<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Wrapped around the axle - iOS + GP + Client Certificate generated on the Palo in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/wrapped-around-the-axle-ios-gp-client-certificate-generated-on/m-p/1260925#M7466</link>
    <description>&lt;P&gt;In the error screen shot above, it doesn't show the error I'm getting. We checked the certificate trust settings on the iPad and it is set to trust the CA of the Palo that issued the client cert, which I've deployed manually (airdrop!) and using Apple Configurator to push the profile.&amp;nbsp; &lt;STRONG&gt;Neither works, and I'm stuck here... Is this just an "Apple thing?"&lt;/STRONG&gt; - I'm starting to see some results around the Apple Developers postings...&amp;nbsp; &lt;U&gt;&lt;EM&gt;Anyone&lt;/EM&gt;&lt;/U&gt; getting IOS devices to work with GP and 2FA?&amp;nbsp; Can't tell me to upgrade - I'm on 12.2.2 and the latest GP 6.3.3-1046.&amp;nbsp; HELP&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Screenshot 2026-08-04 at 10.03.17 AM.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/72191iA3F49CD5D0BA6D22/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2026-08-04 at 10.03.17 AM.png" alt="Screenshot 2026-08-04 at 10.03.17 AM.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 04 Aug 2026 14:12:42 GMT</pubDate>
    <dc:creator>wesprather</dc:creator>
    <dc:date>2026-08-04T14:12:42Z</dc:date>
    <item>
      <title>Wrapped around the axle - iOS + GP + Client Certificate generated on the Palo</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/wrapped-around-the-axle-ios-gp-client-certificate-generated-on/m-p/1260671#M7461</link>
      <description>&lt;P&gt;I’ve got an iPad that has the GlobalProtect client installed. &amp;nbsp;I’ve created self-signed certs using the PA 440 as the CA for the client auth, to enable MFA (user+pass &amp;amp; cert). &amp;nbsp;I get this error &lt;STRONG&gt;“A valid client certificate is required for authentication. &amp;nbsp;If the issue persists, contact your system administrator”.&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I’ve been troubleshooting this for a couple of days. &amp;nbsp;We kept running into pointers to JAMF or Apple Configurator, so I downloaded Apple Configurator and pushed the client certificate and the root CA trust chain, as well as the PA GP client instead of the manual method, *just to see* - and it acts the same way. &amp;nbsp;The iPad device just doesn’t seem to recognize the client certificate and MFA fails. &amp;nbsp;The EXACT same cert works on my MacBook Pro M3 without issue.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="trust settings OK" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/72173i8F4805E62252EE66/image-size/large?v=v2&amp;amp;px=999" role="button" title="IMG_0623.jpeg" alt="trust settings OK" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;trust settings OK&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Valid and trusted client auth certs. OK&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="IMG_0620.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/72168i90EF12CF33B855EB/image-size/large?v=v2&amp;amp;px=999" role="button" title="IMG_0620.png" alt="IMG_0620.png" /&gt;&lt;/span&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="IMG_0619.jpeg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/72167i0D5EE26A7CF1198A/image-size/large?v=v2&amp;amp;px=999" role="button" title="IMG_0619.jpeg" alt="IMG_0619.jpeg" /&gt;&lt;/span&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Profiles in place. OK&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="IMG_0617.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/72170iC35F0AE87C96B417/image-size/large?v=v2&amp;amp;px=999" role="button" title="IMG_0617.png" alt="IMG_0617.png" /&gt;&lt;/span&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Still.. No GO!&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="IMG_0612.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/72169iA2A90BA8483F7789/image-size/large?v=v2&amp;amp;px=999" role="button" title="IMG_0612.png" alt="IMG_0612.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="IMG_0622.jpeg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/72171iDDFF2BD4826018B2/image-size/large?v=v2&amp;amp;px=999" role="button" title="IMG_0622.jpeg" alt="IMG_0622.jpeg" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="IMG_0621.jpeg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/72172i7B1469095DE0B6F5/image-size/large?v=v2&amp;amp;px=999" role="button" title="IMG_0621.jpeg" alt="IMG_0621.jpeg" /&gt;&lt;/span&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 01 Aug 2026 16:32:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/wrapped-around-the-axle-ios-gp-client-certificate-generated-on/m-p/1260671#M7461</guid>
      <dc:creator>wesprather</dc:creator>
      <dc:date>2026-08-01T16:32:52Z</dc:date>
    </item>
    <item>
      <title>Re: Wrapped around the axle - iOS + GP + Client Certificate generated on the Palo</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/wrapped-around-the-axle-ios-gp-client-certificate-generated-on/m-p/1260925#M7466</link>
      <description>&lt;P&gt;In the error screen shot above, it doesn't show the error I'm getting. We checked the certificate trust settings on the iPad and it is set to trust the CA of the Palo that issued the client cert, which I've deployed manually (airdrop!) and using Apple Configurator to push the profile.&amp;nbsp; &lt;STRONG&gt;Neither works, and I'm stuck here... Is this just an "Apple thing?"&lt;/STRONG&gt; - I'm starting to see some results around the Apple Developers postings...&amp;nbsp; &lt;U&gt;&lt;EM&gt;Anyone&lt;/EM&gt;&lt;/U&gt; getting IOS devices to work with GP and 2FA?&amp;nbsp; Can't tell me to upgrade - I'm on 12.2.2 and the latest GP 6.3.3-1046.&amp;nbsp; HELP&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Screenshot 2026-08-04 at 10.03.17 AM.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/72191iA3F49CD5D0BA6D22/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2026-08-04 at 10.03.17 AM.png" alt="Screenshot 2026-08-04 at 10.03.17 AM.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Aug 2026 14:12:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/wrapped-around-the-axle-ios-gp-client-certificate-generated-on/m-p/1260925#M7466</guid>
      <dc:creator>wesprather</dc:creator>
      <dc:date>2026-08-04T14:12:42Z</dc:date>
    </item>
    <item>
      <title>Re: Wrapped around the axle - iOS + GP + Client Certificate generated on the Palo</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/wrapped-around-the-axle-ios-gp-client-certificate-generated-on/m-p/1260938#M7468</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/25626"&gt;@wesprather&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;There are very strict certificate and MDM requirements and the certificates need to be presented as part of a VPN profile, not simply placed on the device. As you've described what you're doing, yes this is an iOS limitation and would be expected with how you appear to be trying to deploy this. It would also explain why you're seeing success with macOS.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Aug 2026 14:38:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/wrapped-around-the-axle-ios-gp-client-certificate-generated-on/m-p/1260938#M7468</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2026-08-04T14:38:40Z</dc:date>
    </item>
    <item>
      <title>Re: Wrapped around the axle - iOS + GP + Client Certificate generated on the Palo</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/wrapped-around-the-axle-ios-gp-client-certificate-generated-on/m-p/1261114#M7478</link>
      <description>&lt;P&gt;Hello.&amp;nbsp; I thought that, too, since I installed the cert manually the 1st time I tested.&amp;nbsp; Then I learned how to push them&amp;nbsp;&lt;STRONG&gt;using Apple Configurator 2.0&lt;/STRONG&gt;&amp;nbsp;&lt;EM&gt;&lt;U&gt;as part of a VPN profile.&lt;/U&gt;&amp;nbsp; &lt;/EM&gt;(see 2,3,4th screen shots in OP).&amp;nbsp; I followed the instructions on the Apple site.&amp;nbsp; I'm still not satisfied with the information that's out there, and I don't have a solution.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Aug 2026 15:36:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/wrapped-around-the-axle-ios-gp-client-certificate-generated-on/m-p/1261114#M7478</guid>
      <dc:creator>wesprather</dc:creator>
      <dc:date>2026-08-05T15:36:47Z</dc:date>
    </item>
  </channel>
</rss>

