<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic GP client Auth Certification in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/gp-client-auth-certification/m-p/525993#M3550</link>
    <description>&lt;P&gt;Hi Team, Do we need to manually install the Client certificate for the Global Protect Certificate authentication or It will automatically fetch from Portal.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 05 Jan 2023 09:09:46 GMT</pubDate>
    <dc:creator>suba_muthuram</dc:creator>
    <dc:date>2023-01-05T09:09:46Z</dc:date>
    <item>
      <title>GP client Auth Certification</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/gp-client-auth-certification/m-p/525993#M3550</link>
      <description>&lt;P&gt;Hi Team, Do we need to manually install the Client certificate for the Global Protect Certificate authentication or It will automatically fetch from Portal.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jan 2023 09:09:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/gp-client-auth-certification/m-p/525993#M3550</guid>
      <dc:creator>suba_muthuram</dc:creator>
      <dc:date>2023-01-05T09:09:46Z</dc:date>
    </item>
    <item>
      <title>Re: GP client Auth Certification</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/gp-client-auth-certification/m-p/525995#M3552</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/262013"&gt;@suba_muthuram&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Yes, the certificate should be installed. However, it depends on how to want to deploy the certificates. Below is the snippet from the &lt;A href="https://docs.paloaltonetworks.com/content/dam/techdocs/en_US/pdf/globalprotect/10-1/globalprotect-admin/globalprotect-admin.pdf" target="_self"&gt;GlobalProtect Admin-Guide&lt;/A&gt;:&lt;BR /&gt;&lt;BR /&gt;For an agent configuration profile that specifies client certificates, each user receives a client&amp;nbsp;certificate. The mechanism for providing the certificates determines whether a certificate is&amp;nbsp;unique to each user or the same for all users under that agent configuration:&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;• To deploy client certificates that are unique to each user and endpoint, use &lt;STRONG&gt;SCEP&lt;/STRONG&gt;. When a user&amp;nbsp;first logs in, the portal requests a certificate from the enterprise’s PKI. The portal obtains a&amp;nbsp;unique certificate and deploys it to the endpoint.&lt;BR /&gt;• To deploy the same client certificate to all users that receive an agent configuration, deploy a&amp;nbsp;certificate that is Local to the firewall.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jan 2023 09:39:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/gp-client-auth-certification/m-p/525995#M3552</guid>
      <dc:creator>Arnesh</dc:creator>
      <dc:date>2023-01-05T09:39:38Z</dc:date>
    </item>
    <item>
      <title>Re: GP client Auth Certification</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/gp-client-auth-certification/m-p/526005#M3553</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/262013"&gt;@suba_muthuram&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can manually install the certificate or configure the portal to push the certificate to the client.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The portal configuration to push the certificate is found under Network &amp;gt; GlobalProtect &amp;gt; Portals &amp;gt; [edit portal] &amp;gt; Agent &amp;gt; [edit config] &amp;gt; Authentication &amp;gt; Client Certificate.&amp;nbsp; There are 3 options available:&amp;nbsp; Local, SCEP, and None.&amp;nbsp; These are the options described by &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/253055"&gt;@Arnesh&lt;/a&gt; above.&amp;nbsp; Please remember to change this setting back to None once the certificate has been distributed to all of your GP clients.&amp;nbsp; Otherwise, there really is no 2FA with certificates, it is pushed every time.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Manual installation can be done by distributing the certificates to the client devices through other means, the most common is MS GPO combined with MS CA server.&amp;nbsp; As &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/253055"&gt;@Arnesh&lt;/a&gt; described, the certificate can be unique to each user or the same for all users.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jan 2023 14:04:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/gp-client-auth-certification/m-p/526005#M3553</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-01-05T14:04:09Z</dc:date>
    </item>
  </channel>
</rss>

