<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Wildcard cert in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/wildcard-cert/m-p/410478#M1370</link>
    <description>&lt;P&gt;I Agree with&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;&amp;nbsp;, there is no way that any public Certificate provider will give you a CA to create certs on their behalf.&amp;nbsp; You could then try to sell their certs and charge for them.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You have to use an Internal CA or allow the firewall to create them for you.&lt;/P&gt;</description>
    <pubDate>Tue, 01 Jun 2021 21:40:01 GMT</pubDate>
    <dc:creator>jdelio</dc:creator>
    <dc:date>2021-06-01T21:40:01Z</dc:date>
    <item>
      <title>Wildcard cert</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/wildcard-cert/m-p/408400#M1310</link>
      <description>&lt;P&gt;I recently setup a backup internet provider and bought a wildcard cert instead of renewing our previous cert. Previously just had a cert for remote.mydomain.com we used for globalprotect from network solutions. I have external DNS A records set for remote.mydomain.com with an ip from our main provider. I also set up an A record for remote2.mydomain.com with an ip from the backup provider. I have not created any automatic failover for GP. I was looking at just manually have GP users change to the secondary portal if our main goes down. I have seen some articles when doing this without a CA but not sure on the exact procedure when using a CA for the wildcart cert. I also have certs generated by the firewall I used as the trusted root cert and SSL decryption certs. I was hoping to use the one wildcard cert for all of these now. I recall having an issue in the past because I believe network solutions also has intermediate certs I needed to account for. Looking for pointers if anyone has been through a setup like this before.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Fri, 21 May 2021 19:12:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/wildcard-cert/m-p/408400#M1310</guid>
      <dc:creator>gvyskocil</dc:creator>
      <dc:date>2021-05-21T19:12:08Z</dc:date>
    </item>
    <item>
      <title>Re: Wildcard cert</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/wildcard-cert/m-p/410477#M1369</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/26025"&gt;@gvyskocil&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The wildcard cert will work perfectly fine for external global protect portals and gateways, but you cannot use this one for SSL decryption. Fo SSL decryption you need a CA certificate and this one you will not get from any public Certificate Authority. So there is no other option than generating one locally or from an internal CA in your company.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Jun 2021 21:36:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/wildcard-cert/m-p/410477#M1369</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2021-06-01T21:36:24Z</dc:date>
    </item>
    <item>
      <title>Re: Wildcard cert</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/wildcard-cert/m-p/410478#M1370</link>
      <description>&lt;P&gt;I Agree with&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;&amp;nbsp;, there is no way that any public Certificate provider will give you a CA to create certs on their behalf.&amp;nbsp; You could then try to sell their certs and charge for them.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You have to use an Internal CA or allow the firewall to create them for you.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Jun 2021 21:40:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/wildcard-cert/m-p/410478#M1370</guid>
      <dc:creator>jdelio</dc:creator>
      <dc:date>2021-06-01T21:40:01Z</dc:date>
    </item>
    <item>
      <title>Re: Wildcard cert</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/wildcard-cert/m-p/410651#M1383</link>
      <description>&lt;P&gt;Thanks for the replies. I guess I was confused on the setup for decryption. For outbound I thought I needed to configure SSL forward proxy and best practice is to use a enterprise CA as forward trust certificate. As both posters noted, that is a internal enterprise CA, not a public one as I though I might use. Or I can just use self signed certificates from the firewall.&amp;nbsp; Then it looks like I need a different certificate for a forward untrust certificate. I will probably just use self signed on both for now. I was getting confused as inbound traffic is part of web traffic but looks like the key is the session itself starts as outgoing. The traffic only starts when an internal user requests an external website and I need to look at that as outbound.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;SSL inbound inspection would be if I have some internal server that people access from outside? For that part can I use the wildcard cert? I have a public cert that server uses for TLS that I am looking at switching to the wildcard cert.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks again for the replies. I think I am getting a better understanding of this now.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Jun 2021 17:23:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/wildcard-cert/m-p/410651#M1383</guid>
      <dc:creator>gvyskocil</dc:creator>
      <dc:date>2021-06-02T17:23:16Z</dc:date>
    </item>
    <item>
      <title>Re: Wildcard cert</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/wildcard-cert/m-p/410653#M1384</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/26025"&gt;@gvyskocil&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes, you're right. For inbound inspection you can use the wildcard certificate.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Jun 2021 17:28:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/wildcard-cert/m-p/410653#M1384</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2021-06-02T17:28:59Z</dc:date>
    </item>
  </channel>
</rss>

