Device Certificate Expired 'Invalid Request. Authentication Failed'

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.
Palo Alto Networks Approved
Palo Alto Networks Approved
Community Expert Verified
Community Expert Verified

Device Certificate Expired 'Invalid Request. Authentication Failed'

L1 Bithead

Hi Everybody,

 

I have 4 firewalls grouped into 2 HA pairs. The first pair had certificates which expired on August 18 and have failed to be renewed. The last fetched message says "Failed to renew device certificate. Invalid request. Authentication failed". I tried going through the OTP process to redeploy the certificate but under Device > Setup > Management > Device Certificate the "Get Certificate" button is no longer there. I also cannot deploy through Panorama as the devices are no longer connected (which I believe is due to the failed certificate request.

 

The second pair of firewalls has certificates which are expiring in a couple of days. These also have failed to renew the certificates citing the same errors.

 

Which authentication is failing here? I'm really not sure where to go from here to fix things. Any ideas?

 

Thanks for any help!

6 REPLIES 6

L1 Bithead

I've found the issue. I ran across the KB article here: https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000004NlxCAE

 

Changing the MTU to 1374 fixed the issue for me.

L2 Linker

I tried changing the mgmt int MTU to 1374 and committed, but can't tell if it worked yet because the 'Get certificate' button is still not there!

Try running the following in CLI:

request certificate fetch

show device-certificate status

configure

commit force

L2 Linker

'request certificate fetch' worked to renew the cert without an OTP, but 'Get certificate' link is still not there. Doesn't seem an issue now, but still no bueno...

Thanks. request certificate fetch fixed it for me. I've had this error several times on a PA-460 running the latest preferred releases of firmware.

Thanks for adding this command for us dude! After fixing the MTU I ran this to test it immediately and it fixed it for me! Great deets!

  • 8336 Views
  • 6 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!