<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Global Protect Certificate Authentication in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-certificate-authentication/m-p/338575#M285</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/135907"&gt;@trivers01&lt;/a&gt;!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your response,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 15 Jul 2020 04:28:21 GMT</pubDate>
    <dc:creator>L1_ENG</dc:creator>
    <dc:date>2020-07-15T04:28:21Z</dc:date>
    <item>
      <title>Global Protect Certificate Authentication</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-certificate-authentication/m-p/338291#M281</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are using self signed certificate for user authentication signed by self-signed CA cert on Palo Alto for our global protect.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;does my understanding below is correct regarding certificate expiration/renewal.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. if CA cert expired while user cert still valid, user does not need to install renewed CA cert.&lt;/P&gt;&lt;P&gt;we can renew the CA cert on palo alto and user will be able to connect to global protect again.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2. If we renew user certificate (i.e user cert is still valid and we renew for 1 year), user will need to install new renewed certificate.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jul 2020 02:25:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-certificate-authentication/m-p/338291#M281</guid>
      <dc:creator>L1_ENG</dc:creator>
      <dc:date>2020-07-14T02:25:29Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect Certificate Authentication</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-certificate-authentication/m-p/338530#M284</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/121038"&gt;@L1_ENG&lt;/a&gt;&amp;nbsp; I hope all is well!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. If the CA certificate used to sign any intermediate or leaf certificate expires, then each subordinate child ticket will be invalidated also. This is true regardless of the certificate being self-signed form the firewall itself or imported from an internal PKI.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2. If the CA certificate is generated on the firewall, and is renewed on the firewall prior to expiring, then it doesn't require being redeployed to the endpoints, as it will automatically be updated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope this helps with your questions!&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;-Stay safe and have a great day!&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jul 2020 20:26:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-certificate-authentication/m-p/338530#M284</guid>
      <dc:creator>trivers01</dc:creator>
      <dc:date>2020-07-14T20:26:34Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect Certificate Authentication</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-certificate-authentication/m-p/338575#M285</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/135907"&gt;@trivers01&lt;/a&gt;!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your response,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jul 2020 04:28:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-certificate-authentication/m-p/338575#M285</guid>
      <dc:creator>L1_ENG</dc:creator>
      <dc:date>2020-07-15T04:28:21Z</dc:date>
    </item>
  </channel>
</rss>

