Created new certificate for decrypt, now I can't commit because of global protect error

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Created new certificate for decrypt, now I can't commit because of global protect error

L0 Member

Hello everyone,

 

I created a new certificate for SSL proxy and now for some reason I cannot commit. The error I get is "error applying transform globalprotect-pre-transform.xsl to config tree", AFAIK there was/is a completely different certificate for global protect connections.

Does anyone have a clue where I should start to search for the problem?

2 REPLIES 2

Cyber Elite
Cyber Elite

Do you recieve the error if you remove the new certificate? In essence have you narrowed it down to the actual cert and not an error that actually happened with the last commit before you tried to add the new cert into the config? 

Hi, thank you for your response.

I Rolled back to the current running configuration, and if I try to validate without any changes done I get the same error, "error applying transform globalprotect-pre-transform.xsl to config tree ( module: device)"

Additionally I get an error about certificate chain for the current ssl-proxy certificate in use, if I up the rootCA cert to the device and I get rid of this error but the first error still stands. 

2 things I find kinda ridiculous about this, error when trying to commit running-configuration without any changes and how uninformative that globalprotect error is..

Though I just found out that the device has support left so I'll pass this problem to palo alto support when I have time.

  • 1673 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!