- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
04-13-2015 02:33 AM
Hi there,
I generated a CSR with PAN-OS 6.1.3 and submitted it to our Microsoft AD CA with subordinate CA template. After uploading the certificate it shows up under the root CA certificate of our domain. But when commiting the changes I get an "Error: Certificate failed to load: invalid certificate chain" error message. What have I done wrong?
The CSR was generated with one main CN as FQDN of both firewalls (leinf-pa-3020-rz.domain.de, it's a HA cluster) and their own management IP adresses and FQDNs for usage as the WebUI certificate.
This is how it looks in the WebUI:
I tried adding the root cert data into the subordinate cert, and when I export it again it is still in there. So why is it complaining about the chain?
Kind Regards
Christian