Managent profiles should really enforce a min of TLSv1.2 on Palo Alto firewalls. In my environment TLSv1 is not allowed. This change worked for me. An alternative fix (untested) would be to specify the protocol as TLS and let the server control the protocol seclection. #24
Changing destination branch to dev branch dev2.3.2.1 and merging