<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Machine Certificate Check/ Not working for me in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/machine-certificate-check-not-working-for-me/m-p/587823#M5384</link>
    <description>&lt;P&gt;This problem was user error, me.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I did not realize I had installed the machinecert in the personal certificate store. That's why it kept on connecting even when I removed the certificates from the computer certificate store. Globalprotect is set on default to check both the user and computer certificate stores. Doh!&lt;/P&gt;</description>
    <pubDate>Thu, 23 May 2024 19:45:41 GMT</pubDate>
    <dc:creator>asiewert</dc:creator>
    <dc:date>2024-05-23T19:45:41Z</dc:date>
    <item>
      <title>Machine Certificate Check/ Not working for me</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/machine-certificate-check-not-working-for-me/m-p/587656#M5378</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Goal:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;When a user connects to the Globalprotect Portal it will authenticate using the LDAP authentication profile, and check for the presence of a certificate on the device.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If the device(in my case I'm only going to use Windows 10 PCs) does not have the certificate, the authentication will fail.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;What I've done so far:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;The LDAP authentication profile works as expected.&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;Created a new RootCA from the firewall, created an IntermediateCA signed by the RootCA, and created a "machinecert" signed by the IntermediateCA&lt;/LI&gt;
&lt;LI&gt;Created a Certificate Profile&amp;nbsp;
&lt;UL&gt;
&lt;LI&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="asiewert_0-1716391538482.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/59989i92378D4D3857FC53/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="asiewert_0-1716391538482.png" alt="asiewert_0-1716391538482.png" /&gt;&lt;/span&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;Within the portal configuration authentication tab, I added the newly created certificate profile. Note that the certificate profile only has the rootca and intermediate certs, not the machinecert.&lt;/LI&gt;
&lt;LI&gt;Under the portal Agent tab, agent config, the settings for save user credentials are set to No and no cookies are used.&lt;/LI&gt;
&lt;LI&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="asiewert_1-1716391699348.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/59990iB9809BE32BF5B9B9/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="asiewert_1-1716391699348.png" alt="asiewert_1-1716391699348.png" /&gt;&lt;/span&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;The problem:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;I can log into globalprotect with or without the certificates installed on my laptop using the settings above.&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;I may be missing something obvious, or completely misconfigured this for what I want.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;I would appreciate some help or guidance on how to correct the config, or change it to meet the goal above. Thank you for your help! Let me know if you guys need further information.&lt;/P&gt;</description>
      <pubDate>Wed, 22 May 2024 15:30:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/machine-certificate-check-not-working-for-me/m-p/587656#M5378</guid>
      <dc:creator>asiewert</dc:creator>
      <dc:date>2024-05-22T15:30:55Z</dc:date>
    </item>
    <item>
      <title>Re: Machine Certificate Check/ Not working for me</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/machine-certificate-check-not-working-for-me/m-p/587757#M5382</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/108558"&gt;@asiewert&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just a quick check, did you by chance "Allow Authentication with User Credentials OR Client Certificate" ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="kiwi_1-1716460105323.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/60011iA1FCF6FB0AC54B86/image-size/medium?v=v2&amp;amp;px=400" role="button" title="kiwi_1-1716460105323.png" alt="kiwi_1-1716460105323.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you select &lt;SPAN class="uicontrol"&gt;No&lt;/SPAN&gt;, users must authenticate to the gateway using both user credentials and client certificates. If you select &lt;SPAN class="uicontrol"&gt;Yes&lt;/SPAN&gt;, users can authenticate to the gateway using either user credentials or client certificates.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps,&lt;/P&gt;
&lt;P&gt;-Kim.&lt;/P&gt;</description>
      <pubDate>Thu, 23 May 2024 10:30:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/machine-certificate-check-not-working-for-me/m-p/587757#M5382</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2024-05-23T10:30:11Z</dc:date>
    </item>
    <item>
      <title>Re: Machine Certificate Check/ Not working for me</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/machine-certificate-check-not-working-for-me/m-p/587814#M5383</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/108558"&gt;@asiewert&lt;/a&gt;&amp;nbsp;,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;if you are looking to use the client/machine certificate for additional authentication to ldap, where have you installed this client/machine certificate? the client/machine certificate will need to be installed on the device requiring remote access. Then a check will be performed to see if this client certificate has been signed by the CAs in your certificate profile.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Try installing the certificate into the "Personal" folder of either the Local Computer or Current User cert store and test authentication again.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/globalprotect/10-1/globalprotect-admin/globalprotect-user-authentication/set-up-client-certificate-authentication/deploy-machine-certificates-for-authentication" target="_blank"&gt;https://docs.paloaltonetworks.com/globalprotect/10-1/globalprotect-admin/globalprotect-user-authentication/set-up-client-certificate-authentication/deploy-machine-certificates-for-authentication&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.youtube.com/watch?v=TFstISND5PE" target="_blank"&gt;https://www.youtube.com/watch?v=TFstISND5PE&lt;/A&gt;&amp;nbsp;(details the creation and export of a client certificate with public/private key pair)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SirchRettop_0-1716486064937.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/60022i2AFADF9765CEB861/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="SirchRettop_0-1716486064937.png" alt="SirchRettop_0-1716486064937.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 May 2024 17:48:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/machine-certificate-check-not-working-for-me/m-p/587814#M5383</guid>
      <dc:creator>SirchRettop</dc:creator>
      <dc:date>2024-05-23T17:48:07Z</dc:date>
    </item>
    <item>
      <title>Re: Machine Certificate Check/ Not working for me</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/machine-certificate-check-not-working-for-me/m-p/587823#M5384</link>
      <description>&lt;P&gt;This problem was user error, me.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I did not realize I had installed the machinecert in the personal certificate store. That's why it kept on connecting even when I removed the certificates from the computer certificate store. Globalprotect is set on default to check both the user and computer certificate stores. Doh!&lt;/P&gt;</description>
      <pubDate>Thu, 23 May 2024 19:45:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/machine-certificate-check-not-working-for-me/m-p/587823#M5384</guid>
      <dc:creator>asiewert</dc:creator>
      <dc:date>2024-05-23T19:45:41Z</dc:date>
    </item>
  </channel>
</rss>

