<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GlobalProtect MFA with external/USB user certificate in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-mfa-with-external-usb-user-certificate/m-p/1253391#M7363</link>
    <description>&lt;P&gt;JWil2 - Where is the private key stored? On the usb as well?&amp;nbsp; Services that need to leverage cert based auth need the public key and private key which windows holds in different places on the OS. The internal components in the OS respond to challenges when responding to auth requests. You could use a solution like Yubikey which is USB based but has a TPM which holds the private key material and also has an open interface that holds the public key... all in one chip. This is usually secured with a PIN so when you open a GP session, Windows will prompt you for PIN which is used to access the Yubikey material through the windows driver and then presents the cert to GP and responds to the cert process. I use this and it works well. Does that answer your question?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-Nathan&lt;/P&gt;
&lt;P&gt;-Nathan&lt;/P&gt;</description>
    <pubDate>Fri, 01 May 2026 15:25:58 GMT</pubDate>
    <dc:creator>NSutfin</dc:creator>
    <dc:date>2026-05-01T15:25:58Z</dc:date>
    <item>
      <title>GlobalProtect MFA with external/USB user certificate</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-mfa-with-external-usb-user-certificate/m-p/1253358#M7362</link>
      <description>&lt;P&gt;We are using LDAP for the username/password authentication and I am now trying to set up our GP Portal to use username/password AND a user certificate for MFA.&amp;nbsp; I've seen some documentation that states that the GP Agent will look at the local user and computer store, but is there a way to have it look at an external device?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also, what information needs to be on the certificate?&amp;nbsp; Specifically what is GP looking for?&amp;nbsp; The username as the subject?&amp;nbsp; Should it be the DOMAIN\username?&amp;nbsp; Or just the username?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Apr 2026 18:19:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-mfa-with-external-usb-user-certificate/m-p/1253358#M7362</guid>
      <dc:creator>jwill2</dc:creator>
      <dc:date>2026-04-30T18:19:36Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect MFA with external/USB user certificate</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-mfa-with-external-usb-user-certificate/m-p/1253391#M7363</link>
      <description>&lt;P&gt;JWil2 - Where is the private key stored? On the usb as well?&amp;nbsp; Services that need to leverage cert based auth need the public key and private key which windows holds in different places on the OS. The internal components in the OS respond to challenges when responding to auth requests. You could use a solution like Yubikey which is USB based but has a TPM which holds the private key material and also has an open interface that holds the public key... all in one chip. This is usually secured with a PIN so when you open a GP session, Windows will prompt you for PIN which is used to access the Yubikey material through the windows driver and then presents the cert to GP and responds to the cert process. I use this and it works well. Does that answer your question?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-Nathan&lt;/P&gt;
&lt;P&gt;-Nathan&lt;/P&gt;</description>
      <pubDate>Fri, 01 May 2026 15:25:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-mfa-with-external-usb-user-certificate/m-p/1253391#M7363</guid>
      <dc:creator>NSutfin</dc:creator>
      <dc:date>2026-05-01T15:25:58Z</dc:date>
    </item>
  </channel>
</rss>

