client is fully recognized by the PA firewall (including the root CA that signed this certificate - the attached certificate profile should be linked to this root CA...). Regarding the SAN, I just added the IP address in the certificate. Worked well 1st time.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that helps... and maybe the full description I did this morning will be posted eventually.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;P&gt;X&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Sep 2020 20:56:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-connection-security-won-t-work/m-p/352287#M87163</guid>
      <dc:creator>Rievax</dc:creator>
      <dc:date>2020-09-25T20:56:54Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Connection Security Won't Work</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-connection-security-won-t-work/m-p/352339#M87169</link>
      <description>&lt;P&gt;@Retired Member,&lt;/P&gt;
&lt;P&gt;The example that&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/73975"&gt;@Rievax&lt;/a&gt;&amp;nbsp;wrote up is great and definitely works perfectly fine. The one thing that I would say is that if you have this certificate signed by an external CA, be sure that you actually have the full cert chain in the certificate profile. You may have to manually chain the certificates if it's signed by an intermediary to get things to work properly.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 26 Sep 2020 04:58:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-connection-security-won-t-work/m-p/352339#M87169</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-09-26T04:58:28Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Connection Security Won't Work</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-connection-security-won-t-work/m-p/413740#M93007</link>
      <description>&lt;P&gt;Hi Tylerhay To remove cert,&lt;/P&gt;&lt;P&gt;i had same issue and edited the UserIDAgentConfig.xml file in User-ID Agent directory, Remove the information between the server certificate tags in the XML file directly and restart the service. This removed the certificate form the user-id application and allowed my firewalls to connect.&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jun 2021 05:01:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-connection-security-won-t-work/m-p/413740#M93007</guid>
      <dc:creator>CraigMason</dc:creator>
      <dc:date>2021-06-17T05:01:39Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Connection Security Won't Work</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-connection-security-won-t-work/m-p/997292#M122470</link>
      <description>&lt;P&gt;&lt;A href="https://thedxt.ca/2024/10/palo-alto-user-id-and-terminal-server-agent-certificates/" target="_blank"&gt;https://thedxt.ca/2024/10/palo-alto-user-id-and-terminal-server-agent-certificates/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On November 18th, 2024, the certificates that the Palo Alto User-ID agent and the Palo Alto Terminal Server agent use to communicate with a Palo Alto firewall will expire, causing all communication to fail.&lt;/P&gt;
&lt;P&gt;Palo Alto Networks has made new versions of the User-ID and TS agents with updated certificates that will expire on January 1st, 2032.&lt;/P&gt;
&lt;P&gt;You may just need to update your User-ID Agent&lt;/P&gt;</description>
      <pubDate>Mon, 09 Dec 2024 21:40:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-connection-security-won-t-work/m-p/997292#M122470</guid>
      <dc:creator>M.Lampe</dc:creator>
      <dc:date>2024-12-09T21:40:33Z</dc:date>
    </item>
  </channel>
</rss>

