<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GlobalProtect version 3 certificate in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-version-3-certificate/m-p/561393#M4505</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/3296"&gt;@emr_1&lt;/a&gt;&amp;nbsp;Thank you for your reply&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;A number of customers are experiencing the symptom now, and i have checked the certificate based on the information you provided.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;All certificates verified as version3.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Therefore, I believe there is another cause for this problem.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If there is any further confirmation, I will update this ticket.&lt;/P&gt;</description>
    <pubDate>Thu, 12 Oct 2023 07:29:19 GMT</pubDate>
    <dc:creator>KyungjunCHOE</dc:creator>
    <dc:date>2023-10-12T07:29:19Z</dc:date>
    <item>
      <title>GlobalProtect version 3 certificate</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-version-3-certificate/m-p/561370#M4503</link>
      <description>&lt;P&gt;Dear Team,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Among models using Android 13, kernel 5.4 or 5.15, a certificate error appears to occur when connecting to the GP.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I confirmed with TAC that I need to use version 3 certificate.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;However, many customers are using Paloalto's own CA certificate.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there a way to create a v3 certificate in Paloalto?&lt;/P&gt;</description>
      <pubDate>Thu, 12 Oct 2023 04:28:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-version-3-certificate/m-p/561370#M4503</guid>
      <dc:creator>KyungjunCHOE</dc:creator>
      <dc:date>2023-10-12T04:28:20Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect version 3 certificate</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-version-3-certificate/m-p/561382#M4504</link>
      <description>&lt;P&gt;I believe default setting is to generate v3 certificate.&lt;/P&gt;
&lt;P&gt;Here is my test result with PAN-OS 9.1.12&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Image 001.png" style="width: 655px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/54351i1B42E92ED2E3A6D3/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Image 001.png" alt="Image 001.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After export this cert, check with openssl command:&lt;/P&gt;
&lt;P&gt;====&lt;/P&gt;
&lt;P&gt;user@dom:~$ openssl x509 -text -noout -in ./cert_testcert.crt&lt;BR /&gt;Certificate:&lt;BR /&gt;Data:&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;Version: 3 (0x2)&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;Serial Number: 3359397260 (0xc83c558c)&lt;BR /&gt;Signature Algorithm: sha256WithRSAEncryption&lt;BR /&gt;Issuer: CN = testca&lt;BR /&gt;Validity&lt;BR /&gt;Not Before: Oct 12 05:21:15 2023 GMT&lt;BR /&gt;Not After : Oct 11 05:21:15 2024 GMT&lt;BR /&gt;Subject: CN = testcert.local&lt;BR /&gt;Subject Public Key Info:&lt;BR /&gt;Public Key Algorithm: rsaEncryption&lt;BR /&gt;RSA Public-Key: (2048 bit)&lt;BR /&gt;Modulus:&lt;BR /&gt;00:9d:a6:2c:d8:de:f8:2d:4f:5f:f0:cc:3f:0c:da:&lt;BR /&gt;0f:7d:25:fa:03:1b:8c:6e:bd:59:52:9d:24:44:86:&lt;BR /&gt;57:fb:d7:f7:b1:cc:21:44:be:d5:cc:80:fd:4e:e4:&lt;BR /&gt;ca:01:3e:dd:c6:f1:18:8e:46:a2:d7:22:6d:93:35:&lt;/P&gt;
&lt;P&gt;..snip..&lt;/P&gt;
&lt;P&gt;====&lt;/P&gt;</description>
      <pubDate>Thu, 12 Oct 2023 05:31:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-version-3-certificate/m-p/561382#M4504</guid>
      <dc:creator>emr_1</dc:creator>
      <dc:date>2023-10-12T05:31:42Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect version 3 certificate</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-version-3-certificate/m-p/561393#M4505</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/3296"&gt;@emr_1&lt;/a&gt;&amp;nbsp;Thank you for your reply&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;A number of customers are experiencing the symptom now, and i have checked the certificate based on the information you provided.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;All certificates verified as version3.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Therefore, I believe there is another cause for this problem.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If there is any further confirmation, I will update this ticket.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Oct 2023 07:29:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-version-3-certificate/m-p/561393#M4505</guid>
      <dc:creator>KyungjunCHOE</dc:creator>
      <dc:date>2023-10-12T07:29:19Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect version 3 certificate</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-version-3-certificate/m-p/565905#M4630</link>
      <description>&lt;P&gt;Previously, customers could use GP with only a root certificate.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;However, due to the latest security patch in Android, GlobalProtect can no longer be used as a root certificate.&lt;/P&gt;
&lt;P&gt;So please refer to the information below:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;- Symptom: Unable to access GP on some Android 13 models&lt;/P&gt;
&lt;P&gt;- Cause: It is expected that certificate-related security policies have been strengthened and changed on the Android side.&lt;/P&gt;
&lt;P&gt;- Solution: When creating a Paloalto certificate, separate the root cert and server cert according to the recommended guide.&lt;/P&gt;
&lt;P&gt;&amp;gt; Related URL: &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClFoCAK" target="_blank"&gt;Certificate config for GlobalProtect - (SSL/TLS, Client cert pr... - Knowledge Base - Palo Alto Networks&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Nov 2023 02:01:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-version-3-certificate/m-p/565905#M4630</guid>
      <dc:creator>KyungjunCHOE</dc:creator>
      <dc:date>2023-11-16T02:01:30Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect version 3 certificate</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-version-3-certificate/m-p/586594#M5350</link>
      <description>&lt;P&gt;Hello &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/311720"&gt;@KyungjunCHOE&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On android device should we upload the certificate as well to work?&lt;/P&gt;</description>
      <pubDate>Tue, 14 May 2024 06:42:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-version-3-certificate/m-p/586594#M5350</guid>
      <dc:creator>KhaleelE</dc:creator>
      <dc:date>2024-05-14T06:42:50Z</dc:date>
    </item>
  </channel>
</rss>

