<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Global Protect Portal Client Certificate Authentication - Cert not found in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-portal-client-certificate-authentication-cert-not/m-p/546228#M4137</link>
    <description>&lt;P&gt;How did you export the user cert, did you use PKCS12 with password???&lt;/P&gt;</description>
    <pubDate>Fri, 16 Jun 2023 09:20:10 GMT</pubDate>
    <dc:creator>Mick_Ball</dc:creator>
    <dc:date>2023-06-16T09:20:10Z</dc:date>
    <item>
      <title>Global Protect Portal Client Certificate Authentication - Cert not found</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-portal-client-certificate-authentication-cert-not/m-p/546066#M4127</link>
      <description>&lt;P&gt;I am trying to setup&amp;nbsp;Global Protect Portal authentication using Client Certificate Authentication instead of radius. I generated CA and self signed cert on the palo. Configured Client Cert profile and attached it to Portal -&amp;gt; Authentication (removed Radius auth) and selected Client Cert profile. Also downloaded and installed the Cert and root CA to laptop in Personal cert store.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But when i attempt the GP Connection I keep getting "a valid client certificate is required for authentication".&amp;nbsp; When i switch back to radius it works fine. Confirmed the cert is installed properly as well as the CA in store.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;GP version 5.2.13&lt;/P&gt;
&lt;P&gt;&amp;lt;msg&amp;gt;Valid client certificate is required&amp;lt;/msg&amp;gt;&lt;BR /&gt;&amp;lt;newmsg&amp;gt;Required client certificate not found. Please contact your IT administrator.&amp;lt;/newmsg&amp;gt;&lt;BR /&gt;&amp;lt;authentication-message&amp;gt;&amp;lt;/authentication-message&amp;gt;&lt;/P&gt;
&lt;P&gt;(P6180-T10460)Debug(8440): 06/08/23 13:51:30:278 Set portal status to valid client cert needed.&lt;BR /&gt;(P6180-T10460)Debug(8450): 06/08/23 13:51:30:278 portal status is Client Cert Required.&lt;BR /&gt;(P6180-T10460)Debug(7685): 06/08/23 13:51:30:278 Portal required client certificate is not found.&lt;BR /&gt;(P6180-T10456)Debug(2513): 06/08/23 13:51:30:278 Setting debug level to 5&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;i followed the config from this KB -&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClIICA0" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClIICA0&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jun 2023 19:32:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-portal-client-certificate-authentication-cert-not/m-p/546066#M4127</guid>
      <dc:creator>Chirah_Rana</dc:creator>
      <dc:date>2023-06-14T19:32:32Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect Portal Client Certificate Authentication - Cert not found</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-portal-client-certificate-authentication-cert-not/m-p/546125#M4130</link>
      <description>&lt;P&gt;what setting do you have in the certificate profile as you will need to set a username field...&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MickBall_0-1686833392114.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/50939i38B9ACCBC2975C80/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="MickBall_0-1686833392114.png" alt="MickBall_0-1686833392114.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;also... try to &lt;A href="https://&amp;lt;yourportaladdress&amp;gt;" target="_blank"&gt;https://&amp;lt;yourportaladdress&amp;gt;&lt;/A&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; and see if the certificate is accepted via your browser...&lt;/P&gt;</description>
      <pubDate>Thu, 15 Jun 2023 12:50:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-portal-client-certificate-authentication-cert-not/m-p/546125#M4130</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2023-06-15T12:50:52Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect Portal Client Certificate Authentication - Cert not found</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-portal-client-certificate-authentication-cert-not/m-p/546133#M4131</link>
      <description>&lt;P&gt;For Cert Proifle, I have username Field set to subject. for SSL/TLS - we are using different Certification. for Client auth i generated a local ROOT CA and Client Cert on PA and exported to laptop.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Chirah_Rana_1-1686839318218.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/50941iAB0026E0DF6CBFD1/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Chirah_Rana_1-1686839318218.png" alt="Chirah_Rana_1-1686839318218.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Chirah_Rana_0-1686839255553.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/50940i40C8E9B56BA297E6/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Chirah_Rana_0-1686839255553.png" alt="Chirah_Rana_0-1686839255553.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Jun 2023 14:28:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-portal-client-certificate-authentication-cert-not/m-p/546133#M4131</guid>
      <dc:creator>Chirah_Rana</dc:creator>
      <dc:date>2023-06-15T14:28:55Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect Portal Client Certificate Authentication - Cert not found</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-portal-client-certificate-authentication-cert-not/m-p/546135#M4132</link>
      <description>&lt;P&gt;OK thatt sounds good but where did you put the user certificate, is it in the users personal store.&amp;nbsp; perhaps run certmanager for users to see if the certificate is in here&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MickBall_0-1686839864952.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/50942i07E497C8510FEB29/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="MickBall_0-1686839864952.png" alt="MickBall_0-1686839864952.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Jun 2023 14:37:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-portal-client-certificate-authentication-cert-not/m-p/546135#M4132</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2023-06-15T14:37:56Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect Portal Client Certificate Authentication - Cert not found</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-portal-client-certificate-authentication-cert-not/m-p/546139#M4133</link>
      <description>&lt;P&gt;I confirmed the cert was install in Personal folder of user as shown in your sceenshot. I also added Root CA in trust Root CA.. it seems the Global protect Agent is not able to locate the cert for some reason. because it says cent found. not invalid cert or any other issue.&lt;/P&gt;</description>
      <pubDate>Thu, 15 Jun 2023 14:53:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-portal-client-certificate-authentication-cert-not/m-p/546139#M4133</guid>
      <dc:creator>Chirah_Rana</dc:creator>
      <dc:date>2023-06-15T14:53:58Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect Portal Client Certificate Authentication - Cert not found</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-portal-client-certificate-authentication-cert-not/m-p/546228#M4137</link>
      <description>&lt;P&gt;How did you export the user cert, did you use PKCS12 with password???&lt;/P&gt;</description>
      <pubDate>Fri, 16 Jun 2023 09:20:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-portal-client-certificate-authentication-cert-not/m-p/546228#M4137</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2023-06-16T09:20:10Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect Portal Client Certificate Authentication - Cert not found</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-portal-client-certificate-authentication-cert-not/m-p/546246#M4139</link>
      <description>&lt;P&gt;yes that is correct. pkc12 with password. it imports sucessfully. also added the root ca in trust ca in store.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Jun 2023 13:04:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-portal-client-certificate-authentication-cert-not/m-p/546246#M4139</guid>
      <dc:creator>Chirah_Rana</dc:creator>
      <dc:date>2023-06-16T13:04:35Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect Portal Client Certificate Authentication - Cert not found</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-portal-client-certificate-authentication-cert-not/m-p/546261#M4140</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/272577"&gt;@Chirah_Rana&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Your configuration should work.&amp;nbsp; I have done this many times.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;One thing you can do to test is to push the certificate to the client by configuring the Agent tab in the portal.&amp;nbsp; Change the client certificate to Local, and specify the certificate that you created on the NGFW (not the CA).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="TomYoung_0-1686926829984.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/50958iCE761AD2CC580CDC/image-size/medium?v=v2&amp;amp;px=400" role="button" title="TomYoung_0-1686926829984.png" alt="TomYoung_0-1686926829984.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The portal will then install the certificate on the client.&amp;nbsp; This solution is not permanent because it defeats the purpose of requiring the client certificate.&amp;nbsp; But, you can see if it works and try to find out what changed on your Windows machine.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Jun 2023 14:51:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-portal-client-certificate-authentication-cert-not/m-p/546261#M4140</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-06-16T14:51:54Z</dc:date>
    </item>
  </channel>
</rss>

