Enhanced Security Measures in Place:   To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.

Fetch Device Certificate failure

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Fetch Device Certificate failure

L0 Member

Hello,

 

I am getting this error (Failed to fetch device certificate.TPM public key match failed.) on a PA460 (11.0.2-h2).

 

I tried multiple solutions without success :

I can ping certificate.paloaltonetworks.com form the management interface.

 

Kindly help to resolve the issue.

9 REPLIES 9

L1 Bithead

Getting the same error on 440 too..

L2 Linker

We have the same error with our new PA-3410 and PAN-OS 10.2.6.

I am going to open a case...

PaloAlto solved the problem for me by deleting the existing certificate and generating a new one. It needed root access to the firewall.

Thanks, @Meed. I will reach out to PAN support.

L2 Linker

Palo Alto also saved it for me. They updated the claim key and Hash Key from their end. After a "commit force" the issue was fixed.

L0 Member

Encountering a "Fetch Device Certificate" failure may result from various issues. Ensure network connectivity, valid credentials, and proper certificate configuration. Troubleshoot systematically, collaborating with support if needed. A comprehensive approach ensures efficient resolution, maintaining secure and seamless device communication.

 

L2 Linker

It will require a maintenance  window you  can follow the below Steps and let me know if it works:

1.Log in to cli
2. Configure  
3. Commit force
4.exit
And see if it works and if you are still getting the same error

Zain

how to delete the existing certificate,?

how to use root access? 

This worked for me. I was trying to download device certificate using the web gui but was getting unexpected otp.

  • 7114 Views
  • 9 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!