GlobalProtect Gateway Server Certificate Renewal impact on HIP checks

GlobalProtect Gateway Server Certificate Renewal impact on HIP checks

411
Created On 12/01/25 06:30 AM - Last Modified 05/26/26 20:06 PM


Symptom


  • GlobalProtect users unable to access resources as the mapping is missing on the firewall and traffic matches incorrect policy.
  • HIP report check failing with error message SSL routines:tls_process_server_certificate:certificate verify failed seen in PanGPS.log:
(P16260-T8340)Debug(1537): 02/27/25 20:23:16:480 OpenSSL alert write:fatal:certificate unknown
(P16260-T8340)Dump (1546): 02/27/25 20:23:16:480 SSL_connect:error in error
(P16260-T8340)Debug( 459): 02/27/25 20:23:16:480 SSL connect failed
(P16260-T8340)Debug( 66): 02/27/25 20:23:16:480 detailed SSL error info:
(P16260-T8340)Debug( 69): 02/27/25 20:23:16:480 *** error:1416F086:SSL routines:tls_process_server_certificate:certificate verify failed
(P16260-T8340)Debug( 948): 02/27/25 20:23:16:480 connect() faile


Environment


  • NGFW Firewalls
  • Supported PAN-OS versions
  • Supported GlobalProtect (GP) versions
  • GlobalProtect Gateway
  • Server Certificate Renewal
  • HIP Report Check


Cause


  • Gateway provides a server certificate checksum to GP app as part of successful login response, along with a session cookie and other information.
  • This checksum is used for certificate verification in subsequent GP connections to gateway while sending HIP reports.
  • When Gateway server certificate was renewed, GP app was unaware of this renewal and continued to use the old checksum to verify against the new server certificate.
  • This mismatch led to server certificate verification failures, preventing GP app from successfully sending HIP reports.


Resolution


To resolve the issue for active sessions, the cached certificate information on the client must be updated. This can be achieved through one of the following methods:

Method 1: Manual Reconnect or Refresh

  1. Manually Disconnect and Reconnect their GlobalProtect app, OR 
  2. Click the Refresh Connection option in the GlobalProtect app settings.
  3. This forces a fresh authentication process, updates the cached gateway certificate checksum, and restores normal HIP reporting functionality.

Method 2: Administrator Logout Administrators can log out the affected users directly from the gateway.

  1. To log out a specific user, use the CLI command: request global-protect-gateway logout user <username>
  2. To log out all users at once, use the CLI command: request global-protect-gateway client-logout-all
  3. Once logged out, the GlobalProtect client will automatically attempt to refresh the connection and re-authenticate, thereby obtaining the new certificate.


Additional Information


Best Practice:

  • Because there is no seamless rollover mechanism for active sessions during a certificate replacement, it is recommended to perform gateway certificate renewals during a scheduled maintenance window when active user connections are minimal.
  • Once the maintenance is complete, instruct users to refresh their GlobalProtect connection.


Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA1Ki000000wk58KAA&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail