"No valid device certificate found" messages in system log of a Palo Alto Networks firewall ?
47498
Created On 05/26/21 01:31 AM - Last Modified 06/11/25 18:58 PM
Symptom
- Starting PAN-OS 9.1.2 version, device certificate is required for using cloud services with their firewall (such as Device Telemetry and Device Security)
- "No valid device certificate found" is logged in system log with the priority high even though cloud services are not enabled on the firewall.
Environment
- PAN-OS 9.1.2 and later.
- Cloud services (Device Telemetry and Device Security) is not being used
Cause
- When the device certificate is not installed, the messages "No valid device certificate found" is logged in system log.
- This is logged with or without cloud services being enabled in PAN-OS 9.1.2.
Resolution
- If the firewall is used for cloud services such as device Telemetry and Device Security then install the Device certificate .
- If the cloud service such as Device Telemetry and Device Security are not used with the Palo Alto Networks firewall then the message can be safely ignored.
Additional Information
When using cloud service such as Device Telemetry and Device Security with your Palo Alto Networks firewall and seeing the message "No valid device certificate found", Refer Why is the system log logging "No valid device certificate found"?