How to reimport a Chained Certificate signed by a Public CA

cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements
We are conducting regularly scheduled maintenance over the weekend, which could cause some downtime on LIVEcommunity. We apologize for any inconvenience.

How to reimport a Chained Certificate signed by a Public CA

L0 Member

I purchased a certificate from a public CA to be used for a Global Protect deployment. When I originally imported the certificate, I failed to import the chained certificate per the instructions at https://live.paloaltonetworks.com/t5/Management-Articles/How-to-Install-a-Chained-Certificate-Signed... I only installed the server certificate and not the intermediate.

 

Following the instructions from https://live.paloaltonetworks.com/t5/Management-Articles/Fix-For-Error-When-Importing-Chained-PEM-Fo... I am unable to reimport that chained certificate I am manually assembling.

 

When I attempt to commit, I get the following error:

 

Commit job 14578 is in progress. Use Ctrl+C to return to command prompt
......55%
Error: Certificate company_GPVPN failed to load: Unmatched certificate and key
Error loading vsys cfg
failed to handle CONFIG_UPDATE_START
Error: response from cfgpush.s1.dp0.comm.cfg-dp: Certificate company_GPVPN failed to load: Unmatched certificate and key
Error loading vsys cfg
failed to handle CONFIG_UPDATE_START
(Module: device)
Commit failed
[edit]

 

Is this a result of the private key already being tied to the original certificate import by way of the CSR?

0 REPLIES 0
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!