<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic globalprotect Client certificate with OID requesting users to select their certificate in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-client-certificate-with-oid-requesting-users-to/m-p/547029#M4164</link>
    <description>&lt;P&gt;I recently configured my globalprotect agent to look for a machine certificate including a specific OID to avoid a confusing selection process on devices with multiple client certificates signed by the same CA. Our original configuration started requesting users to select which certificate to use. I wanted to avoid this confusion by including an OID so globalprotect knew exactly what certificate to use. Unfortunately, the users are still prompted to choose a certificate. However, they are now asked to choose the Intermediate certificate that signs the client cert. I'm wondering if the OID must be applied to the intermediate certificate, or is it possible I'm missing something here?&lt;BR /&gt;&lt;LI-PRODUCT title="GlobalProtect" id="GlobalProtect"&gt;&lt;/LI-PRODUCT&gt; 6.1.1&lt;/P&gt;</description>
    <pubDate>Fri, 23 Jun 2023 15:48:04 GMT</pubDate>
    <dc:creator>KAckerman12</dc:creator>
    <dc:date>2023-06-23T15:48:04Z</dc:date>
    <item>
      <title>globalprotect Client certificate with OID requesting users to select their certificate</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-client-certificate-with-oid-requesting-users-to/m-p/547029#M4164</link>
      <description>&lt;P&gt;I recently configured my globalprotect agent to look for a machine certificate including a specific OID to avoid a confusing selection process on devices with multiple client certificates signed by the same CA. Our original configuration started requesting users to select which certificate to use. I wanted to avoid this confusion by including an OID so globalprotect knew exactly what certificate to use. Unfortunately, the users are still prompted to choose a certificate. However, they are now asked to choose the Intermediate certificate that signs the client cert. I'm wondering if the OID must be applied to the intermediate certificate, or is it possible I'm missing something here?&lt;BR /&gt;&lt;LI-PRODUCT title="GlobalProtect" id="GlobalProtect"&gt;&lt;/LI-PRODUCT&gt; 6.1.1&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jun 2023 15:48:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-client-certificate-with-oid-requesting-users-to/m-p/547029#M4164</guid>
      <dc:creator>KAckerman12</dc:creator>
      <dc:date>2023-06-23T15:48:04Z</dc:date>
    </item>
  </channel>
</rss>

