GlobalProtect client fails with error "Could not verify the server certificate of the gateway..."
238751
Created On 04/14/22 02:27 AM - Last Modified 07/16/26 13:33 PM
Symptom
- GlobalProtect client throws below error message when a user tries to connect
"Could not verify the server certificate of the gateway. If the issue persists, contact your administrator."
- Certificate validation errors can be seen in the PanGPS.log file.
20830 02/04 09:08:07:640041 - unable to verify, index=0
20830 02/04 09:08:07:640202 - java.security.cert.CertPathValidatorException: Trust anchor for certification path not found.
20830 02/04 09:08:07:640332 - proceed to verify server cert against portal CAs...
20830 02/04 09:08:07:640885 - 1322
20830 02/0409:08:07:646400java.io.FileNotFoundException: /data/user/0/com.paloaltonetworks.globalprotect/files/tca.cer: open failed: ENOENT (No such file or directory)
20830 02/04 09:08:07:652614 - PanHttpsClient: 1738, found exception:javax.net.ssl.SSLHandshakeException: CertPathValidatorException:,Trust anchor for certification path not found
20830 02/04 09:08:07:652749 - PanHttpsClient: server cert error
- Access the portal URL from any browser on the affected machine will show the certificate warning.
Environment
- GlobalProtect App 5.2
Cause
- The certificate used by Portal and Gateway is signed by an external certificate authority (CA).
- The certificate chain is incomplete in the firewall's configuration, causing it not to send the intermediate certificate(s) as required by TLS
Resolution
- Follow the process document to How to Install a Chained Certificate Signed by a Public CA:
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClkoCAC