- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
11-22-2017 01:41 AM
Hello
we have our enterprise CA and our PA firewalls have signed certs from it. Now for our captive portal, we also have a certi signed from our enterprise CA. Everything works and there is no browser error for certificate.
But in the FW commit, we get a warning "Warning: cannot find complete certificate chain for certificate ..."
I found the following KB for a Public CA
and I also tried the Workaround mentioned at the bottom of the KB, but it does not work.
Any suggestions?
Thanks and Regards,
R
11-22-2017 01:52 AM
Hi @rjdahav163
My advice would be to take a look at the certificate hierarchy in Windows, are you seeing the full chain there that is expected when you open up the file?
Example here, taken from the live community website:
hope this helps,
Ben
11-22-2017 02:34 AM
Hi @bmorris1
Yes I see the complete chain in the hierarchy as expected and installed the same on FW but still firewall complains. 😞
Regards,
R
06-27-2023 12:47 AM
Hi @rjdahav163 , have you resolved this issue? I'm having the same.
09-17-2023 09:36 PM
@IMTechSupport Yes.. I uploaded certificates one by one, starting from the device cert, then intermediate cert and then the root cert.
09-18-2023 04:57 AM
Hi @rjdahav163 , @IMTechSupport ,
I have noticed that when generating certificate from our internal Windows PKI and opeing the cert with text editor it looks like PKI is listing the full chain (the root, the intermiediate, the server and then the key), but the order is wrong. In my experience the root and the intermediate order was mixed and if put them in correct order (root, intermediate, server) and then upload it palo fw. After that the warning is gone.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!