下一代防火墙无法连接到 Panorama,并显示“证书验证失败:错误:10(证书已过期)”
7413
Created On 05/15/24 15:25 PM - Last Modified 08/14/24 01:47 AM
Symptom
- ms.log (少 mp-log ms.log) 每 10 秒显示 “Cert verify failed: error: 10 (certificate has expired)” 消息
0900 Error: valid_cert(cs_client.c:17): commssl: Cert verify failed: error: 10 (certificate has expired)
.....
0900 Error: valid_cert(cs_client.c:17): commssl: Cert verify failed: error: 10 (certificate has expired)
- 根据 证书过期文章,已安装所需的应用版本(已安装 8847-8736,高于 8795-8489)
- 系统日志 (show log system) 显示“请重新启动您的设备”
2024/05/15 12:12:40 info general general 0 This is applicable only to Panorama/Panorama-managed devices and can be ignored otherwise. The Panorama certificate, expiring 19-Nov-2033, for managing NGFW and log collectors has been installed. To activate the renewed certificate, please reboot your device. Panorama can not manage devices after April 7th without a reboot. Additional information is available in the content release notes. If a custom certificate is used then this message is not applicable, and no action is required.
Environment
- 下一代防火墙
- 全景
- PAN-OS 8.1 及以上。
- 证书过期
Cause
如系统日志和 实时文章中所示,安装高于 8795-8489 的应用程序后需要重新启动。
Resolution
安装高于 8795-8489 的应用程序后,重新启动 Panorama 和 Next-Generation-Firewall。