<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic GlobalProtect - Renew Certs and Upgrade Clients for remote user in production in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-renew-certs-and-upgrade-clients-for-remote-user-in/m-p/323379#M58</link>
    <description>&lt;P&gt;Current CA and Device Certs need to be renewed. GP client software updated.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can someone tell me how folks are doing this if they need an active GP VPN connection to deploy to the clients in the first place?&amp;nbsp;&lt;/P&gt;&lt;P&gt;We do not use Portal. - and Users cannot install software on devices&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any suggestiosn?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I should make new CA/Device certs (certs are both created on FW) assume I would need new naming conventions?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any tips how to get the new client upgraded - when they are connected using the current client? And do not have perms to do so on their own?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks - and hope everyone is staying safe/healthy&lt;/P&gt;</description>
    <pubDate>Fri, 17 Apr 2020 11:26:21 GMT</pubDate>
    <dc:creator>GreatTest</dc:creator>
    <dc:date>2020-04-17T11:26:21Z</dc:date>
    <item>
      <title>GlobalProtect - Renew Certs and Upgrade Clients for remote user in production</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-renew-certs-and-upgrade-clients-for-remote-user-in/m-p/323379#M58</link>
      <description>&lt;P&gt;Current CA and Device Certs need to be renewed. GP client software updated.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can someone tell me how folks are doing this if they need an active GP VPN connection to deploy to the clients in the first place?&amp;nbsp;&lt;/P&gt;&lt;P&gt;We do not use Portal. - and Users cannot install software on devices&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any suggestiosn?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I should make new CA/Device certs (certs are both created on FW) assume I would need new naming conventions?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any tips how to get the new client upgraded - when they are connected using the current client? And do not have perms to do so on their own?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks - and hope everyone is staying safe/healthy&lt;/P&gt;</description>
      <pubDate>Fri, 17 Apr 2020 11:26:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-renew-certs-and-upgrade-clients-for-remote-user-in/m-p/323379#M58</guid>
      <dc:creator>GreatTest</dc:creator>
      <dc:date>2020-04-17T11:26:21Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect - Renew Certs and Upgrade Clients for remote user in prod</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-renew-certs-and-upgrade-clients-for-remote-user-in/m-p/334200#M218</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;If they are generated on the firewall, then they can be renewed on the firewall, by selecting the certificate and clicking renew at the bottom.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;You can also create new certificates for Root, Intermediate, and server. You will need to change the server certificate in the SSL/TLS profile which is being used for the Portal and Gateway, then the Root and intermediate certificates can be added to the Portal config under Portal --&amp;gt; Agent --&amp;gt; Trusted Root CA, so they're trusted for the GP connection.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;If you wanted the user browser to trust the Root and Intermediate CA certificates alongside GP client, then you can also check the box next to the certificate "Install in Local Root Certificate Store"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Users should have permission to install the Root and Intermediate CAs to their local Trust Root Certificate Store.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;BR /&gt;Let us know if that helps&lt;BR /&gt;&lt;BR /&gt;Thanks and stay safe!&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jun 2020 21:58:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-renew-certs-and-upgrade-clients-for-remote-user-in/m-p/334200#M218</guid>
      <dc:creator>khans</dc:creator>
      <dc:date>2020-06-18T21:58:29Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect - Renew Certs and Upgrade Clients for remote user in prod</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-renew-certs-and-upgrade-clients-for-remote-user-in/m-p/336070#M249</link>
      <description>&lt;P&gt;I created new certs&lt;/P&gt;&lt;P&gt;Deployed over VPN while current/old certs still in use&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;then cutover portal/config to new CA new cert configs&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;all set&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jun 2020 15:48:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-renew-certs-and-upgrade-clients-for-remote-user-in/m-p/336070#M249</guid>
      <dc:creator>GreatTest</dc:creator>
      <dc:date>2020-06-30T15:48:58Z</dc:date>
    </item>
  </channel>
</rss>

