Device Certificate Enforcement Issue Encountered

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Device Certificate Enforcement Issue Encountered

L1 Bithead

Hi, I am following the instructions to apply the device certificate, but I am blocked by the following error:
“Unable to execute OTP install operations command to some firewalls. Please identify the firewalls that failed the process from Panorama and retry OTP.”

I followed the instructions provided in this link:
https://live.paloaltonetworks.com/t5/customer-advisories/update-to-additional-pan-os-certificate-exp...

My setup is as follows:

Panorama: Software version 11.1.6-h3

NGFW: Model PA-850, Software version 11.1.6-h3

 

The command below shows the following output:

show device-certificate status
Device Certificate Information:

Current device certificate status: Valid

Not valid before: 2025/12/26 05:26:50 CST

Not valid after: 2026/03/26 06:26:49 CDT

Last fetched timestamp: 2026/02/04 10:42:39 CST

Last fetched status: Failure

Last fetched info: Failed to fetch device certificate. OTP is not valid

3 REPLIES 3

L0 Member

I ran into something similar, the following helped me and might help you.

 

* Configure NTP, sync and commit the changes. OTP are time based and could cause issues if there is a time drift. If the times didn't match, try creating a new OTP and retry. 

* Another option to get more info, in CLI execute the following commands. 

> show system log | match cert
> show system log | match otp

 

Hope this helps!

V/R
N

Hi @nmbarker, NTP is already configured and pointing to pool.ntp.org. I tried running these commands, but they did not give me any output on the firewall and Panorama.

> show system log | match cert
> show system log | match otp

I also see that the clock is correct when I run the show clock command.

Inside of Panorama, under Panorama > Managed Devices > Summary > Device Certificate / OTP can you see if there's a way to acknowledge the failed OTP operation?

V/R
N
  • 572 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!