<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Result: Failed to validate server certificate for endpoint api.paloaltonetworks.com in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/result-failed-to-validate-server-certificate-for-endpoint-api/m-p/414247#M93087</link>
    <description>&lt;P&gt;&lt;SPAN&gt;issue1:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I am having issues with getting Panorama and firewalls connected up to datalake. I opened a case and i am told it can't connect to api.paloaltonetworks.com. I have pcap that says otherwise. There is no ssl decryption in between. Its frustrating when you spend serious amount of money on this storage and it doesn't work.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;issue2:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I am have a hard time find nice straight forward instructions on how to get panorama managed firewalls along with panorama setup with datalake. The instructions are all over the place. If someone has instructions they followed, preferably including the cert generation from the cloud services that would be really helpful.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 20 Jun 2021 01:38:06 GMT</pubDate>
    <dc:creator>Johndbabio1</dc:creator>
    <dc:date>2021-06-20T01:38:06Z</dc:date>
    <item>
      <title>Result: Failed to validate server certificate for endpoint api.paloaltonetworks.com</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/result-failed-to-validate-server-certificate-for-endpoint-api/m-p/414247#M93087</link>
      <description>&lt;P&gt;&lt;SPAN&gt;issue1:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I am having issues with getting Panorama and firewalls connected up to datalake. I opened a case and i am told it can't connect to api.paloaltonetworks.com. I have pcap that says otherwise. There is no ssl decryption in between. Its frustrating when you spend serious amount of money on this storage and it doesn't work.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;issue2:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I am have a hard time find nice straight forward instructions on how to get panorama managed firewalls along with panorama setup with datalake. The instructions are all over the place. If someone has instructions they followed, preferably including the cert generation from the cloud services that would be really helpful.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 20 Jun 2021 01:38:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/result-failed-to-validate-server-certificate-for-endpoint-api/m-p/414247#M93087</guid>
      <dc:creator>Johndbabio1</dc:creator>
      <dc:date>2021-06-20T01:38:06Z</dc:date>
    </item>
    <item>
      <title>Re: Result: Failed to validate server certificate for endpoint api.paloaltonetworks.com</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/result-failed-to-validate-server-certificate-for-endpoint-api/m-p/414248#M93088</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/140173"&gt;@Johndbabio1&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Are you allowing your firewalls to communicate with ocsp.paloaltonetworks.com and crl.paloaltonetworks.com? The error your getting is simply stating that they can't validate the certificate of api.paloaltonetworks.com, not that it's not able to reach api.paloaltonetworks.com. Take a look at the required &lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-data-lake/cortex-data-lake-getting-started/get-started-with-cortex-data-lake/ports-and-fqdns.html#id17B6L07J09S" target="_blank" rel="noopener"&gt;communication&lt;/A&gt;&amp;nbsp;document and make sure you can actually communicate to all of the required FQDNs and that you're actually allowing all of the necessary traffic to pass.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What documentation are you attempting to follow? The &lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-data-lake/cortex-data-lake-getting-started/get-started-with-cortex-data-lake.html" target="_blank" rel="noopener"&gt;Getting Started&lt;/A&gt;&amp;nbsp;documentation will walk you through how you go about setting this up in a step by step fashion.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 20 Jun 2021 03:26:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/result-failed-to-validate-server-certificate-for-endpoint-api/m-p/414248#M93088</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2021-06-20T03:26:25Z</dc:date>
    </item>
    <item>
      <title>Re: Result: Failed to validate server certificate for endpoint api.paloaltonetworks.com</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/result-failed-to-validate-server-certificate-for-endpoint-api/m-p/414249#M93089</link>
      <description>&lt;P&gt;tail follow yes mp-log lcaas_agent.log&lt;/P&gt;&lt;P&gt;2021-06-19 23:16:59,171 lcaas_agent INFO source interface: src route sysd str: cfg.net.s0.srcif&lt;BR /&gt;2021-06-19 23:16:59,171 lcaas_agent INFO source interface: src_table: {'refresh': 300}&lt;BR /&gt;2021-06-19 23:16:59,171 lcaas_agent INFO Server not passed in. Picking up from cfg.lcaas-orch-server-domain sysd node&lt;BR /&gt;2021-06-19 23:16:59,179 lcaas_agent INFO LCaas server port not passed in. Picking up from cfg.lcaas-orch-server-port sysd node&lt;BR /&gt;2021-06-19 23:17:59,239 lcaas_agent ERROR Failed to fetch LCaaS server cert - retrying....&lt;BR /&gt;2021-06-19 23:19:01,270 lcaas_agent ERROR Failed to fetch LCaaS server cert - retrying....&lt;BR /&gt;2021-06-19 23:20:03,296 lcaas_agent ERROR Failed to fetch LCaaS server cert - retrying....&lt;BR /&gt;2021-06-19 23:21:05,322 lcaas_agent ERROR Failed to fetch LCaaS server cert - retrying....&lt;BR /&gt;2021-06-19 23:22:07,347 lcaas_agent ERROR Failed to fetch LCaaS server cert for validation check after 5 retries&lt;BR /&gt;2021-06-19 23:22:07,348 lcaas_agent ERROR Failed to validate server certificate for endpoint api.paloaltonetworks.com&lt;/P&gt;</description>
      <pubDate>Sun, 20 Jun 2021 04:47:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/result-failed-to-validate-server-certificate-for-endpoint-api/m-p/414249#M93089</guid>
      <dc:creator>Johndbabio1</dc:creator>
      <dc:date>2021-06-20T04:47:02Z</dc:date>
    </item>
    <item>
      <title>Re: Result: Failed to validate server certificate for endpoint api.paloaltonetworks.com</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/result-failed-to-validate-server-certificate-for-endpoint-api/m-p/485335#M104517</link>
      <description>&lt;P&gt;Did you find a solution to this one?&lt;/P&gt;</description>
      <pubDate>Fri, 06 May 2022 05:08:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/result-failed-to-validate-server-certificate-for-endpoint-api/m-p/485335#M104517</guid>
      <dc:creator>oadrian</dc:creator>
      <dc:date>2022-05-06T05:08:17Z</dc:date>
    </item>
    <item>
      <title>Re: Result: Failed to validate server certificate for endpoint api.paloaltonetworks.com</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/result-failed-to-validate-server-certificate-for-endpoint-api/m-p/514895#M106854</link>
      <description>&lt;P&gt;Engineers will find solutions for everything else not the LCaaS errors. i think we must accept that not even the programmers at Palo Alto can fix this.&lt;/P&gt;
&lt;P&gt;Why is it difficult for the solution to this problem to be posted?&lt;/P&gt;</description>
      <pubDate>Wed, 14 Sep 2022 22:30:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/result-failed-to-validate-server-certificate-for-endpoint-api/m-p/514895#M106854</guid>
      <dc:creator>Silas1</dc:creator>
      <dc:date>2022-09-14T22:30:45Z</dc:date>
    </item>
    <item>
      <title>Re: Result: Failed to validate server certificate for endpoint api.paloaltonetworks.com</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/result-failed-to-validate-server-certificate-for-endpoint-api/m-p/526450#M108803</link>
      <description>&lt;P data-unlink="true"&gt;I know this is a late reply, but have you checked this doc?&amp;nbsp;The one command: &lt;EM&gt;&lt;STRONG&gt;request logging-service-forwarding customerinfo [show|fetch]&lt;/STRONG&gt; &lt;/EM&gt;was pretty helpful - error message showed me I was getting SSL handshake rejected.&lt;/P&gt;
&lt;P data-unlink="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-unlink="true"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PMXKCA4&lt;/P&gt;
&lt;P data-unlink="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-unlink="true"&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Jan 2023 04:45:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/result-failed-to-validate-server-certificate-for-endpoint-api/m-p/526450#M108803</guid>
      <dc:creator>chmotley</dc:creator>
      <dc:date>2023-01-10T04:45:17Z</dc:date>
    </item>
    <item>
      <title>Re: Result: Failed to validate server certificate for endpoint api.paloaltonetworks.com</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/result-failed-to-validate-server-certificate-for-endpoint-api/m-p/1226898#M124046</link>
      <description>&lt;P&gt;Bump for an old thread, however I found more relevant information. &lt;BR /&gt;&lt;BR /&gt;1.) 3rd Gen firewalls (PA-800s, PA-3200s, PA-5200s) did NOT come with the Device Certificate. You have to fetch it using the OTP method (from Device Certificate in Support Portal). "&lt;STRONG&gt;request certificate fetch otp ##############################&lt;/STRONG&gt;"&lt;BR /&gt;2.) Run the "&lt;SPAN&gt;&lt;STRONG&gt;request logging-service-forwarding status"&amp;nbsp;&lt;/STRONG&gt;&lt;/SPAN&gt;If you are missing the Logging Service Certificate (see screenshot), then run&amp;nbsp;&lt;SPAN&gt;"&lt;STRONG&gt;request logging-service-forwarding customerinfo fetch&lt;/STRONG&gt;"&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;3.)&amp;nbsp;Port TCP/444 has to be open for the firewall to fetch server certificate when doing the "&lt;STRONG&gt;request logging-service-forwarding customerinfo fetch&lt;/STRONG&gt;" command (see screenshot)&lt;BR /&gt;&lt;BR /&gt;I found this helpful trying to get IoT Security working on a PA-3220. We were not seeing any devices make it to the IoT dashboard until the Device Certificate and the Logging Server Certificate was fetched successfully.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 18 Apr 2025 15:01:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/result-failed-to-validate-server-certificate-for-endpoint-api/m-p/1226898#M124046</guid>
      <dc:creator>apiche1</dc:creator>
      <dc:date>2025-04-18T15:01:37Z</dc:date>
    </item>
    <item>
      <title>Re: Result: Failed to validate server certificate for endpoint api.paloaltonetworks.com</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/result-failed-to-validate-server-certificate-for-endpoint-api/m-p/1226972#M124054</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27041"&gt;@apiche1&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;Bump for an old thread, however I found more relevant information. &lt;BR /&gt;&lt;BR /&gt;1.) 3rd Gen firewalls (PA-800s, PA-3200s, PA-5200s) did NOT come with the Device Certificate. You have to fetch it using the OTP method (from Device Certificate in Support Portal). "&lt;STRONG&gt;request certificate fetch otp ##############################&lt;/STRONG&gt;"&lt;BR /&gt;2.) Run the "&lt;SPAN&gt;&lt;STRONG&gt;request logging-service-forwarding status"&amp;nbsp;&lt;/STRONG&gt;&lt;/SPAN&gt;If you are missing the Logging Service Certificate (see screenshot), then run&amp;nbsp;&lt;SPAN&gt;"&lt;STRONG&gt;request logging-service-forwarding customerinfo fetch&lt;/STRONG&gt;"&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;3.)&amp;nbsp;Port TCP/444 has to be open for the firewall to fetch server certificate when doing the "&lt;STRONG&gt;request logging-service-forwarding customerinfo fetch&lt;/STRONG&gt;" command (see screenshot)&lt;BR /&gt;&lt;BR /&gt;I found this helpful trying to get IoT Security working on a PA-3220. We were not seeing any devices make it to the IoT dashboard until the Device Certificate and the Logging Server Certificate was fetched successfully.&lt;/SPAN&gt;&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;GL, trying to stand-up IoT.&amp;nbsp; I've been evaluating it at my company for ~6ish months.&amp;nbsp; We did finally get it added to our ELA.&amp;nbsp; It seems like a great feature, but still has a lot of quirks we're working through with them.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Apr 2025 13:41:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/result-failed-to-validate-server-certificate-for-endpoint-api/m-p/1226972#M124054</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2025-04-21T13:41:09Z</dc:date>
    </item>
  </channel>
</rss>

