<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GlobalProtect -Select Certificate Error? in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-select-certificate-error/m-p/545779#M4123</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/297687"&gt;@CheungRJ&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;The user has two matching certificates installed on the device for some reason. Without knowing anything about your environment the only thing we can tell you is that there's now two certificates matching the criteria GlobalProtect is looking for, and that this appears to be non-standard within your environment. Why that user has two nobody here could help you with.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can prevent this by using custom certificates for GlobalProtect with a custom Extended Key Usage OID value specified in the certificate to have GlobalProtect automatically select the proper certificate when multiple certificates are present.&amp;nbsp;&lt;EM&gt;Many&amp;nbsp;&lt;/EM&gt;environments will never configure this as having multiple matching certificates on a single device would be an extreme edge-case scenario and issuing out a dedicated certificate has additional overhead.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 13 Jun 2023 14:30:47 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2023-06-13T14:30:47Z</dc:date>
    <item>
      <title>GlobalProtect -Select Certificate Error?</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-select-certificate-error/m-p/545775#M4121</link>
      <description>&lt;P&gt;Hello, I'm a help desktop tech. I have a user who is asking why he is receiving this error message. I'm not sure myself, can someone explain it to me. Thank you&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="f40b664a87572550179d85d4dabb355f.jpg" style="width: 633px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/50859iBF2E74A8F8CAA457/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="f40b664a87572550179d85d4dabb355f.jpg" alt="f40b664a87572550179d85d4dabb355f.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jun 2023 14:19:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-select-certificate-error/m-p/545775#M4121</guid>
      <dc:creator>CheungRJ</dc:creator>
      <dc:date>2023-06-13T14:19:09Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect -Select Certificate Error?</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-select-certificate-error/m-p/545776#M4122</link>
      <description>&lt;P&gt;Forgot to add, the user had the option to pick between two certificates, usually the user wouldn't have to pick.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jun 2023 14:21:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-select-certificate-error/m-p/545776#M4122</guid>
      <dc:creator>CheungRJ</dc:creator>
      <dc:date>2023-06-13T14:21:07Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect -Select Certificate Error?</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-select-certificate-error/m-p/545779#M4123</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/297687"&gt;@CheungRJ&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;The user has two matching certificates installed on the device for some reason. Without knowing anything about your environment the only thing we can tell you is that there's now two certificates matching the criteria GlobalProtect is looking for, and that this appears to be non-standard within your environment. Why that user has two nobody here could help you with.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can prevent this by using custom certificates for GlobalProtect with a custom Extended Key Usage OID value specified in the certificate to have GlobalProtect automatically select the proper certificate when multiple certificates are present.&amp;nbsp;&lt;EM&gt;Many&amp;nbsp;&lt;/EM&gt;environments will never configure this as having multiple matching certificates on a single device would be an extreme edge-case scenario and issuing out a dedicated certificate has additional overhead.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jun 2023 14:30:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-select-certificate-error/m-p/545779#M4123</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2023-06-13T14:30:47Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect -Select Certificate Error?</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-select-certificate-error/m-p/545829#M4124</link>
      <description>&lt;P&gt;As per BPry but are the certificate cn/subjalt the same.. perhaps you are using this in the GP portal app and GP is also detecting a cert in the computer personal store..&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MickBall_0-1686675941539.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/50870i93B574B1E1ED284C/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="MickBall_0-1686675941539.png" alt="MickBall_0-1686675941539.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jun 2023 17:05:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-select-certificate-error/m-p/545829#M4124</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2023-06-13T17:05:54Z</dc:date>
    </item>
  </channel>
</rss>

