<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: User-id with GP client certificate authentication in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/user-id-with-gp-client-certificate-authentication/m-p/1235457#M6959</link>
    <description>&lt;P&gt;1) Yes&lt;/P&gt;
&lt;P&gt;2) You'll need an internal gateway&lt;/P&gt;
&lt;P&gt;3) You're correct that the certificate will need a unique user attribute on it. We used the email field in the certificate SAN to populate the email address and extract the userid from there. On the internal gateway, you can select configure the certificate profile to pull that info from the certificate.&lt;/P&gt;</description>
    <pubDate>Tue, 05 Aug 2025 12:35:08 GMT</pubDate>
    <dc:creator>sk_display</dc:creator>
    <dc:date>2025-08-05T12:35:08Z</dc:date>
    <item>
      <title>User-id with GP client certificate authentication</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/user-id-with-gp-client-certificate-authentication/m-p/1234978#M6934</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have questions regarding user-id operation with GP client certificate authentication only for iOS/Android devices.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Current state:&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;We have GlobalProtect portal and external gateway on the same firewall with &lt;U&gt;SAML authentication&lt;/U&gt; for mobile devices - iOS (on-demand, but &lt;EM&gt;enforcement to use VPN is achieved with proxy file) and &lt;/EM&gt;Chrombook (always-on)&lt;/LI&gt;&lt;LI&gt;IHD (Internal Host Detection) is not used hence mobile devices are always tunnelled to the external gateway even they are on the internal network.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Target state:&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Reconfigure GlobalProtect with a unique &lt;U&gt;client certificate profile for authentication&lt;/U&gt; without other authentication methods. (Remove SAML authentication)&lt;/LI&gt;&lt;LI&gt;Configure Certificate profile with username field of Subject (common-name)&lt;/LI&gt;&lt;LI&gt;Change App connection method to always-on for iOS devices.&lt;/LI&gt;&lt;LI&gt;Enable IHD(Internal Host Detection) to make clients on internal network won’t be tunnelled.&lt;/LI&gt;&lt;LI&gt;Create new GP internal gateway without establishing a VPN tunnel to the firewall &amp;nbsp;to collect user-id information&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Questions:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;1) For devices on the internal network, is an internal GlobalProtect gateway required to report User-ID information to the firewall?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2) If we switch to client certificate-only authentication (no user credentials), will the GlobalProtect gateways still report User-ID mappings?&lt;BR /&gt;I assume the gateways extract the username from the certificate’s Subject (e.g., CN), so this should still work — can you confirm?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;3) For accurate User-ID mapping, should we use user certificates rather than machine certificates?&lt;/P&gt;&lt;P&gt;Machine certificates contain the device name or host FQDN in the subject. So I assume firewall may end up mapping the IP to a device name, not the user which is not expected.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jul 2025 04:38:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/user-id-with-gp-client-certificate-authentication/m-p/1234978#M6934</guid>
      <dc:creator>ahwang2929</dc:creator>
      <dc:date>2025-07-30T04:38:19Z</dc:date>
    </item>
    <item>
      <title>Re: User-id with GP client certificate authentication</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/user-id-with-gp-client-certificate-authentication/m-p/1235457#M6959</link>
      <description>&lt;P&gt;1) Yes&lt;/P&gt;
&lt;P&gt;2) You'll need an internal gateway&lt;/P&gt;
&lt;P&gt;3) You're correct that the certificate will need a unique user attribute on it. We used the email field in the certificate SAN to populate the email address and extract the userid from there. On the internal gateway, you can select configure the certificate profile to pull that info from the certificate.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Aug 2025 12:35:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/user-id-with-gp-client-certificate-authentication/m-p/1235457#M6959</guid>
      <dc:creator>sk_display</dc:creator>
      <dc:date>2025-08-05T12:35:08Z</dc:date>
    </item>
  </channel>
</rss>

