HA pair not syncing after SSL cert change

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

HA pair not syncing after SSL cert change

L0 Member

Hi there folks,

 

I'm trying to troubleshoot an issue with 2 firewalls where we uploaded the same SSL cert in both FWs and now they are not syncing.

 

Our troubleshooting efforts have come to the following:
- Reboot management server on both firewalls.

- Config didn't change, this was working before the cert change.

removing and readding the cert while Config Sync is turned off 

- Adding the certificate and the SSL/TLS Service Profile "GP_CertificateProfile" to only the active device and sync (with original certificate and new certificate)

- Adding the certificate and the SSL/TLS Service Profile "GP_CertificateProfile" to both the active and passive device and sync (with original certificate and new certificate)

- Followed this other live community post:

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000004OHyCAM&lang=en_US%E2%80%A...

 

- This other KB: https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClgSCAS

The exact error is the following:|
Screenshot 2024-10-11 124237.jpg

 

Would appreciate any guidance.

 

Thanks.

0 REPLIES 0
  • 207 Views
  • 0 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!