- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
12-16-2015 07:07 AM - edited 12-16-2015 07:08 AM
Hi,
This issue is on a Palo-Alto PA-500.
I've renewed my SSL certificate from my provider and updated it in the Palo-alto / Device / Certificates.
It tells me that this certificate is valid.
Ok. thanls.
But now that the date it should have expire is gone, my Global Protect clients have an error about the certificate that tells them that it's no more valid.
Where do I need to update the certificate, as I thought that it was stored on the Palo-Alto and checked by the client before any connection.
If anybody have any clue on how it worked, that would be nice to share.
Thank you.
12-16-2015 09:54 AM
When you installed the updated cert, did you install the full chain (cert + intermediate) as per this article:
If not, that's the most likely cause. The cert must be installed with the chain, or else all your clients must already trust the intermediate CA (or multiple intermediate CAs, if needed).
If you did just the server certificate itself and not the full chain, try doing the chain install to see if that solves it for you.
Cheers,
Greg
12-22-2015 12:47 AM
Hi,
I've added the certfile then the intermediate file, but it didn't resolve so I tried to add a file with cert+interm. but it didn"t change anything.
The state is still "valid" on the PA but the client still have a message about the validity of the certificate.
Should I try to revoke the certificate on the PA and import it again ?
12-22-2015 05:50 PM
Are you using the same certificate in the portal and the Gateway?
Please verify if you are getting the same error when you trying to access the portal.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!