<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Creating self signed Certificate for IOS device 14 and 15 on Palo Alto firewall in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/creating-self-signed-certificate-for-ios-device-14-and-15-on/m-p/443716#M2078</link>
    <description>&lt;P&gt;Hi Folks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Our GP VPN Portal and Gateway Certificate had expired recently. When we created an new self signed certificate on Palo Alto firewall and mapped it to GP VPN Portal and Gateway.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are able to connect to portal and Gateway and it is working fine for windows and Android device.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But when we try to connect to GP Portal through IOS device we are successfully authenticated into the portal but not able to connect to Gateway.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Checked the GP Logs collected from the Apple IOS Device and could see the Portal authentication is being succeeded and connected. HIP report is also being send by the IOS device but the IOS device is not establishing connectivity to the Gateway and showing the below error:&lt;/P&gt;&lt;DIV&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; {&lt;BR /&gt;&lt;STRONG&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Certificate = "&amp;lt;cert(0x105829a00) s: x.x.x.x i: x.x.x.x&amp;gt;";&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Property = &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; {&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; type = error;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; value = "Policy requirements not met.";&lt;/STRONG&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; };&lt;BR /&gt;&amp;nbsp; &amp;nbsp; }&lt;BR /&gt;)}&lt;BR /&gt;connectTimeout: 5&lt;BR /&gt;receiveTimeout: 30&lt;BR /&gt;responseData(0):&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;P1363-T14087 10/21/2021 18:14:07:926 Debug( 482): error detail is Server cert verification failed&lt;BR /&gt;P1363-T14087 10/21/2021 18:14:07:926 Info ( 305): Session &amp;lt;__NSURLSessionLocal: 0x104c4f2e0&amp;gt; set to (null)&lt;BR /&gt;P1363-T14087 10/21/2021 18:14:07:926 Debug( 331): m_errorDetails is Server cert verification failed&lt;/STRONG&gt;.&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;Checked some documentation and came to know IOS device will only establish connectivity with an server if the certificate met some requirements set by apple.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;&lt;STRONG&gt;GLOBAL PROTECT DOESN'T CONNECT IN IOS 13 AND MACOS 10.15 DUE TO" SERVER CERTIFICATE VERIFICATION FAILED":&lt;/STRONG&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000HB5rCAG" target="_blank" rel="noopener noreferrer"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000HB5rCAG&lt;/A&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;STRONG&gt;Requirements for trusted certificates in iOS 13 and macOS 10.15(Apple Documentation)&lt;BR /&gt;&lt;/STRONG&gt;&lt;A href="https://support.apple.com/en-in/HT210176" target="_blank" rel="noopener noreferrer"&gt;https://support.apple.com/en-in/HT210176&lt;/A&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;EM&gt;&lt;STRONG&gt;Is there any idea on how to create an self signed certificate on Palo Alto firewall that will be compactible with IOS 15 and 14 device certificate requirements ?&lt;/STRONG&gt;&lt;/EM&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Thanks in advance!!&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 27 Oct 2021 08:09:25 GMT</pubDate>
    <dc:creator>tamilvanan</dc:creator>
    <dc:date>2021-10-27T08:09:25Z</dc:date>
    <item>
      <title>Creating self signed Certificate for IOS device 14 and 15 on Palo Alto firewall</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/creating-self-signed-certificate-for-ios-device-14-and-15-on/m-p/443716#M2078</link>
      <description>&lt;P&gt;Hi Folks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Our GP VPN Portal and Gateway Certificate had expired recently. When we created an new self signed certificate on Palo Alto firewall and mapped it to GP VPN Portal and Gateway.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are able to connect to portal and Gateway and it is working fine for windows and Android device.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But when we try to connect to GP Portal through IOS device we are successfully authenticated into the portal but not able to connect to Gateway.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Checked the GP Logs collected from the Apple IOS Device and could see the Portal authentication is being succeeded and connected. HIP report is also being send by the IOS device but the IOS device is not establishing connectivity to the Gateway and showing the below error:&lt;/P&gt;&lt;DIV&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; {&lt;BR /&gt;&lt;STRONG&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Certificate = "&amp;lt;cert(0x105829a00) s: x.x.x.x i: x.x.x.x&amp;gt;";&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Property = &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; {&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; type = error;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; value = "Policy requirements not met.";&lt;/STRONG&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; };&lt;BR /&gt;&amp;nbsp; &amp;nbsp; }&lt;BR /&gt;)}&lt;BR /&gt;connectTimeout: 5&lt;BR /&gt;receiveTimeout: 30&lt;BR /&gt;responseData(0):&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;P1363-T14087 10/21/2021 18:14:07:926 Debug( 482): error detail is Server cert verification failed&lt;BR /&gt;P1363-T14087 10/21/2021 18:14:07:926 Info ( 305): Session &amp;lt;__NSURLSessionLocal: 0x104c4f2e0&amp;gt; set to (null)&lt;BR /&gt;P1363-T14087 10/21/2021 18:14:07:926 Debug( 331): m_errorDetails is Server cert verification failed&lt;/STRONG&gt;.&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;Checked some documentation and came to know IOS device will only establish connectivity with an server if the certificate met some requirements set by apple.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;&lt;STRONG&gt;GLOBAL PROTECT DOESN'T CONNECT IN IOS 13 AND MACOS 10.15 DUE TO" SERVER CERTIFICATE VERIFICATION FAILED":&lt;/STRONG&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000HB5rCAG" target="_blank" rel="noopener noreferrer"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000HB5rCAG&lt;/A&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;STRONG&gt;Requirements for trusted certificates in iOS 13 and macOS 10.15(Apple Documentation)&lt;BR /&gt;&lt;/STRONG&gt;&lt;A href="https://support.apple.com/en-in/HT210176" target="_blank" rel="noopener noreferrer"&gt;https://support.apple.com/en-in/HT210176&lt;/A&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;EM&gt;&lt;STRONG&gt;Is there any idea on how to create an self signed certificate on Palo Alto firewall that will be compactible with IOS 15 and 14 device certificate requirements ?&lt;/STRONG&gt;&lt;/EM&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Thanks in advance!!&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Oct 2021 08:09:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/creating-self-signed-certificate-for-ios-device-14-and-15-on/m-p/443716#M2078</guid>
      <dc:creator>tamilvanan</dc:creator>
      <dc:date>2021-10-27T08:09:25Z</dc:date>
    </item>
    <item>
      <title>Re: Creating self signed Certificate for IOS device 14 and 15 on Palo Alto firewall</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/creating-self-signed-certificate-for-ios-device-14-and-15-on/m-p/443759#M2080</link>
      <description>&lt;P&gt;make sure your self-signed comply with this also:&lt;BR /&gt;&lt;A href="https://support.apple.com/en-us/HT211025" target="_blank" rel="noopener"&gt;https://support.apple.com/en-us/HT211025&lt;/A&gt;&lt;BR /&gt;you can make the self-signed root CA trusted under your IOS device settings:&amp;nbsp;Settings &amp;gt; General &amp;gt; About &amp;gt; Certificate Trust Settings then enable full trust for that CA.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Oct 2021 11:55:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/creating-self-signed-certificate-for-ios-device-14-and-15-on/m-p/443759#M2080</guid>
      <dc:creator>Abdul-Fattah</dc:creator>
      <dc:date>2021-10-27T11:55:48Z</dc:date>
    </item>
    <item>
      <title>Re: Creating self signed Certificate for IOS device 14 and 15 on Palo Alto firewall</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/creating-self-signed-certificate-for-ios-device-14-and-15-on/m-p/454772#M2238</link>
      <description>&lt;P&gt;Ensure that the SSL cert has a SAN (Host Name in Certificate attributes) that matches the CN/FQDN.&amp;nbsp; Make sure the Cert follows Apple's req's, including the validity &amp;lt;=825 days.&amp;nbsp; Add the Root Certificate to the Apple device trust store (you can email yourself the root cert and open it on the iPhone to get it into your trust store via profiles).&amp;nbsp; Then Follow Abdul-Fattah's recommendation to trust the self-signed Root.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Dec 2021 18:54:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/creating-self-signed-certificate-for-ios-device-14-and-15-on/m-p/454772#M2238</guid>
      <dc:creator>darrengayler</dc:creator>
      <dc:date>2021-12-21T18:54:15Z</dc:date>
    </item>
  </channel>
</rss>

