<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Global Protect users cant connect - certificate out of date in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-users-cant-connect-certificate-out-of-date/m-p/464852#M2457</link>
    <description>&lt;P&gt;Thanks for the reply - i have got two users to go into site and the server team had to remote onto their laptop and do the following&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Start&lt;/LI&gt;&lt;LI&gt;Manage computer certificates&lt;/LI&gt;&lt;LI&gt;Personal&lt;/LI&gt;&lt;LI&gt;Root certificates&lt;/LI&gt;&lt;LI&gt;… issued by ROOTCA - click on the certificate and renew it&amp;nbsp;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Should this not be an automatic thing that happens once a year.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 10 Feb 2022 11:38:28 GMT</pubDate>
    <dc:creator>Kevin-OHare</dc:creator>
    <dc:date>2022-02-10T11:38:28Z</dc:date>
    <item>
      <title>Global Protect users cant connect - certificate out of date</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-users-cant-connect-certificate-out-of-date/m-p/464617#M2451</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have over 1000 users and just this week some users (maybe 10) have not been able to connect to Global Protect from home.&amp;nbsp; I worked out its because their ROOTCA has expired under Manage Certificates on their laptop.&amp;nbsp; Its been working for 2 years and every user seems to have different dates.&amp;nbsp; As far as i know the certificate server on-prem corporate network is supposed to update their certificate periodically.&amp;nbsp; It must have done this at some stage.&amp;nbsp; I am not getting much response from the server team who look after the certificate server and i know the Global Protect users have routing and a the relevant ports open to connect to the cert server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When a user cant connect he has to drive to the office and connect to the LAN.&amp;nbsp; The the server team issue him a renewed certificate.&amp;nbsp; Then he can go home and connect in again no problems&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How do i prove the palo alto is not the problem&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks, Kevin&lt;/P&gt;</description>
      <pubDate>Wed, 09 Feb 2022 20:21:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-users-cant-connect-certificate-out-of-date/m-p/464617#M2451</guid>
      <dc:creator>Kevin-OHare</dc:creator>
      <dc:date>2022-02-09T20:21:13Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect users cant connect - certificate out of date</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-users-cant-connect-certificate-out-of-date/m-p/464734#M2454</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/167045"&gt;@Kevin-OHare&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Ummm ... that actually sounds like a firewall problem to me. Short of something being very oddly configured in Group Policy, I can't see how this isn't an issue with communication between the GlobalProtect clients and your PKI hosts. Sadly you would need your server team to review Group Policy and the PKI server if you don't have access to either, but if its working when a client is on-site it should be working over the GlobalProtect connection.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Feb 2022 03:56:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-users-cant-connect-certificate-out-of-date/m-p/464734#M2454</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2022-02-10T03:56:21Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect users cant connect - certificate out of date</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-users-cant-connect-certificate-out-of-date/m-p/464852#M2457</link>
      <description>&lt;P&gt;Thanks for the reply - i have got two users to go into site and the server team had to remote onto their laptop and do the following&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Start&lt;/LI&gt;&lt;LI&gt;Manage computer certificates&lt;/LI&gt;&lt;LI&gt;Personal&lt;/LI&gt;&lt;LI&gt;Root certificates&lt;/LI&gt;&lt;LI&gt;… issued by ROOTCA - click on the certificate and renew it&amp;nbsp;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Should this not be an automatic thing that happens once a year.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Feb 2022 11:38:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-users-cant-connect-certificate-out-of-date/m-p/464852#M2457</guid>
      <dc:creator>Kevin-OHare</dc:creator>
      <dc:date>2022-02-10T11:38:28Z</dc:date>
    </item>
  </channel>
</rss>

