- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
09-04-2026 06:38 AM - edited 09-04-2026 06:45 AM
I was asked to assist with a new wildcard certificate that was uploaded to the firewall yesterday, update the SSL/TLS Service Profile and confirmed settings for GP. Commit failed so began reviewing configuration. The 2 reasons listed for the failure were:
client useridd phase 1 failure
client gp_broker phase 1 failure
Double checking and the wildcard certificate was set active for the Authentication Override between the GP Portal and Gateway; reverted to the old certificate and the that error cleared.
While looking into the other commit error was for found that the SSL/TLS profile had been used in the user-id settings for the server monitor section.
I was able to create a new SSL/TLS profile using the new correct certificate and confirmed that is now working for the GP login page, but would like to get the other 2 errors corrected so I can remove the expired certificates.
What I did notice is that if I select TLS 1.3 as the maximum version for in the SSL/TLS profile, the new profile isn't listed as an option in the User-ID Syslog Service Profile drop down.
Both old and new certificates are from the same CA. The only real difference I see between the 2 certificates is that the old certificate had the following SANs:
*.mydomain.org
mydomain.org
While the new only has *.mydomain.org.
09-04-2026 06:43 PM
Original and new cert have same algorithm (RSA vs Elliptic Curve)?
09-08-2026 07:52 AM
Both are RSA and come from the same CA.
09-09-2026 11:59 AM
Revert firewall back to running config "Device > Setup > Operations > Revert to last running configuration"
This will remove any change done after last commit.
Then try to import cert again (so you can be sure only cert import is only change that has been done).
Does commit work then?
09-10-2026 08:53 AM
I was able to commit the changes and get the certificate applied properly by setting the certificate used for the cookie to the old expired certificate. And I used the new TLS profile w/ the new certificate for the portal and gateway authentication profile. So it seems the syslog server and the cookie for authentication from the portal and gateway appear to be what is outstanding.
I wasn't the one who initially did make the changes so not sure what else was bundled as a part of the other commit unfortunately.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!

