<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: certificate  format from CA to clients and GP in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/certificate-format-from-ca-to-clients-and-gp/m-p/350333#M423</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp; Thanks a lot .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any way to check what is the format ?&lt;/P&gt;&lt;P&gt;I believe all certificates are X.509&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;these PKCS or PFX are file format&lt;/P&gt;</description>
    <pubDate>Fri, 18 Sep 2020 06:46:20 GMT</pubDate>
    <dc:creator>FWPalolearner</dc:creator>
    <dc:date>2020-09-18T06:46:20Z</dc:date>
    <item>
      <title>certificate  format from CA to clients and GP</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/certificate-format-from-ca-to-clients-and-gp/m-p/350223#M420</link>
      <description>&lt;P&gt;Hello Team&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Our GP is running with users authenticating via AD account&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now we are rolling out Machine certificate via Group Policy from our Microsoft CA server to all the Domain clients&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and then the goal is to enable certificate check in addition to AD authentication for Global protect corporate users&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My question is when Microsoft CA issues certifciate , in which format they get stored on user machine - PKCS or pfix ; how to check ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do GP support all the formats ?&amp;nbsp; &amp;nbsp; this is important because this is huge rollout of 1000 CLIENTS&lt;/P&gt;</description>
      <pubDate>Thu, 17 Sep 2020 20:46:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/certificate-format-from-ca-to-clients-and-gp/m-p/350223#M420</guid>
      <dc:creator>FWPalolearner</dc:creator>
      <dc:date>2020-09-17T20:46:29Z</dc:date>
    </item>
    <item>
      <title>Re: certificate  format from CA to clients and GP</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/certificate-format-from-ca-to-clients-and-gp/m-p/350290#M422</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/133520"&gt;@FWPalolearner&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;As long as the certificate is imported into the machine store and GlobalProtect is configured to search the machine store this will work perfectly fine. Keep in mind that windows will generally keep anything with a private key in PFX format, but really all PFX means is that it's using PKCS#12. This is really easy to deploy, and as long as you have the certificate in the machine store and the firewall has a properly configured certificate profile assigned it'll "just work".&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The only gotcha that you should keep in mind with this change is that by default the agent option is set to search both the machine and user certificate stores. If you aren't setup to handle users will user certificates, you'll want to ensure that you have the agent configured to look solely at the machine store.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 18 Sep 2020 04:30:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/certificate-format-from-ca-to-clients-and-gp/m-p/350290#M422</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-09-18T04:30:53Z</dc:date>
    </item>
    <item>
      <title>Re: certificate  format from CA to clients and GP</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/certificate-format-from-ca-to-clients-and-gp/m-p/350333#M423</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp; Thanks a lot .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any way to check what is the format ?&lt;/P&gt;&lt;P&gt;I believe all certificates are X.509&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;these PKCS or PFX are file format&lt;/P&gt;</description>
      <pubDate>Fri, 18 Sep 2020 06:46:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/certificate-format-from-ca-to-clients-and-gp/m-p/350333#M423</guid>
      <dc:creator>FWPalolearner</dc:creator>
      <dc:date>2020-09-18T06:46:20Z</dc:date>
    </item>
  </channel>
</rss>

