missing "otp" displayed when trying to run "request certificate fetch otp"
8214
Created On 01/31/23 06:06 AM - Last Modified 09/11/24 21:44 PM
Symptom
- Trying to install a device certificate on Palo Alto Firewall.
- OTP is displayed as missing when executing "request certificate fetch otp xxxxxxx"
> request certificate fetch otp xxxxxxx
missing "otp"
Environment
- Palo Alto Next Gen Firewalls
- PAN-OS 10.1 or later
Cause
Some of the Next-Generation firewall models install the device certificate when they first connect to the CSP during the initial registration process.
Resolution
- The following Palo Alto Networks Next-Generation firewall models install the device certificate when they first connect to the CSP during the initial registration process.
- Manual install the device certificate is not needed for these firewall models.
- This information is documented under Install A Device Certificate.
- PA-400 Series firewalls
- PA-1400 Series firewalls
- PA-3400 Series firewalls
- PA-5400 Series firewalls
- PA-5450 firewall
- PA-7500 Series firewalls
- Register with the Firewall on Customer Support Portal and if required, use the CLI command "request certificate fetch".