<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Certificate Validation not working in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/certificate-validation-not-working/m-p/400368#M91602</link>
    <description>&lt;P&gt;There are many posts for such issues. I think that that the SSL certfificate you added in the certficate profile is intermidiate certficate and you also need to download, import and add to the certficate prfile the root CA certficate of the root CA provider for Hydrant. Read the link below to see how people solved this issue:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/general-topics/dyndns-client-on-panos-9-0/m-p/252050" target="_blank"&gt;https://live.paloaltonetworks.com/t5/general-topics/dyndns-client-on-panos-9-0/m-p/252050&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 20 Apr 2021 05:47:20 GMT</pubDate>
    <dc:creator>nikoolayy1</dc:creator>
    <dc:date>2021-04-20T05:47:20Z</dc:date>
    <item>
      <title>Certificate Validation not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/certificate-validation-not-working/m-p/399854#M91582</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;hope you are doing well!&lt;/P&gt;&lt;P&gt;I've a little probelm with the certificate validation.&lt;/P&gt;&lt;P&gt;I've changed the DDNS provider to a custom one bit certifiate validation dows not work.&lt;/P&gt;&lt;P&gt;PAN OS: 10.0.5&lt;/P&gt;&lt;P&gt;First what I've done on CLI:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;set network interface ethernet ethernet1/1 layer3 ddns-config ddns-vendor-config dyn-api-host value updates.dnsomatic.com
set network interface ethernet ethernet1/1 layer3 ddns-config ddns-vendor-config dyn-baseuri value /nic/update
set network interface ethernet ethernet1/1 layer3 ddns-config ddns-vendor-config dyn-username value username
set network interface ethernet ethernet1/1 layer3 ddns-config ddns-vendor-config dyn-password value password&lt;/LI-CODE&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Image 4.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/32018i2A5BB8071D98D908/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Image 4.png" alt="Image 4.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My Certificate Profile looks like this:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Image 5.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/32019i9C4DAC63FAE31084/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Image 5.png" alt="Image 5.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And the&amp;nbsp; certificate for Hydrant:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Image 3.png" style="width: 598px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/32020i8F268524DF2962C4/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Image 3.png" alt="Image 3.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;As my opinion it should work but I got the following error:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Image 2.png" style="width: 742px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/32023i7F1CDDFC5FEB9ACF/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Image 2.png" alt="Image 2.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And the pcap:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Image 1.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/32022iFF0977C683D2447E/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Image 1.png" alt="Image 1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;The server send the right certificate but the Palo will not verify it.&lt;/P&gt;&lt;P&gt;Any hints?&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Sören&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Apr 2021 12:05:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/certificate-validation-not-working/m-p/399854#M91582</guid>
      <dc:creator>SoerenMindorf</dc:creator>
      <dc:date>2021-04-19T12:05:02Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate Validation not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/certificate-validation-not-working/m-p/400368#M91602</link>
      <description>&lt;P&gt;There are many posts for such issues. I think that that the SSL certfificate you added in the certficate profile is intermidiate certficate and you also need to download, import and add to the certficate prfile the root CA certficate of the root CA provider for Hydrant. Read the link below to see how people solved this issue:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/general-topics/dyndns-client-on-panos-9-0/m-p/252050" target="_blank"&gt;https://live.paloaltonetworks.com/t5/general-topics/dyndns-client-on-panos-9-0/m-p/252050&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Apr 2021 05:47:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/certificate-validation-not-working/m-p/400368#M91602</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2021-04-20T05:47:20Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate Validation not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/certificate-validation-not-working/m-p/400422#M91604</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/153031"&gt;@nikoolayy1&lt;/a&gt;&amp;nbsp;you are right, but I've done it already without success.&lt;/P&gt;&lt;P&gt;Today I've tested again:&lt;/P&gt;&lt;P&gt;I used the ROOT-CA too, the status of ddns was only "initalizing" and didn't change.&lt;/P&gt;&lt;P&gt;I've restarted the dns-proxy with&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;gt; debug software restart process dnsproxy&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now it is working.&lt;/P&gt;&lt;P&gt;The process restart did it.&lt;/P&gt;</description>
      <pubDate>Tue, 20 Apr 2021 10:32:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/certificate-validation-not-working/m-p/400422#M91604</guid>
      <dc:creator>SoerenMindorf</dc:creator>
      <dc:date>2021-04-20T10:32:31Z</dc:date>
    </item>
  </channel>
</rss>

