- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
10-31-2018 11:07 AM
Hi There,
I'm having the same issue but not on self signed certificate and on linux ( Fedora 29)
Global Protect is configured with the certificate signed by the Authorized CA.
The Chain is:
DigiCert Global Root CA
DigiCert SHA2 Secure Server CA
Server certificate.
It works perfect on Windows.
On Linux, Fedora.
I get the error
Error: Gateway exgw: The server certificate is invalid. Please contact your IT administrator.
I checked if certificate is trusted
xxx\Downloads]$ trust list | grep Digi
label: DigiCert Global Root CA
label: DigiCert SHA2 Secure Server CA
The first two are the exactly the ones that are trusted.
I am puzzled. Did anybody have issues with Global Protect on linux ?
10-31-2018 11:10 PM
Hello @PiankaMariusz
Yes, as per PA it supports below three types of Linux distributions only.
I do have 3rd party CA signed cert configured and tested it on both Ubuntu and RHEL. It works smoothly without any issues.
10-31-2018 01:33 PM
Are you actually sending the full chain, or are you only sending your Server certificate?
10-31-2018 01:57 PM
Well,
Full chain is present on the firewall.
However, I did a lot of googling since I posted it.
I found this
And I believe this is an issue.
I can understand the software is supported on 3 distros of Linux, but technically Fedora is Redhat.
I am going to try Global Protect on Centos next and if it will work without me changing a single line of configuration on Palo Alto that will be it.
10-31-2018 11:10 PM
Hello @PiankaMariusz
Yes, as per PA it supports below three types of Linux distributions only.
I do have 3rd party CA signed cert configured and tested it on both Ubuntu and RHEL. It works smoothly without any issues.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!