Error:
An unexpected error occurred. Please click Reload to try again.
Error:
An unexpected error occurred. Please click Reload to try again.
Why is the system log logging "No valid device certificate found"?

Why is the system log logging "No valid device certificate found"?

159233
Created On 09/02/20 00:32 AM - Last Modified 08/01/22 01:46 AM


Question


Why is the system log logging "No valid device certificate found"?

Example:
  • System Log:
2020/09/01 04:04:06 high     general        general 0  No valid device certificate found
2020/08/31 04:03:34 high     general        general 0  No valid device certificate found
2020/08/30 04:03:02 high     general        general 0  No valid device certificate found
2020/08/29 04:04:30 high     general        general 0  No valid device certificate found
2020/08/28 04:03:58 high     general        general 0  No valid device certificate found
2020/08/27 04:03:26 high     general        general 0  No valid device certificate found
2020/08/26 20:35:00 high     general        general 0  No valid device certificate found
  • WebUI
User-added image


Environment


  • Palo Alto Firewall.
  • PAN-OS 9.1.2 and above.


Answer


  • In order to use the cloud services such as IoT Security, DLP, and Device Telemetry in PAN-OS version in 10.0.0, 9.1.2, 8.1.14 or later, a device certificate is required.
  • If no a device certificate is installed:
    1. No valid device certificate found log will be generated in the system log.
    2. Device certificate not found will be shown in the Device Certificate Tab.

To resolve:
  1. Log in to the Customer Support Portal 
  2. Select Assets > Device Certificates and Generate OTP.
  3. For the Device Type, select Generate OTP for Next-Gen Firewalls.
  4. Select your PAN OS Device serial number.
  5. Generate OTP and copy the OTP.
  6. Log in to your next-generation firewall as an admin user.
  7. Select Device > Setup > Management > Device Certificate and Get Certificate.
  8. Paste the One-time Password you generated and click OK.
  9. Your next-generation firewall successfully retrieves and installs the certificated.
Note: After a correct device certificate is successfully installed.
 
User-added image


Additional Information


For more details on installing a device certificate, click this link:  Install a Device Certificate


See also:

Does "No valid device certificate found" mean critical situation for all of the customers using PaloAltoNetworks firewall ?


Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000HAayCAG&lang=en_US%E2%80%A9&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language