Failed to renew device certificate

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Failed to renew device certificate

L0 Member

Sorry, not sure what board to post this on, as it's my first support post.  Getting an error on my Primary PaloAlto firewall: Failed to renew device certificate.Failed to send request to CSP server.Error: OpenSSL SSL_connect: SSL_ERROR_SYSCALL in connection to certificatetrusted.paloaltonetworks.com:443 

 

When I log onto the firewall, it shows the device certificate is valid on the main dashboard, and when I go to Device->Certificate Management->Certificates, all certs show fine until at least March of 2022.  I'm not sure what to do at this point. 

 

Thanks in advance!

 

1 accepted solution

Accepted Solutions

Cyber Elite
Cyber Elite

@esheldon,

The device certificate process checks in regularly to automatically keep the certificate up to date and to make sure it isn't revoked. The error that you are getting can be caused by a few different things actually. I would verify that your firewall is actually getting to the URL properly according to your logs and verify that a client behind the firewall can reach that URL. 

Be aware that the website will give you a certificate error and will prompt you for a client certificate. As long as you can get that prompt your firewall should be able to access the website without issue. The firewall trusts the website and presents the device certificate to authenticate to the site, so as long as your device certificate is valid you should be all set. 

View solution in original post

2 REPLIES 2

Cyber Elite
Cyber Elite

@esheldon,

The device certificate process checks in regularly to automatically keep the certificate up to date and to make sure it isn't revoked. The error that you are getting can be caused by a few different things actually. I would verify that your firewall is actually getting to the URL properly according to your logs and verify that a client behind the firewall can reach that URL. 

Be aware that the website will give you a certificate error and will prompt you for a client certificate. As long as you can get that prompt your firewall should be able to access the website without issue. The firewall trusts the website and presents the device certificate to authenticate to the site, so as long as your device certificate is valid you should be all set. 

Cyber Elite
Cyber Elite

Hi @esheldon ,

 

The error is referring to the certificate under Device > Setup > Management > Device Certificate.  It is not listed under Certificate Management.  It is used to leverage cloud services.

 

https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-admin/certificate-management/obtain-certificate...

 

Thanks,

 

Tom

Help the community: Like helpful comments and mark solutions.
  • 1 accepted solution
  • 5364 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!