<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Ubuntu 22.04.1 LTS VPN not able to connect in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/ubuntu-22-04-1-lts-vpn-not-able-to-connect/m-p/527287#M3593</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/257744"&gt;@Sudhir&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;The error message you receive says that your GlobalProtect agent, doesn't trust the SSL server certificate presented by your GP gateway.&lt;/P&gt;
&lt;P&gt;It is very likely you are using self-signed certificate on the FW for the GP gateway. This means that the CA (certificate authority) used to generate the server certificate used by the GP gateway is not public, or at least is not trusted by default by your Ubuntu client.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To be honest I don't have lot of experience with GlobalProtect on Linux (actually non), so I am not sure what certificate store will GP use on Ubuntu. But after little googling , it seems you need to import the CA cert (only the cert, no need for key) that used to create server cert for the GP gateway to the Ubuntu client in the following steps:&lt;/P&gt;
&lt;P&gt;- import the CA in &lt;CODE&gt;/usr/local/share/ca-certificates&lt;/CODE&gt;.&lt;/P&gt;
&lt;P&gt;- execute &lt;CODE&gt;update-ca-certificates&lt;/CODE&gt; (you may need sudo for that)&lt;/P&gt;
&lt;P&gt;- above command should put the imported cert to the /etc/ssl/certs directory.&lt;/P&gt;
&lt;P&gt;After that you can try to reconnect to GlobalProtect&lt;/P&gt;</description>
    <pubDate>Mon, 16 Jan 2023 22:57:27 GMT</pubDate>
    <dc:creator>aleksandar.astardzhiev</dc:creator>
    <dc:date>2023-01-16T22:57:27Z</dc:date>
    <item>
      <title>Ubuntu 22.04.1 LTS VPN not able to connect</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/ubuntu-22-04-1-lts-vpn-not-able-to-connect/m-p/521365#M3431</link>
      <description>&lt;P&gt;I am trying to use Global Protect VPN on my Linux Machine (Ubuntu 22.04.1 LTS).&lt;BR /&gt;&lt;BR /&gt;But whenever I try to connect I get the following error:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MicrosoftTeams-image (8).png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/45361i177CAB37DBB8DC15/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="MicrosoftTeams-image (8).png" alt="MicrosoftTeams-image (8).png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;
&lt;P&gt;I am not able to understand what is the exact issue.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Nov 2022 05:08:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/ubuntu-22-04-1-lts-vpn-not-able-to-connect/m-p/521365#M3431</guid>
      <dc:creator>Sudhir</dc:creator>
      <dc:date>2022-11-16T05:08:44Z</dc:date>
    </item>
    <item>
      <title>Re: Ubuntu 22.04.1 LTS VPN not able to connect</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/ubuntu-22-04-1-lts-vpn-not-able-to-connect/m-p/527287#M3593</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/257744"&gt;@Sudhir&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;The error message you receive says that your GlobalProtect agent, doesn't trust the SSL server certificate presented by your GP gateway.&lt;/P&gt;
&lt;P&gt;It is very likely you are using self-signed certificate on the FW for the GP gateway. This means that the CA (certificate authority) used to generate the server certificate used by the GP gateway is not public, or at least is not trusted by default by your Ubuntu client.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To be honest I don't have lot of experience with GlobalProtect on Linux (actually non), so I am not sure what certificate store will GP use on Ubuntu. But after little googling , it seems you need to import the CA cert (only the cert, no need for key) that used to create server cert for the GP gateway to the Ubuntu client in the following steps:&lt;/P&gt;
&lt;P&gt;- import the CA in &lt;CODE&gt;/usr/local/share/ca-certificates&lt;/CODE&gt;.&lt;/P&gt;
&lt;P&gt;- execute &lt;CODE&gt;update-ca-certificates&lt;/CODE&gt; (you may need sudo for that)&lt;/P&gt;
&lt;P&gt;- above command should put the imported cert to the /etc/ssl/certs directory.&lt;/P&gt;
&lt;P&gt;After that you can try to reconnect to GlobalProtect&lt;/P&gt;</description>
      <pubDate>Mon, 16 Jan 2023 22:57:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/ubuntu-22-04-1-lts-vpn-not-able-to-connect/m-p/527287#M3593</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2023-01-16T22:57:27Z</dc:date>
    </item>
  </channel>
</rss>

