We're encountering a GlobalProtect error stating 'Certificate is not within its validity period,' despite this being a newly configured Palo Alto setu

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

We're encountering a GlobalProtect error stating 'Certificate is not within its validity period,' despite this being a newly configured Palo Alto setu

L1 Bithead

We are currently setting up a PA-VM Firewall under the Alibaba Cloud Platform. However, we are encountering an issue with GlobalProtect. The client keeps showing an error stating that the certificate is not within its validity period, even though the certificate is valid until July 2026, as this setup was just recently provisioned.

We have already manually installed the certificate on the client devices, including the root CA, but the issue still persists.

 

 

GlobalProtect  #CertificateIssue

GFrondozo
2 REPLIES 2

Community Team Member

Hi @Glenyvie ,

 

 

Which GP client version are you running? Where did you get your cert from? I would double check to make sure the entire cert chain (root and any intermediate CAs) have correctly been imported into the firewall and the client machine (trusted root cert store). Id also verify the correct SSL/TLS profile is being referenced in the Portal and Gateway. 

 

LIVEcommunity team member
Stay Secure,
Jay
Don't forget to Like items if a post is helpful to you!

Please help out other users and “Accept as Solution” if a post helps solve your problem !

Read more about how and why to accept solutions.

Cyber Elite
Cyber Elite

s this issue resolved itself in the meantime?

most commonly this issue happens when you have a brand new certificate and due to misconfiguration in the time of the firewall or client (no NTP, wrong timezone, wrong time or date,...) and the system thinks it has not reached the starting ValidFrom date&time on the certificate yet

 

setting up NTP everywhere and ensure the right timezone etc usually fixes this issue

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization
  • 496 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!