"No valid device certificate found" messages in system log of a Palo Alto Networks firewall ?
41790
Created On 05/26/21 01:31 AM - Last Modified 04/22/24 21:03 PM
Symptom
- Starting PAN-OS 9.1.2 version, device certificate is required for using cloud services with their firewall (such as Device Telemetry and IoT)
- "No valid device certificate found" is logged in system log with the priority high even though cloud services are not enabled on the firewall.
Environment
- PAN-OS 9.1.2 and later.
- Cloud services (Device Telemetry and IoT) is not being used
Cause
- When the device certificate is not installed, the messages "No valid device certificate found" is logged in system log.
- This is logged with or without cloud services being enabled in PAN-OS 9.1.2.
Resolution
- If the firewall is used for cloud services such as device Telemetry and IoT then install the Device certificate .
- If the cloud service such as Device Telemetry and IoT are not used with the Palo Alto Networks firewall then the message can be safely ignored.
Additional Information
When using cloud service such as Device Telemetry and IoT with your Palo Alto Networks firewall and seeing the message "No valid device certificate found", Refer Why is the system log logging "No valid device certificate found"?