Network Management
Invalid SSL certificate message when adding credentials for Palo Alto Polling settings
When adding API polling to Palo Alto nodes you get an invalid cert warning.
First published date
Last published date
Overview
Product section
Cause
- Certificate is not signed by a trusted certificate authority.
- Certificate is not within the validity period or expired
- Certificate is issued to a common name that does not match.
Resolution
Scenario 1: Certificate is not signed by a trusted certificate authority
If a certificate is self-signed and not signed a public certificate authority (CA), each node will produce the following error message and must be manually accepted. Once accepted, this certificate will be added to node setting to avoid the prompt in the future. Please note, if a new self-signed certificate is generated on the Palo Alto firewall, the new certificate must be manually accepted again
If the certificate is signed by a public CA, please add the root certificate to Trusted Root Certificate Authorities store on the poling engine.
- Open Microsoft Management Console (MMC).
- From the File menu, select Add/Remove Snap In.
- The Add or Remove Snap-ins window appears.
- From the Available snap-ins list, choose Certificates
- Select Add

- In the Certificates snap-in window, select Computer account
- Select Next
- In the Add or Remove Snap-in window, select OK

- From the the MMC snap-in, select Console Root in the left pane, then expand Certificates (Local Computer) > Trusted Root Certification Authorities
- Right-click Trusted Root Certification Authorities folder
- Select All Tasks > Import
- Follow the prompts in the wizard to import the root certificate
- Click OK
Scenario 2: Certificate is not within the validity period or expired
If the certificate is past the expiration date, a new certificate will need to be created. If the certificate is signed by a public CA, please reach out the CA to issue a new certificate. The validity period is based on the time settings of the polling engine. If the certificate is within the validity period, check the time setting on the polling engine are correct.