<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Failed to renew device certificate in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/failed-to-renew-device-certificate/m-p/391961#M90821</link>
    <description>&lt;P&gt;I have exactly same problem on many devices in different configurations. Nothing is blocked, DNS resolves OK.&lt;/P&gt;</description>
    <pubDate>Thu, 18 Mar 2021 10:12:37 GMT</pubDate>
    <dc:creator>KoShy</dc:creator>
    <dc:date>2021-03-18T10:12:37Z</dc:date>
    <item>
      <title>Failed to renew device certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/failed-to-renew-device-certificate/m-p/391693#M90801</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the device certificate is going to expire end of march.&lt;/P&gt;&lt;P&gt;My PA trys to renew it and comes up with the following error:&lt;/P&gt;&lt;P&gt;&lt;FONT color="#0000FF"&gt;Failed to renew device certificate.Failed to send request to CSP server.Error: No OCSP response received(dest =&amp;gt; 35.238.43.180)&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;I have no telemetry enabled. &lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;Just activated the certificate with OTP on&amp;nbsp;2020/12/29 after upgrading to PanOS 9.1.7.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;Now it´s the first try of my PA to renew it.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;The only thing i found relates to&amp;nbsp;&lt;/FONT&gt;&lt;FONT color="#000000"&gt;PanOS 9.1.8 wich seems to fix another error with device certificate:&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#339966"&gt;&lt;SPAN&gt;Fixed an issue where the firewall returned the following error message when attempting to request a device certificate using a one-time password (OTP):&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;DIV&gt;&lt;FONT color="#339966"&gt;invalid ocsp response sig-alg&lt;/FONT&gt;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Any ideas where to look for?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;TIA&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Mar 2021 11:37:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/failed-to-renew-device-certificate/m-p/391693#M90801</guid>
      <dc:creator>kbe</dc:creator>
      <dc:date>2021-03-17T11:37:43Z</dc:date>
    </item>
    <item>
      <title>Re: Failed to renew device certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/failed-to-renew-device-certificate/m-p/391728#M90803</link>
      <description>&lt;P&gt;Have you checked your conectivity to certificate.paloaltonetworks.com?&lt;/P&gt;&lt;P&gt;I've just installed a new certificate for a Panorama, worked ok.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Mar 2021 14:38:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/failed-to-renew-device-certificate/m-p/391728#M90803</guid>
      <dc:creator>LGCoelho</dc:creator>
      <dc:date>2021-03-17T14:38:02Z</dc:date>
    </item>
    <item>
      <title>Re: Failed to renew device certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/failed-to-renew-device-certificate/m-p/391729#M90804</link>
      <description>&lt;P&gt;Last traffic to&amp;nbsp;( url eq 'certificate.paloaltonetworks.com' ) was on 12/29 when the certificate was installed the first time.&lt;/P&gt;&lt;P&gt;No block / deny or other traffic to this url or ip since then.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Seems the PA ist trying to connect to&amp;nbsp;35.238.43.180 and there is no deny for it.&lt;/P&gt;&lt;P&gt;The mgmt interface has an allow rule but the renew is not working.&lt;/P&gt;&lt;P&gt;This was the traffic from the last 2 days to&amp;nbsp;&lt;A href="http://certificatetrusted.paloaltonetworks.com/" target="_blank" rel="noopener"&gt;https://certificatetrusted.paloaltonetworks.com/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="kbe_0-1615993074517.png" style="width: 2024px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/30398iBB596110C19A6670/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="kbe_0-1615993074517.png" alt="kbe_0-1615993074517.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The Root CA&amp;nbsp;Palo Alto Networks Inc.-Root-CA G1 that signed the cert for&amp;nbsp;&lt;A href="http://certificatetrusted.paloaltonetworks.com/" target="_blank" rel="noopener"&gt;certificatetrusted.paloaltonetworks.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;is not trusted if you browse to the url. But that should not be the problem.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Mar 2021 15:04:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/failed-to-renew-device-certificate/m-p/391729#M90804</guid>
      <dc:creator>kbe</dc:creator>
      <dc:date>2021-03-17T15:04:48Z</dc:date>
    </item>
    <item>
      <title>Re: Failed to renew device certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/failed-to-renew-device-certificate/m-p/391961#M90821</link>
      <description>&lt;P&gt;I have exactly same problem on many devices in different configurations. Nothing is blocked, DNS resolves OK.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Mar 2021 10:12:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/failed-to-renew-device-certificate/m-p/391961#M90821</guid>
      <dc:creator>KoShy</dc:creator>
      <dc:date>2021-03-18T10:12:37Z</dc:date>
    </item>
    <item>
      <title>Re: Failed to renew device certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/failed-to-renew-device-certificate/m-p/391980#M90824</link>
      <description>&lt;P&gt;Today i requested a new OTP and choose to Get Certificate on the PA which revokes the actual cert and requests a new one.&lt;/P&gt;&lt;P&gt;The new Cert request finished without problems.&lt;/P&gt;&lt;P&gt;Now i wait til 16-06 to see if the next renew will work automatically or if the problem comes up again.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Mar 2021 11:15:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/failed-to-renew-device-certificate/m-p/391980#M90824</guid>
      <dc:creator>kbe</dc:creator>
      <dc:date>2021-03-18T11:15:35Z</dc:date>
    </item>
    <item>
      <title>Re: Failed to renew device certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/failed-to-renew-device-certificate/m-p/392011#M90831</link>
      <description>&lt;P&gt;same problem here, i also renew the certificates using one-time password.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Mar 2021 12:26:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/failed-to-renew-device-certificate/m-p/392011#M90831</guid>
      <dc:creator>Administrator.Klina</dc:creator>
      <dc:date>2021-03-18T12:26:40Z</dc:date>
    </item>
    <item>
      <title>Re: Failed to renew device certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/failed-to-renew-device-certificate/m-p/456339#M101703</link>
      <description>&lt;P&gt;allow app 'paloalto-shared-services' to mgmt console rule, your most likely getting blocked. I was&lt;/P&gt;</description>
      <pubDate>Sun, 02 Jan 2022 16:37:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/failed-to-renew-device-certificate/m-p/456339#M101703</guid>
      <dc:creator>Housing1</dc:creator>
      <dc:date>2022-01-02T16:37:08Z</dc:date>
    </item>
    <item>
      <title>Re: Failed to renew device certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/failed-to-renew-device-certificate/m-p/466207#M102666</link>
      <description>&lt;P&gt;Thanks, this is what helped me with getting the device cert installed on a couple of new firewalls.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Feb 2022 14:25:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/failed-to-renew-device-certificate/m-p/466207#M102666</guid>
      <dc:creator>Jaysta</dc:creator>
      <dc:date>2022-02-16T14:25:27Z</dc:date>
    </item>
    <item>
      <title>Re: Failed to renew device certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/failed-to-renew-device-certificate/m-p/515635#M107087</link>
      <description>&lt;P&gt;My cert expires in 31 days and I see no way to renew it.&amp;nbsp; I don't have a way to track the firewalls attempts since this happens via the mgmt interface.&amp;nbsp; All I see is the graphic below and it doesn't look like it's tried to connect to the server since the cert was issued.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How do I renew it?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Jason_Lieberman_0-1663785812418.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/44069i63CFDC378EA75254/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Jason_Lieberman_0-1663785812418.png" alt="Jason_Lieberman_0-1663785812418.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Sep 2022 18:44:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/failed-to-renew-device-certificate/m-p/515635#M107087</guid>
      <dc:creator>Jason_Lieberman</dc:creator>
      <dc:date>2022-09-21T18:44:36Z</dc:date>
    </item>
    <item>
      <title>Re: Failed to renew device certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/failed-to-renew-device-certificate/m-p/517739#M107428</link>
      <description>&lt;P&gt;The Palo normally fetches a new cert by itself before the other expires. There should be no need to get it manually under normal conditions.&lt;/P&gt;
&lt;P&gt;I see a link with get certificate wich i used the last time (see my older posting from&amp;nbsp;&lt;SPAN&gt;2021-03-18).&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="kbe_0-1665646592424.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/44658iDE2E9B91E73165AD/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="kbe_0-1665646592424.png" alt="kbe_0-1665646592424.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Oct 2022 07:37:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/failed-to-renew-device-certificate/m-p/517739#M107428</guid>
      <dc:creator>kbe</dc:creator>
      <dc:date>2022-10-13T07:37:22Z</dc:date>
    </item>
    <item>
      <title>Re: Failed to renew device certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/failed-to-renew-device-certificate/m-p/517798#M107436</link>
      <description>&lt;P&gt;I have no such link.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Jason_Lieberman_0-1665673082896.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/44664iBFB9FACF490EE0D5/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Jason_Lieberman_0-1665673082896.png" alt="Jason_Lieberman_0-1665673082896.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Oct 2022 14:58:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/failed-to-renew-device-certificate/m-p/517798#M107436</guid>
      <dc:creator>Jason_Lieberman</dc:creator>
      <dc:date>2022-10-13T14:58:11Z</dc:date>
    </item>
    <item>
      <title>Re: Failed to renew device certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/failed-to-renew-device-certificate/m-p/518083#M107482</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/182396"&gt;@Jason_Lieberman&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There's a way to fetch it using the CLI:&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;admin@PA-LAB&amp;gt; request certificate fetch otp &amp;lt;value&amp;gt;&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;replace &amp;lt;value&amp;gt; with the OTP generated on the support portal.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps,&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;
&lt;DIV id="ConnectiveDocSignExtentionInstalled" data-extension-version="1.0.4"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Mon, 17 Oct 2022 10:12:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/failed-to-renew-device-certificate/m-p/518083#M107482</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2022-10-17T10:12:55Z</dc:date>
    </item>
    <item>
      <title>Re: Failed to renew device certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/failed-to-renew-device-certificate/m-p/518094#M107486</link>
      <description>&lt;P&gt;While the '&lt;SPAN&gt;request certificate fetch otp' is not a valid command on my 440.&amp;nbsp; 'request certificate fetch' is.&amp;nbsp; When I ran that is managed to get a new cert.&amp;nbsp; I'm shocked!&amp;nbsp; It's been failing for a few weeks now and TAC is stumped as to why.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thank you for that.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Oct 2022 13:30:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/failed-to-renew-device-certificate/m-p/518094#M107486</guid>
      <dc:creator>Jason_Lieberman</dc:creator>
      <dc:date>2022-10-17T13:30:13Z</dc:date>
    </item>
    <item>
      <title>Re: Failed to renew device certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/failed-to-renew-device-certificate/m-p/520901#M107973</link>
      <description>&lt;P&gt;Try the solution here on the 440 - it works luckily :&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000004NlxCAE" target="_blank" rel="nofollow noopener noreferrer"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000004NlxCAE&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Nov 2022 12:09:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/failed-to-renew-device-certificate/m-p/520901#M107973</guid>
      <dc:creator>niavasha</dc:creator>
      <dc:date>2022-11-10T12:09:51Z</dc:date>
    </item>
    <item>
      <title>Re: Failed to renew device certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/failed-to-renew-device-certificate/m-p/520902#M107974</link>
      <description>&lt;P&gt;Then ssh in and try simply:&lt;/P&gt;
&lt;PRE&gt; request certificate fetch&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Nov 2022 12:11:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/failed-to-renew-device-certificate/m-p/520902#M107974</guid>
      <dc:creator>niavasha</dc:creator>
      <dc:date>2022-11-10T12:11:23Z</dc:date>
    </item>
    <item>
      <title>Re: Failed to renew device certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/failed-to-renew-device-certificate/m-p/536538#M110223</link>
      <description>&lt;P&gt;PA-5450 PAN-OS 10.2.3-h4 憑證已經過期 無法自動更新&lt;BR /&gt;我嘗試你的Cli，它可以運作，憑證更新成功了~ Thank you&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JoeCheng_1-1679892204122.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/49032i28266C7C340E6AF5/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="JoeCheng_1-1679892204122.png" alt="JoeCheng_1-1679892204122.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JoeCheng_0-1679892170381.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/49031iBC90CFE15438B0A8/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="JoeCheng_0-1679892170381.png" alt="JoeCheng_0-1679892170381.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Mar 2023 04:43:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/failed-to-renew-device-certificate/m-p/536538#M110223</guid>
      <dc:creator>JoeCheng</dc:creator>
      <dc:date>2023-03-27T04:43:30Z</dc:date>
    </item>
  </channel>
</rss>

