cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Who rated this post

Certificate Validation not working

L0 Member

Hi all,

hope you are doing well!

I've a little probelm with the certificate validation.

I've changed the DDNS provider to a custom one bit certifiate validation dows not work.

PAN OS: 10.0.5

First what I've done on CLI:

set network interface ethernet ethernet1/1 layer3 ddns-config ddns-vendor-config dyn-api-host value updates.dnsomatic.com
set network interface ethernet ethernet1/1 layer3 ddns-config ddns-vendor-config dyn-baseuri value /nic/update
set network interface ethernet ethernet1/1 layer3 ddns-config ddns-vendor-config dyn-username value username
set network interface ethernet ethernet1/1 layer3 ddns-config ddns-vendor-config dyn-password value password

Image 4.png

 

My Certificate Profile looks like this:

Image 5.png

 

And the  certificate for Hydrant:

Image 3.png

As my opinion it should work but I got the following error:

Image 2.png

 

And the pcap:

Image 1.png

The server send the right certificate but the Palo will not verify it.

Any hints?

Thanks,

Sören

 

The only winning move is not to play!
Who rated this post