Unable to create console access to the firewall in OCI.

Unable to create console access to the firewall in OCI.

0
Created On 02/29/20 00:10 AM - Last Modified 07/19/22 23:16 PM


Symptom


  • While attempting to create console access to PA-VM firewall instance, below errors are encountered:
  1. InvalidParameter - Invalid ssh public key type "-----BEGIN"”
  2. TooManyRequests - Too many requests for the user

 

  • Navigate to PA-VM instance in OCI and scroll down to “Console connections”
  • Click on “Create Console Connection”
  • Choose SSH Key Files and select the .pub file to save on your computer and check the result or paste the SSH Key and check the result.
  • In both cases you will encounter different error messages.
  • Review the format of the public key pasted from the .pu file or imported .pub file which looks like this:

User-added image

  • This format is not accepted by OCI. Even if you delete “--- BEGIN *** ---” and “--- END SSH2 **---”, the key will not be accepted by OCI.


Environment


  • Platform: PA-VM
  • Deployment: Any


Cause


  • The format of the public key that is either being pasted or imported from the computer is not accepted by OCI.


Resolution


  • Create a new key using puttygen and copy the public key. Accepted key looks as below:

  • Accepted Key looks like this



Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000POtcCAG&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail