System logs report "Failed to renew device certificate. Application Error occurred"
7340
Created On 12/23/22 20:54 PM - Last Modified 10/20/23 02:33 AM
Symptom
- Device certificate expires and automatic renew fails.
- System logs (show log system) report the following error
Failed to renew device certificate. Application Error occurred. Please contact support!
- device_certgen.log (tail follow yes mp-log device_certgen.log))report similar error
device_certgen INFO Generated pkey and CSR
device_certgen ERROR Certificate fetch request failed : Application Error occurred. Please contact support!Environment
- Palo Alto Firewalls or Panorama
- Supported PAN-OS
- Device Certificate
Resolution
- Manually fetch the certificate from the CLI using CLI command "request certificate fetch"
- If the manual fetch fails, then install the certificate againÂ
- Log in to the Customer Support Portal.
- Select Products > and click on Device Certificates
- Click on "Generate OTP".
- For the Device Type, select Generate OTP for Next-Gen Firewalls.
- Select your PAN-OS Device serial number.
- Generate OTP and copy the OTP.
- Log in to your next-generation firewall as an admin user.
- Select Device > Setup > Management > Device Certificate and Get certificate.
- Paste the One-time Password you generated and click OK.
- Your next-generation firewall successfully retrieves and installs the certificate.