Enterprise PKI Cert Chain Error

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Enterprise PKI Cert Chain Error

L3 Networker

Hello 

 

we have our enterprise CA and our PA firewalls have signed certs from it. Now for our captive portal, we also have a certi signed from our enterprise CA. Everything works and there is no browser error for certificate.

But in the FW commit, we get a warning "Warning: cannot find complete certificate chain for certificate ..."

 

I found the following KB for a Public CA

https://live.paloaltonetworks.com/t5/Management-Articles/How-to-Install-a-Chained-Certificate-Signed...

 

and I also tried the Workaround mentioned at the bottom of the KB, but it does not work.

 

Any suggestions?

 

Thanks and Regards,

R

5 REPLIES 5

L4 Transporter

Hi @rjdahav163

 

My advice would be to take a look at the certificate hierarchy in Windows, are you seeing the full chain there that is expected when you open up the file?

 

Example here, taken from the live community website:

certhier.png

 

hope this helps,

Ben

Hi @bmorris1

 

Yes I see the complete chain in the hierarchy as expected and installed the same on FW but still firewall complains. 😞

 

Regards,

R

L2 Linker

Hi @rjdahav163 , have you resolved this issue? I'm having the same.

L3 Networker

@IMTechSupport Yes.. I uploaded certificates one by one, starting from the device cert, then intermediate cert and then the root cert.

Hi @rjdahav163 , @IMTechSupport ,

I have noticed that when generating certificate from our internal Windows PKI and opeing the cert with text editor it looks like PKI is listing the full chain (the root, the intermiediate, the server and then the key), but the order is wrong. In my experience the root and the intermediate order was mixed and if put them in correct order (root, intermediate, server) and  then upload it palo fw. After that the warning is gone.

  • 3782 Views
  • 5 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!