<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic User management with  Client certificates not working in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/user-management-with-client-certificates-not-working/m-p/397256#M1154</link>
    <description>&lt;P&gt;Hello experts,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are trying to authenticate users connecting to GP via client certs, idea is to revoke client certs and thus prevent users from connecting to GP. Test user is still able to connect after certification has been revoked. Due to some reasons, OCSP has been disabled on the gateway, CRL does not contain revocation status, only delta CRL does, which is not supported by PAN-OS ref (tac case &lt;SPAN&gt;01728222&lt;/SPAN&gt;).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In PANGPS following logs are seen:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;(T532)Info (5289): 02/05/21 15:23:47:711 cert 000001E403ACF4B0 verification result is 0x4 &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;(T532)Info (5292): 02/05/21 15:23:47:711 cert 000001E403ACF4B0 failed revocation verificaiton &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;(T532)Debug(5309): 02/05/21 15:23:47:711 Check certificate revocation returns FALSE&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Questions here are:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1&amp;gt; Does the above logs indicate that the GP agent has detected that the cert is expired or that the revocation check has failed.&lt;/P&gt;&lt;P&gt;2&amp;gt; Will the GP agent do a client cert validation prior to allowing the user to connect. or not.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 12 Apr 2021 16:03:19 GMT</pubDate>
    <dc:creator>ksoni</dc:creator>
    <dc:date>2021-04-12T16:03:19Z</dc:date>
    <item>
      <title>User management with  Client certificates not working</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/user-management-with-client-certificates-not-working/m-p/397256#M1154</link>
      <description>&lt;P&gt;Hello experts,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are trying to authenticate users connecting to GP via client certs, idea is to revoke client certs and thus prevent users from connecting to GP. Test user is still able to connect after certification has been revoked. Due to some reasons, OCSP has been disabled on the gateway, CRL does not contain revocation status, only delta CRL does, which is not supported by PAN-OS ref (tac case &lt;SPAN&gt;01728222&lt;/SPAN&gt;).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In PANGPS following logs are seen:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;(T532)Info (5289): 02/05/21 15:23:47:711 cert 000001E403ACF4B0 verification result is 0x4 &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;(T532)Info (5292): 02/05/21 15:23:47:711 cert 000001E403ACF4B0 failed revocation verificaiton &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;(T532)Debug(5309): 02/05/21 15:23:47:711 Check certificate revocation returns FALSE&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Questions here are:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1&amp;gt; Does the above logs indicate that the GP agent has detected that the cert is expired or that the revocation check has failed.&lt;/P&gt;&lt;P&gt;2&amp;gt; Will the GP agent do a client cert validation prior to allowing the user to connect. or not.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Apr 2021 16:03:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/user-management-with-client-certificates-not-working/m-p/397256#M1154</guid>
      <dc:creator>ksoni</dc:creator>
      <dc:date>2021-04-12T16:03:19Z</dc:date>
    </item>
    <item>
      <title>Re: User management with  Client certificates not working</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/user-management-with-client-certificates-not-working/m-p/397296#M1155</link>
      <description>&lt;P&gt;Are you utilizing cookies as well and if so what are they set too?&amp;nbsp; It could it be possible that you are using a 24 hour cookie and its using this to authenticate the client (but I'm not 100% sure of this).&amp;nbsp; If you do a manual "Refresh Connections" does it fail to connect after?&lt;/P&gt;</description>
      <pubDate>Mon, 12 Apr 2021 18:10:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/user-management-with-client-certificates-not-working/m-p/397296#M1155</guid>
      <dc:creator>mlinsemier</dc:creator>
      <dc:date>2021-04-12T18:10:47Z</dc:date>
    </item>
  </channel>
</rss>

