ssl sever certificat can't be verified

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

ssl sever certificat can't be verified

L0 Member

Hi,

 

This issue is on a Palo-Alto PA-500.

 

I've renewed my SSL certificate from my provider and updated it in the Palo-alto / Device / Certificates.

 

It tells me that this certificate is valid.

Ok. thanls.

 

But now that the date it should have expire is gone, my Global Protect clients have an error about the certificate that tells them that it's no more valid.

 

Where do I need to update the certificate, as I thought that it was stored on the Palo-Alto and checked by the client before any connection.

 

If anybody have any clue on how it worked, that would be nice to share.

 

 

Thank you.

3 REPLIES 3

L7 Applicator

When you installed the updated cert, did you install the full chain (cert + intermediate) as per this article:

https://live.paloaltonetworks.com/t5/Management-Articles/How-to-Install-a-Chained-Certificate-Signed...

 

If not, that's the most likely cause. The cert must be installed with the chain, or else all your clients must already trust the intermediate CA (or multiple intermediate CAs, if needed). 

 

If you did just the server certificate itself and not the full chain, try doing the chain install to see if that solves it for you.

 

Cheers,

Greg

Hi,

I've added the certfile then the intermediate file, but it didn't resolve so I tried to add a file with cert+interm. but it didn"t change anything.

 

The state is still "valid" on the PA but the client still have a message about the validity of the certificate.

 

Should I try to revoke the certificate on the PA and import it again ?

Are you using the same certificate in the portal and the Gateway?

 

Please verify if you are getting the same error when you trying to access the portal.

  • 2221 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!