<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Certificate error on GP access in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/certificate-error-on-gp-access/m-p/353904#M87372</link>
    <description>&lt;P&gt;Dear Team,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am facing the issue certificate error while accessing the GP portal. below is the screenshot.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Jafar_Hussain_0-1601894358196.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/28083i7806A906A09C7554/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Jafar_Hussain_0-1601894358196.png" alt="Jafar_Hussain_0-1601894358196.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Below is the troubleshooting steps:-&lt;/P&gt;&lt;P&gt;Generated a new self-signed certificate and apply in SSL/TLS.&lt;/P&gt;&lt;P&gt;Same certificate export and configure in the machine as well as browser.&lt;/P&gt;&lt;P&gt;Can anyone help me on this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Clear the&lt;/P&gt;</description>
    <pubDate>Mon, 05 Oct 2020 10:42:20 GMT</pubDate>
    <dc:creator>Jafar_Hussain</dc:creator>
    <dc:date>2020-10-05T10:42:20Z</dc:date>
    <item>
      <title>Certificate error on GP access</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/certificate-error-on-gp-access/m-p/353904#M87372</link>
      <description>&lt;P&gt;Dear Team,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am facing the issue certificate error while accessing the GP portal. below is the screenshot.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Jafar_Hussain_0-1601894358196.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/28083i7806A906A09C7554/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Jafar_Hussain_0-1601894358196.png" alt="Jafar_Hussain_0-1601894358196.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Below is the troubleshooting steps:-&lt;/P&gt;&lt;P&gt;Generated a new self-signed certificate and apply in SSL/TLS.&lt;/P&gt;&lt;P&gt;Same certificate export and configure in the machine as well as browser.&lt;/P&gt;&lt;P&gt;Can anyone help me on this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Clear the&lt;/P&gt;</description>
      <pubDate>Mon, 05 Oct 2020 10:42:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/certificate-error-on-gp-access/m-p/353904#M87372</guid>
      <dc:creator>Jafar_Hussain</dc:creator>
      <dc:date>2020-10-05T10:42:20Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate error on GP access</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/certificate-error-on-gp-access/m-p/353921#M87377</link>
      <description>&lt;P&gt;You should generate a CA certificate and then create a new (second) certitfate signed by this CA that you can use for the portal/gateway.&lt;/P&gt;&lt;P&gt;Then export the CA certificate and import it into the trusted sroot signing certificates store of the user&lt;/P&gt;</description>
      <pubDate>Mon, 05 Oct 2020 11:27:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/certificate-error-on-gp-access/m-p/353921#M87377</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2020-10-05T11:27:03Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate error on GP access</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/certificate-error-on-gp-access/m-p/353922#M87378</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The same i have tried but still the issue is the same.&lt;/P&gt;</description>
      <pubDate>Mon, 05 Oct 2020 11:29:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/certificate-error-on-gp-access/m-p/353922#M87378</guid>
      <dc:creator>Jafar_Hussain</dc:creator>
      <dc:date>2020-10-05T11:29:44Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate error on GP access</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/certificate-error-on-gp-access/m-p/353924#M87379</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/124013"&gt;@Jafar_Hussain&lt;/a&gt;&amp;nbsp; ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please check if your SSL Certificate CN and portal URL/IP are matching? It should match.&lt;/P&gt;</description>
      <pubDate>Mon, 05 Oct 2020 12:11:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/certificate-error-on-gp-access/m-p/353924#M87379</guid>
      <dc:creator>SutareMayur</dc:creator>
      <dc:date>2020-10-05T12:11:25Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate error on GP access</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/certificate-error-on-gp-access/m-p/353925#M87380</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/124013"&gt;@Jafar_Hussain&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You need to make sure that when you create certificate then certificate attributes has&amp;nbsp; hostname&amp;nbsp; field filled with FQDN.&lt;/P&gt;
&lt;P&gt;As Chrome browser gives untrusted warning if hostname is not their in Certificates attribute.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Mon, 05 Oct 2020 12:12:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/certificate-error-on-gp-access/m-p/353925#M87380</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2020-10-05T12:12:38Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate error on GP access</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/certificate-error-on-gp-access/m-p/353968#M87383</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/132521"&gt;@SutareMayur&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have configured the URL for portal access it is matched.&lt;/P&gt;</description>
      <pubDate>Mon, 05 Oct 2020 12:50:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/certificate-error-on-gp-access/m-p/353968#M87383</guid>
      <dc:creator>Jafar_Hussain</dc:creator>
      <dc:date>2020-10-05T12:50:49Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate error on GP access</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/certificate-error-on-gp-access/m-p/353983#M87384</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/75039"&gt;@MP18&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I want to highlight some points here.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have observed once i open the portal in edge and internet explorer it is working fine only for some machine.&lt;/P&gt;&lt;P&gt;When i open portal in chrome and firefox then i am getting error.&lt;/P&gt;&lt;P&gt;When i checked the certificate some time is showing certificate is OK.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When i click on root CA it is shwoing below error:-&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Jafar_Hussain_0-1601902524939.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/28088iD9823D78C6E1EED6/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Jafar_Hussain_0-1601902524939.png" alt="Jafar_Hussain_0-1601902524939.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Oct 2020 12:56:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/certificate-error-on-gp-access/m-p/353983#M87384</guid>
      <dc:creator>Jafar_Hussain</dc:creator>
      <dc:date>2020-10-05T12:56:04Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate error on GP access</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/certificate-error-on-gp-access/m-p/354036#M87387</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/124013"&gt;@Jafar_Hussain&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;So it would appear that you have some clients that are successfully getting the root CA installed via whatever method you've chosen, but then other machines aren't. You need to look into why some of the machines don't trust the root CA certificate you are using and address that issue.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Oct 2020 15:18:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/certificate-error-on-gp-access/m-p/354036#M87387</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-10-05T15:18:24Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate error on GP access</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/certificate-error-on-gp-access/m-p/354228#M87410</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/124013"&gt;@Jafar_Hussain&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;correctly pointed out it seems that the problematic machines doesn't have the root CA properly installed. Either it was not installed at all, or it was not installed under "Trusted Root Certificates". It is common mistake when the root CA was manually installed. During the cert installation wizard you can manually select under which section to install the certificate or let the wizard choose automatically for you. However for security reasons windows will never automatically put cert into trusted root certs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also have in mind that Chrome, Edge and IE are using Windows certificate store, but&amp;nbsp;Firefox is using separate certificate store. So it is possible that all other browsers to work properly, but to receive cert warning from Firefox. In that case you need to install the root CA in Firefox cert store as well.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Oct 2020 07:18:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/certificate-error-on-gp-access/m-p/354228#M87410</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2020-10-06T07:18:54Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate error on GP access</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/certificate-error-on-gp-access/m-p/356975#M87709</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/70130"&gt;@aleksandar.astardzhiev&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your email. As i explain i have configure only root CA with common name IP address and the same certificate installed in client machine trusted root certificate store.&lt;/P&gt;&lt;P&gt;However again i am getting the warning. the same i have checked with child certificate but not able to resolve my issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As per my understanding, this is a self-sign certificate from the firewall that is sometimes not trusted by the client machine so i think i need to generate CSR and sign by 3rd party which is already trusted by the client machine. i will import this certificate in firewall. might be it will fix the issue.&lt;/P&gt;&lt;P&gt;Share your openion.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 18 Oct 2020 09:31:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/certificate-error-on-gp-access/m-p/356975#M87709</guid>
      <dc:creator>Jafar_Hussain</dc:creator>
      <dc:date>2020-10-18T09:31:25Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate error on GP access</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/certificate-error-on-gp-access/m-p/357268#M87752</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/124013"&gt;@Jafar_Hussain&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Using certificated signed by public CA is probably the way to go (if you don't have internal PKI in your environment). So CSR signed by public CA will definitely solve your certificate warnings.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However the self-signed certificate should work, but the devil is in the details. I just noticed that the warning message&lt;SPAN&gt;&amp;nbsp;from your original post is that the certificate common name is invalid, while you were looking at the CA (if the problem was with browser not trusting the self-signed CA, the warning would be "UNKNOWN_ISSUER". So it seem you probably have not one, but multiple issues.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;There is no such think as "&lt;SPAN&gt;self-sign certificate from the firewall that is sometimes not trusted by the client machine" - it is either you have done something wrong, or you don't do something. If you still keen on understanding what is actually the problem:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="inherit"&gt;1. Confirm your self-signed CA is installed in the trusted rot certificate &lt;/FONT&gt;authorities&lt;FONT face="inherit"&gt;&amp;nbsp;and certificate is listed as trusted when you view cert details&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="inherit"&gt;2. Confirm your both certs (GP and CA) are both with valid dates (start date is in the past and end date is in the future)&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="inherit"&gt;3. When opening the GP portal for address use what you have put in the certificate Common Name (CN). (common name invalid error could be caused by the fact that you are opening the page using the ip address in the browser, but the certificate to be configured with FQDN)&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Oct 2020 21:10:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/certificate-error-on-gp-access/m-p/357268#M87752</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2020-10-19T21:10:44Z</dc:date>
    </item>
  </channel>
</rss>

