<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic CRL for Globalprotect in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/crl-for-globalprotect/m-p/532108#M3718</link>
    <description>&lt;P&gt;Hi, greetings.&lt;/P&gt;
&lt;P&gt;Is there a way to use the CLR to verify the machine/user certificate through globalprotect, to drop connections if the certificate is revoked?&lt;/P&gt;</description>
    <pubDate>Thu, 23 Feb 2023 15:37:56 GMT</pubDate>
    <dc:creator>g-crisostomo</dc:creator>
    <dc:date>2023-02-23T15:37:56Z</dc:date>
    <item>
      <title>CRL for Globalprotect</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/crl-for-globalprotect/m-p/532108#M3718</link>
      <description>&lt;P&gt;Hi, greetings.&lt;/P&gt;
&lt;P&gt;Is there a way to use the CLR to verify the machine/user certificate through globalprotect, to drop connections if the certificate is revoked?&lt;/P&gt;</description>
      <pubDate>Thu, 23 Feb 2023 15:37:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/crl-for-globalprotect/m-p/532108#M3718</guid>
      <dc:creator>g-crisostomo</dc:creator>
      <dc:date>2023-02-23T15:37:56Z</dc:date>
    </item>
    <item>
      <title>Re: CRL for Globalprotect</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/crl-for-globalprotect/m-p/532110#M3719</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/230997"&gt;@g-crisostomo&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;GP uses a Certificate Profile to authenticate certificates, and it has a check box to use CRL.&amp;nbsp; Theoretically, the authentication should fail if the certificate is revoked.&amp;nbsp; Please let us know the results if you configure it!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="TomYoung_0-1677167656244.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/48175i9266342CC6149674/image-size/medium?v=v2&amp;amp;px=400" role="button" title="TomYoung_0-1677167656244.png" alt="TomYoung_0-1677167656244.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Thu, 23 Feb 2023 15:56:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/crl-for-globalprotect/m-p/532110#M3719</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-02-23T15:56:25Z</dc:date>
    </item>
    <item>
      <title>Re: CRL for Globalprotect</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/crl-for-globalprotect/m-p/532113#M3722</link>
      <description>&lt;P&gt;I have marked this option, but how can I assure the CRL is being used?&lt;/P&gt;
&lt;P&gt;I added the URL from the certificate to the Default OCSP URL but still I can't see how I can refer to the list.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Feb 2023 16:40:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/crl-for-globalprotect/m-p/532113#M3722</guid>
      <dc:creator>g-crisostomo</dc:creator>
      <dc:date>2023-02-23T16:40:59Z</dc:date>
    </item>
    <item>
      <title>Re: CRL for Globalprotect</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/crl-for-globalprotect/m-p/532115#M3724</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/230997"&gt;@g-crisostomo&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;OCSP is a different protocol.&amp;nbsp; If you check the URL box, for every certificate authentication request the NGFW should check the CRL listed in the CA certificate in &lt;EM&gt;the same&lt;/EM&gt; certificate profile.&amp;nbsp; The best way to check is to revoke a certificate and see if the authentication fails.&amp;nbsp; If traffic from the management interface to the CRL URL goes through the NGFW, you should also see the session in the logs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Thu, 23 Feb 2023 16:47:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/crl-for-globalprotect/m-p/532115#M3724</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-02-23T16:47:44Z</dc:date>
    </item>
    <item>
      <title>Re: CRL for Globalprotect</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/crl-for-globalprotect/m-p/532647#M3736</link>
      <description>&lt;P&gt;Thank you for your help, I guess I found out whats going on; The CRL listed on certificate in the firewall, is different from the user's certificate CRL, because they have 2 servers issuing certificates and they didn't point me this until now.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks once again.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Mar 2023 12:08:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/crl-for-globalprotect/m-p/532647#M3736</guid>
      <dc:creator>g-crisostomo</dc:creator>
      <dc:date>2023-03-01T12:08:13Z</dc:date>
    </item>
  </channel>
</rss>

