Error message 'Thermite certificate is used for CDL communication' when trying to fetch Cortex Data lake certificate

Error message 'Thermite certificate is used for CDL communication' when trying to fetch Cortex Data lake certificate

19539
Created On 05/05/22 02:52 AM - Last Modified 08/04/22 19:54 PM


Symptom


  • A Strata NGFW (Next generation firewall) admin have Cortex Data Lake (CDL) license on a firewall.
  • To troubleshoot an issue with CDL functionality, the admin runs one of the following commands on the firewall command line interface which throws an error.
admin@PA220> request logging-service-forwarding certificate delete
Server error : Thermite certificate is used for CDL communication

admin@YogeshHomePA220> request logging-service-forwarding certificate info
Server error : Thermite certificate is used for CDL communication
  • The same error is displayed when an admin attempts to onboard a Firewall running 10.1 PanOS to cortex data lake using old pre-shared key method.
CDL-PSK-Onboarding-Thermite-error.png
 
 


Environment


  • Palo Alto Strata Firewall with Cortex Data lake license
  • PanOS version 10.1 or above


Cause


  • The error message is expected on PanOS version 10.1 and above.
  • Starting with 10.1, Cortex data lake no longer requires a separate certificate and uses the device certificate instead.
  • Do not attempt to use the old method of PSK (PreShared Key) to onboard ata lake for a firewall running 10.1.0 or above.

 


 


Resolution


  1. This error message does not have any impact on the CDL functionality.
  2. Install the device certificate on the firewall as directed and follow the steps described in Onboard Firewalls without Panorama (10.1 or Later).


Additional Information


Following commands should be used to verify the device certificate status and CDL status on the firewall.
admin@PA220> show device-certificate info
admin@PA220> show device-certificate status
admin@PA220> request logging-service-forwarding status
admin@PA220> show logging-status

 


Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000004OWtCAM&lang=en_US%E2%80%A9&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language