Palo Alto Failed To Fetch Device Certificate Tpm Public Key Match Failed ^hot^
Follow these steps in order. Most resolutions do not require rebuilding the endpoint.
If the above steps fail, the issue often requires intervention. Support must typically gain root access to the device to manually delete the invalid certificate files from the /opt/pancfg/mgmt/ssl/private/ directory before a new certificate can be generated and fetched. TPM public key match failed - LIVEcommunity - 1239222 Follow these steps in order
Compare against TPM public key (requires tpm2_readpublic for TPM 2.0). Support must typically gain root access to the
: For TPM-enabled devices, use the specific command request certificate fetch rather than the OTP-based command. This error occurs on a (or possibly Panorama)
This error occurs on a (or possibly Panorama) when the device attempts to retrieve its device certificate from the Trusted Platform Module (TPM) . The “public key match failed” part indicates that the TPM-stored key does not match the expected public key for the certificate being requested.
