- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
08-22-2022 12:16 PM
Hi Everybody,
I have 4 firewalls grouped into 2 HA pairs. The first pair had certificates which expired on August 18 and have failed to be renewed. The last fetched message says "Failed to renew device certificate. Invalid request. Authentication failed". I tried going through the OTP process to redeploy the certificate but under Device > Setup > Management > Device Certificate the "Get Certificate" button is no longer there. I also cannot deploy through Panorama as the devices are no longer connected (which I believe is due to the failed certificate request.
The second pair of firewalls has certificates which are expiring in a couple of days. These also have failed to renew the certificates citing the same errors.
Which authentication is failing here? I'm really not sure where to go from here to fix things. Any ideas?
Thanks for any help!
08-23-2022 10:39 AM
I've found the issue. I ran across the KB article here: https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000004NlxCAE
Changing the MTU to 1374 fixed the issue for me.
04-17-2023 08:54 AM
I tried changing the mgmt int MTU to 1374 and committed, but can't tell if it worked yet because the 'Get certificate' button is still not there!
04-17-2023 09:01 AM
Try running the following in CLI:
request certificate fetch
show device-certificate status
configure
commit force
04-17-2023 09:09 AM
'request certificate fetch' worked to renew the cert without an OTP, but 'Get certificate' link is still not there. Doesn't seem an issue now, but still no bueno...
04-17-2023 11:17 AM
Thanks. request certificate fetch fixed it for me. I've had this error several times on a PA-460 running the latest preferred releases of firmware.
07-03-2023 02:07 PM
Thanks for adding this command for us dude! After fixing the MTU I ran this to test it immediately and it fixed it for me! Great deets!
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!