<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Global Protect - valid certificate client is required in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-valid-certificate-client-is-required/m-p/527495#M3597</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;all of a sudden at the beginning of this week, our Global protect clietns have been failing with "valid certificate client is required"&lt;/P&gt;
&lt;P&gt;the environment is set for machine cert auth (windows adcs)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;now, to get around this issue we have turned off CRL in the certificate profile, but still at a loss&lt;/P&gt;
&lt;P&gt;tried the latsst version of gp client&lt;/P&gt;
&lt;P&gt;checked ntp&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ps. its the same result on all our firewalls, until we turn off CRL&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;the only thing that might stick, is our issuing ca was patched, then our issues started a few days later.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;the best log ive found so far is "a certificate chain could not be built to a trusted root auth"&lt;/P&gt;
&lt;P&gt;but our chain is valid,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;any ideas what else to do?&lt;/P&gt;</description>
    <pubDate>Wed, 18 Jan 2023 05:34:09 GMT</pubDate>
    <dc:creator>noobynetwork</dc:creator>
    <dc:date>2023-01-18T05:34:09Z</dc:date>
    <item>
      <title>Global Protect - valid certificate client is required</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-valid-certificate-client-is-required/m-p/527495#M3597</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;all of a sudden at the beginning of this week, our Global protect clietns have been failing with "valid certificate client is required"&lt;/P&gt;
&lt;P&gt;the environment is set for machine cert auth (windows adcs)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;now, to get around this issue we have turned off CRL in the certificate profile, but still at a loss&lt;/P&gt;
&lt;P&gt;tried the latsst version of gp client&lt;/P&gt;
&lt;P&gt;checked ntp&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ps. its the same result on all our firewalls, until we turn off CRL&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;the only thing that might stick, is our issuing ca was patched, then our issues started a few days later.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;the best log ive found so far is "a certificate chain could not be built to a trusted root auth"&lt;/P&gt;
&lt;P&gt;but our chain is valid,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;any ideas what else to do?&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jan 2023 05:34:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-valid-certificate-client-is-required/m-p/527495#M3597</guid>
      <dc:creator>noobynetwork</dc:creator>
      <dc:date>2023-01-18T05:34:09Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect - valid certificate client is required</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-valid-certificate-client-is-required/m-p/527545#M3598</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/268318"&gt;@noobynetwork&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;"the only thing that might stick, is our issuing ca was patched, then our issues started a few days later." &lt;BR /&gt;Was your CA renewed around the server patching?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;"now, to get around this issue we have turned off CRL in the certificate profile, but still at a loss"&lt;/P&gt;
&lt;P&gt;"ps. its the same result on all our firewalls, until we turn off CRL"&lt;/P&gt;
&lt;P&gt;I am confused does it work after you disable CRL or still not?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The error message you receive speak for itself - you firewall is not trusting the machine certificate that your user are providing during authentication. However there are couple of reasons this could happen:&lt;/P&gt;
&lt;P&gt;- Machine certificate has expired and it was not renewed automatically. On one of the affected machine check the certificate store and see if the machine certificate that should be used for GP is valid (not expired)&lt;/P&gt;
&lt;P&gt;- Certificate Profile on GP portal/gateway not listing correct CAs. If machine certificate is signed by CA that is not in the Cert profile used by the GP portal/gateway, GP client wouldn't know which client cert to use and wouldn't provide any. Check one of the affected client certs and confirm that the issuing CA is in the cert profile&lt;/P&gt;
&lt;P&gt;- CA certificate was renewed. If you have renewed your CA recently, some of the machines may already have enrolled client certs from the new CA, while some are still cert issued from the old CA. The old and the new CA may have exact same CN, but they are different. In this case you will need to import both CAs to the firewall and use them in the cert profile.&lt;/P&gt;
&lt;P&gt;- RL endpoints listed in the certificate profile are not reachable. You can check this KB, not exactly the same issues, but could give you directions how to confirm if CRL is not reachable &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000oMSlCAM" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000oMSlCAM&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jan 2023 13:36:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-valid-certificate-client-is-required/m-p/527545#M3598</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2023-01-18T13:36:30Z</dc:date>
    </item>
  </channel>
</rss>

