What you do is merge the certificate and the CA into one cert and upload. Palo Alto will not join the chain together for you. You need to join the certificates yourself then upload. The Panorama will strip the second certificate, so you will need to upload locally. Took a bit of time but again, works nicely. So do something like.... cat mycert.crt myCA.crt > mycertchain.pem. Then upload that with the key. This works.
... View more