Global Protect - Linux Fedora , CA trusted cert error

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Global Protect - Linux Fedora , CA trusted cert error

L1 Bithead

Hi There,

I'm having the same issue but not on self signed certificate and on linux ( Fedora 29) 

Global Protect is configured with the certificate signed by the Authorized CA.

The Chain is:

DigiCert Global Root CA
DigiCert SHA2 Secure Server CA

Server certificate.

 

It works perfect on Windows.

 

On Linux, Fedora.

I get the error 

Error: Gateway exgw: The server certificate is invalid. Please contact your IT administrator.

 

I checked if certificate is trusted 

 

xxx\Downloads]$ trust list | grep Digi
label: DigiCert Global Root CA
label: DigiCert SHA2 Secure Server CA

The first two are the exactly the ones that are trusted.


I am puzzled. Did anybody have issues with Global Protect on linux ? 

1 accepted solution

Accepted Solutions

L3 Networker

Hello @PiankaMariusz

 

Yes, as per PA it supports below three types of Linux distributions only.

 

I do have 3rd party CA signed cert configured and tested it on both Ubuntu and RHEL. It works smoothly without any issues.

 

https://www.paloaltonetworks.com/documentation/global/compatibility-matrix/globalprotect/where-can-i...

 

 

Capture.PNG

View solution in original post

3 REPLIES 3

Cyber Elite
Cyber Elite

@PiankaMariusz,

Are you actually sending the full chain, or are you only sending your Server certificate? 

Well,

Full chain is present on the firewall.

 

However, I did a lot of googling since I posted it.

I found this

https://www.reddit.com/r/paloaltonetworks/comments/9hh9g0/does_globalprotect_work_with_linux_distrib...

 

And I believe this is an issue.

 

I can understand the software is supported on 3 distros of Linux, but technically Fedora is Redhat.

I am going to try Global Protect on Centos next and if it will work without me changing a single line of configuration on Palo Alto that will be it.



 

L3 Networker

Hello @PiankaMariusz

 

Yes, as per PA it supports below three types of Linux distributions only.

 

I do have 3rd party CA signed cert configured and tested it on both Ubuntu and RHEL. It works smoothly without any issues.

 

https://www.paloaltonetworks.com/documentation/global/compatibility-matrix/globalprotect/where-can-i...

 

 

Capture.PNG

  • 1 accepted solution
  • 5257 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!