<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Global Protect - valid certificate when using Azure SAML authentication in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-valid-certificate-when-using-azure-saml/m-p/445066#M2097</link>
    <description>&lt;P&gt;In logging I can see that&amp;nbsp; SAML authentication via Azure is succeeding. However my GP client is&lt;/P&gt;&lt;P&gt;failing to successfully connect I believe for some deficiency in the certificate. I have a self signed&lt;/P&gt;&lt;P&gt;certificate in a cert profile at the portal and gateway for this GP On Demand setup. Authentication&lt;/P&gt;&lt;P&gt;is set to require certificate *and* user ID/password. (Soon this will be MFA. But first things first.)&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can a self signed certificate serve the need in this case? What properties would need to be&lt;/P&gt;&lt;P&gt;in such a self signed certificate to get GP connect? Thank you.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 02 Nov 2021 20:23:36 GMT</pubDate>
    <dc:creator>MichaelMedwid</dc:creator>
    <dc:date>2021-11-02T20:23:36Z</dc:date>
    <item>
      <title>Global Protect - valid certificate when using Azure SAML authentication</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-valid-certificate-when-using-azure-saml/m-p/445066#M2097</link>
      <description>&lt;P&gt;In logging I can see that&amp;nbsp; SAML authentication via Azure is succeeding. However my GP client is&lt;/P&gt;&lt;P&gt;failing to successfully connect I believe for some deficiency in the certificate. I have a self signed&lt;/P&gt;&lt;P&gt;certificate in a cert profile at the portal and gateway for this GP On Demand setup. Authentication&lt;/P&gt;&lt;P&gt;is set to require certificate *and* user ID/password. (Soon this will be MFA. But first things first.)&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can a self signed certificate serve the need in this case? What properties would need to be&lt;/P&gt;&lt;P&gt;in such a self signed certificate to get GP connect? Thank you.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Nov 2021 20:23:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-valid-certificate-when-using-azure-saml/m-p/445066#M2097</guid>
      <dc:creator>MichaelMedwid</dc:creator>
      <dc:date>2021-11-02T20:23:36Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect - valid certificate when using Azure SAML authentication</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-valid-certificate-when-using-azure-saml/m-p/446049#M2116</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/132469"&gt;@MichaelMedwid&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;First, I would never recommend using a self-signed certificate with GlobalProtect. Either get the certificate issued by your internal CA or have it signed by a public trusted CA. Second, taking away SAML authentication for a second is this an existing working configuration or something you're just trying to get setup?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 07 Nov 2021 15:18:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-valid-certificate-when-using-azure-saml/m-p/446049#M2116</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2021-11-07T15:18:37Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect - valid certificate when using Azure SAML authentication</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-valid-certificate-when-using-azure-saml/m-p/448304#M2157</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/132469"&gt;@MichaelMedwid&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As BPry mentioned, you should get a CA certificate for the GP portal and gateways.&lt;BR /&gt;In addition to that, you need to export the Microsoft Azure Federated SSO Certificate from the Azure Portal and import it to the firewall (Device -&amp;gt; Certificate Management -&amp;gt; Certificates).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The following KB shows how to set up Azure SAML authentication with GlobalProtect, but this export/import certificate step is missing.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;How to setup Azure SAML authentication with GlobalProtect&lt;/STRONG&gt;&lt;BR /&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g0000008U48CAE" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g0000008U48CAE&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You may refer to this KB for the SAML IdP.&lt;BR /&gt;&lt;STRONG&gt;Identity Provider Configuration for SAML&lt;/STRONG&gt;&lt;BR /&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000008UXPCA2" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000008UXPCA2&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps!&lt;/P&gt;</description>
      <pubDate>Thu, 18 Nov 2021 00:58:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-valid-certificate-when-using-azure-saml/m-p/448304#M2157</guid>
      <dc:creator>AnalysisMan</dc:creator>
      <dc:date>2021-11-18T00:58:48Z</dc:date>
    </item>
  </channel>
</rss>

