Failed to determine issuer

Showing results for 
Show  only  | Search instead for 
Did you mean: 
Please sign in to see details of an important advisory in our Customer Advisories area.

Failed to determine issuer

L3 Networker

Hi guys,


I have a certificate that I need renewing as it's expired, but I am seeing "failed to determine issuer" when attempting to do this.


The certificate is a self-signed certificate, but it wasn't generated on the Palo, but rather an external CA. Do I need to remove this certifiate and renew it on the server I generated it from, or should I be able to renew it on the Palo? I believe that the CA must revoke the certificate, but this means they have to renew it as well, or can you renew it on the Palo using OCSP?




L5 Sessionator

Try importing the Root ca public cert on firewall and then try. If that fails then you have to renew it on server and then import it on firewall.

Hi Pankaj,


That is what was done intially to get the error message.

  • 2 replies
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!