- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
10-06-2025 06:04 AM
I had already tried a commit force and it changed nothing. Ultimately, I was able to convince Palo Alto to handle my case directly since my provider is still dragging their feet.
Indeed Palo Alto support must go through a challenge/response process to gain root access to the device in order to clear out the old cert and generate a new one. I asked and this seems to be a regular problem. I'm not sure why Palo Alto wouldn't prioritize a proper fix for this issue both to alleviate support load and to enable their customers to continue working. Since the device certificate was preventing a successful CIE sync, all VPN user/group addition/removals were blocked until we could get support's attention to fix the issue. This should not be an acceptable bug to leave in the product.