Device certificate fetch fails with error "Failed to fetch device certificate. Failed to send request to CSP server."

Device certificate fetch fails with error "Failed to fetch device certificate. Failed to send request to CSP server."

10105
Created On 02/01/24 18:30 PM - Last Modified 05/20/24 20:45 PM


Symptom


Failed to fetch device certificate. Failed to send request to CSP server. Error: OpenSSL SSL_connect: SSL_ERROR_SYSCALL in connection to certificate.paloaltonetworks.com:443


Environment


  • Any Palo Alto Networks Firewall or Panorama
  • PAN-OS version 10.0 and above
  • Traffic from the management interface (dynamic updates, certificate fetch, etc) is routed through a firewalls data plane for inspection.


Cause


  • The certificate fetch error can occur when the 'paloalto-shared services' application is absent from the configured security policy that is supposed to allow this traffic.
  • Without including this specific application in the policy rules, the firewall may not properly handle management traffic such as dynamic updates and device certificate updates.


Resolution


  1. Review and update your security policy to include the following applications:
    • Web-Browsing
    • SSL
    • paloalto-updates
    • paloalto-shared-services
  2. After making the necessary policy changes, commit the configuration.
  3. Proceed to 'Device' > 'Setup' > 'Management' > 'Device Certificate' and select 'Get certificate.'
  4. Paste the OTP obtained from the SCP and click 'Get certificate.'


Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000XhiACAS&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail