<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Global Protect Google SAML Authentication Failure in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-google-saml-authentication-failure/m-p/593812#M5624</link>
    <description>&lt;P&gt;Okay, after spending a lot of time between Google and PaloAlto I was finally able to resolve my issue. The problem I was running into was unique and may not be what you were experiencing.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;3 factors in tandem created this error. First off, the GP client 6.2.2 does NOT work with SAML authentication through google. Upgrading to 6.2.3 helped resolve my issues. Secondly, I had to create a 2nd certificate for SAML IDP and reconfigure the Authentication profile with the new cert after marking it as it's own CA. Finally, some of my commits had failed and I hadn't known until searching through the logs via CLI. After restarting the firewall's manage service I was able to clear changes stuck in limbo and reapply some of the changes I made.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Again, my issue was pretty unique but I hope this helps you.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 01 Aug 2024 18:15:57 GMT</pubDate>
    <dc:creator>BenjaminRaimondi</dc:creator>
    <dc:date>2024-08-01T18:15:57Z</dc:date>
    <item>
      <title>Global Protect Google SAML Authentication Failure</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-google-saml-authentication-failure/m-p/592311#M5592</link>
      <description>&lt;P&gt;Hello Community,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have been working on changing out our local LDAP authentication to google SAML for our globalprotect login on both our gateway and portal. Authentication for the gateway works as intended but the portal auth refuses to complete. A successful handshake between google and the paloalto is made via the certificate and I can login with any user, but the portal connection fails to complete and a google 403 error (app_not_configured_for_user) appears (attached a screenshot for reference). The service has already been turned on within the google SAML app webpage for all users.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The encoded SAML request and response all match up. ACS and Entity IDs match with no deviations (ie no misplaced uppercase letters).&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If it's any hint, the Test SAML Login option within the Google Admin SAML app page brings me to PaloAltos login page and allows me to use my proper google account, however I am greeted with a Paloalto page that says Authentication Failed (attached screenshot for splash page).&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;TAC said everything looks fine on the firewall side of things. Google support has been contacted but so far they haven't been very useful.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Has anyone else experienced this issue? Any advice would be greatly appreciated.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jul 2024 13:49:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-google-saml-authentication-failure/m-p/592311#M5592</guid>
      <dc:creator>BenjaminRaimondi</dc:creator>
      <dc:date>2024-07-17T13:49:17Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect Google SAML Authentication Failure</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-google-saml-authentication-failure/m-p/592956#M5599</link>
      <description>&lt;P&gt;Hello, We have the same problem. Plase, i would appreciate it if could comment on whether managed to resolve the case.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jul 2024 03:12:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-google-saml-authentication-failure/m-p/592956#M5599</guid>
      <dc:creator>socteamperu</dc:creator>
      <dc:date>2024-07-25T03:12:57Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect Google SAML Authentication Failure</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-google-saml-authentication-failure/m-p/592998#M5602</link>
      <description>&lt;P&gt;Hello Socteamperu,&lt;/P&gt;
&lt;P&gt;According to TAC my issue is on the google side of things. I am still working with Google to get this issue resolved. I will return the results when able.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jul 2024 12:58:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-google-saml-authentication-failure/m-p/592998#M5602</guid>
      <dc:creator>BenjaminRaimondi</dc:creator>
      <dc:date>2024-07-25T12:58:27Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect Google SAML Authentication Failure</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-google-saml-authentication-failure/m-p/593812#M5624</link>
      <description>&lt;P&gt;Okay, after spending a lot of time between Google and PaloAlto I was finally able to resolve my issue. The problem I was running into was unique and may not be what you were experiencing.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;3 factors in tandem created this error. First off, the GP client 6.2.2 does NOT work with SAML authentication through google. Upgrading to 6.2.3 helped resolve my issues. Secondly, I had to create a 2nd certificate for SAML IDP and reconfigure the Authentication profile with the new cert after marking it as it's own CA. Finally, some of my commits had failed and I hadn't known until searching through the logs via CLI. After restarting the firewall's manage service I was able to clear changes stuck in limbo and reapply some of the changes I made.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Again, my issue was pretty unique but I hope this helps you.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Aug 2024 18:15:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-google-saml-authentication-failure/m-p/593812#M5624</guid>
      <dc:creator>BenjaminRaimondi</dc:creator>
      <dc:date>2024-08-01T18:15:57Z</dc:date>
    </item>
  </channel>
</rss>

