<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GlobalProtect Required client certificate not found - Export-Import certificate(s) in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-required-client-certificate-not-found-export/m-p/384732#M904</link>
    <description>&lt;P&gt;The certificate cannot be used from the “other people” store.&lt;/P&gt;&lt;P&gt;The cert needs to be in personal or machine store.&lt;/P&gt;&lt;P&gt;&lt;FONT color="#339966"&gt;&amp;gt;&amp;gt;&amp;gt;How I transfer from "other people" to "personal"?&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;where exactly are you getting that cert from and how was that cert originally imported.&lt;/P&gt;&lt;P&gt;&lt;FONT color="#339966"&gt;&amp;gt;&amp;gt;&amp;gt;The certificates should come from a central place (I do not know). They should be "downloaded automatically", as our support says.&lt;BR /&gt;Just one day, GlobalProtect started to show the error (see the topic).&lt;BR /&gt;The second device was created recently, after the first device stopped to connect due to the error with certificates.&lt;BR /&gt;Actually, I tried to export/import them from a new device. No success.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;it sounds like it may have been a cert for a specific domain member, if so then you will struggle with export/import.&lt;/P&gt;&lt;P&gt;&lt;FONT color="#339966"&gt;&amp;gt;&amp;gt;&amp;gt;My question is can we export/import the certificates? Yes, it is&amp;nbsp;&lt;SPAN&gt;cert for a specific domain member.&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;mmc can be run from command prompt. Select certificates and then local. &amp;nbsp; You can perform various tasks via right click but you will still be limited to what you can do with an intended user certificate.&lt;/P&gt;&lt;P&gt;&lt;FONT color="#339966"&gt;&amp;gt;&amp;gt;&amp;gt;What I do with mmc?&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 09 Feb 2021 10:32:02 GMT</pubDate>
    <dc:creator>mark236</dc:creator>
    <dc:date>2021-02-09T10:32:02Z</dc:date>
    <item>
      <title>GlobalProtect Required client certificate not found - Export-Import certificate(s)</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-required-client-certificate-not-found-export/m-p/384384#M893</link>
      <description>&lt;P&gt;Windows 10 (1909)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;GlobalProtect stopped working with error message "ConnectionFailed: Required client certificate not found".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Our IT Administrator is unable to solve it, sorry.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please help.&lt;/P&gt;&lt;P&gt;I have another Windows 10 laptop, that have certificates and GlobalProtect works fine.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Feb 2021 00:48:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-required-client-certificate-not-found-export/m-p/384384#M893</guid>
      <dc:creator>mark236</dc:creator>
      <dc:date>2021-02-08T00:48:34Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Required client certificate not found - Export-Import certificate(s)</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-required-client-certificate-not-found-export/m-p/384387#M894</link>
      <description>&lt;P&gt;Dump&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;02/08/21 10:25:42:262 CaptivePortalDetectionThread: IsDetectingCaptivePortal=0, PreLoginIsDone=1&lt;BR /&gt;(T15364)Debug(5016): 02/08/21 10:25:42:262 CaptivePortalDetectionThread: wait (-1 ms) for captive portal detection event.&lt;BR /&gt;(T15632)Info ( 502): 02/08/21 10:26:06:975 msgtype = setdebug&lt;BR /&gt;(T15632)Info (1640): 02/08/21 10:26:06:975 Setting debug level to 6&lt;BR /&gt;(T15632)Dump (11128): 02/08/21 10:26:06:975 Set m_bPreviousSwitchOffMsg to 0&lt;BR /&gt;(T15628)Debug(2381): 02/08/21 10:26:06:975 Setting debug level to 6&lt;BR /&gt;(T15632)Dump ( 312): 02/08/21 10:26:10:899 Recv len is 1008&lt;BR /&gt;(T15632)Info ( 502): 02/08/21 10:26:10:899 msgtype = portal&lt;BR /&gt;(T15632)Debug(2234): 02/08/21 10:26:10:899 ----portal processing starts----&lt;BR /&gt;(T15632)Debug(2262): 02/08/21 10:26:10:899 User profile type is 0(not roaming)&lt;BR /&gt;(T15632)Debug(2295): 02/08/21 10:26:10:899 pg, source = 0, old source is 0&lt;BR /&gt;(T15632)Debug(2317): 02/08/21 10:26:10:899 pg, preferred gateway not set in message, old prefergateway=:)&lt;BR /&gt;(T15632)Dump (2370): 02/08/21 10:26:10:899 checkupdate tag exists with value no&lt;BR /&gt;(T15632)Debug(2374): 02/08/21 10:26:10:899 CheckUpdate is false.&lt;BR /&gt;)(T15632)Debug(2389): 02/08/21 10:26:10:899 portal-certificate-verification is yes&lt;BR /&gt;(T15632)Dump (2399): 02/08/21 10:26:10:899 m_bVerifyPortalCertificate and m_bAdditionalCheck are true.&lt;BR /&gt;)(T15632)Debug(2429): 02/08/21 10:26:10:899 No saml-load-cache tag.&lt;BR /&gt;(T15632)Debug(2452): 02/08/21 10:26:10:899 no saml-auth-error tag.&lt;BR /&gt;(T15632)Debug(2465): 02/08/21 10:26:10:899 allow-cached-portal is yes&lt;BR /&gt;(T15632)Dump (2504): 02/08/21 10:26:10:899 This portal message is not from prelogon thread&lt;BR /&gt;(T15632)Debug(2509): 02/08/21 10:26:10:899 NewWinUser is MINDLINM, WinUser is , PreviousSwitchOffMsg is false&lt;BR /&gt;(T15632)Debug(2510): 02/08/21 10:26:10:899 GetPrelogonStatus() 0, m_userName ___empty_username___, m_preUsername&lt;BR /&gt;(T15632)Debug(3268): 02/08/21 10:26:10:899 Grace period is 0&lt;BR /&gt;(T15632)Debug(6522): 02/08/21 10:26:10:899 StopThreads starts:&lt;BR /&gt;(T15632)Debug(6529): 02/08/21 10:26:10:899 There are 5 threads running...&lt;BR /&gt;(T16228)Debug(5852): 02/08/21 10:26:10:899 HipReportThread: got exit event.&lt;BR /&gt;(T15632)Debug(1384): 02/08/21 10:26:10:899 Logging out gateway, reason is StopThreads&lt;BR /&gt;(T16228)Debug(6151): 02/08/21 10:26:10:899 HipReportThread: HipReportThread quits.&lt;BR /&gt;(T15632)Debug(1423): 02/08/21 10:26:10:899 Logging out gateway over&lt;BR /&gt;(T10160)Debug(6293): 02/08/21 10:26:10:899 NetworkConnectionMonitorThread: got exit event.&lt;BR /&gt;(T15632)Debug(6539): 02/08/21 10:26:10:899 Going to wait all threads exit...&lt;BR /&gt;(T16204)Debug(5268): 02/08/21 10:26:10:899 NetworkDiscoverThread: got exit event.&lt;BR /&gt;(T3456)Debug(4818): 02/08/21 10:26:10:899 NotificationTimerThread: got exit event.&lt;BR /&gt;(T16204)Debug(5719): 02/08/21 10:26:10:899 NetworkDiscoverThread: quits.&lt;BR /&gt;(T10160)Debug(6308): 02/08/21 10:26:10:899 NetworkConnectionMonitorThread: quits.&lt;BR /&gt;(T15364)Debug(5019): 02/08/21 10:26:10:899 CaptivePortalDetectionThread: got exit event.&lt;BR /&gt;(T15364)Debug(5183): 02/08/21 10:26:10:899 CaptivePortalDetectionThread: captive portal detection thread exit status is (failed).&lt;BR /&gt;(T15632)Debug(6543): 02/08/21 10:26:11:008 threads are gracefully stopped, counter=599.&lt;BR /&gt;(T15632)Debug(6556): 02/08/21 10:26:11:008 Double check all threads.&lt;BR /&gt;(T15632)Debug(6602): 02/08/21 10:26:11:008 To reset thread quit event.&lt;BR /&gt;(T15852)Debug( 435): 02/08/21 10:26:11:008 HipMissingPatchThread: got thread exit event.&lt;BR /&gt;(T2488)Debug( 242): 02/08/21 10:26:11:008 HipCheckThread: got thread exit event.&lt;BR /&gt;(T14148)Debug( 418): 02/08/21 10:26:11:008 HipMonitor gets quit event.&lt;BR /&gt;(T14148)Debug( 435): 02/08/21 10:26:11:008 Unregister -- WscUnRegisterChanges&lt;BR /&gt;(T14148)Debug( 763): 02/08/21 10:26:11:024 HipMonitorThread quits.&lt;BR /&gt;(T2488)Debug( 287): 02/08/21 10:26:11:024 HipCheckThread: Hip check thread quits.&lt;BR /&gt;(T15852)Debug( 533): 02/08/21 10:26:11:039 HipMissingPatchThread: Hip check missiing patch thread quits.&lt;BR /&gt;(T15632)Debug( 132): 02/08/21 10:26:11:039 All hip collect threads quit gracefully.&lt;BR /&gt;(T15632)Debug(6612): 02/08/21 10:26:11:039 StopThreads ends.&lt;BR /&gt;(T15632)Dump (2526): 02/08/21 10:26:11:039 Clear lastErrStr&lt;BR /&gt;(T15632)Dump (4358): 02/08/21 10:26:11:039 Set registry LastErrorString as&lt;BR /&gt;(T15632)Debug(6486): 02/08/21 10:26:11:039 StartThreads starts:&lt;BR /&gt;(T15628)Debug(2381): 02/08/21 10:26:11:039 Setting debug level to 6&lt;BR /&gt;(T15632)Debug( 25): 02/08/21 10:26:11:039 create thread 0x6d8 with thread ID 13716&lt;BR /&gt;(T13716)Debug(4661): 02/08/21 10:26:11:039 NotificationTimerThread: notification timer thread starts.&lt;BR /&gt;(T13716)Debug(4811): 02/08/21 10:26:11:039 NotificationTimerThread: wait (-1 ms) for notification timer event.&lt;BR /&gt;(T15632)Debug( 25): 02/08/21 10:26:11:039 create thread 0x6e0 with thread ID 11188&lt;BR /&gt;(T11188)Debug(4857): 02/08/21 10:26:11:039 CaptivePortalDetectionThread: captive portal detection thread starts.&lt;BR /&gt;(T11188)Debug(5016): 02/08/21 10:26:11:039 CaptivePortalDetectionThread: wait (-1 ms) for captive portal detection event.&lt;BR /&gt;(T15632)Debug( 25): 02/08/21 10:26:11:039 create thread 0x6dc with thread ID 7904&lt;BR /&gt;(T7904)Debug(5193): 02/08/21 10:26:11:039 NetworkDiscoverThread: network discover thread starts.&lt;BR /&gt;(T7904)Debug(5258): 02/08/21 10:26:11:039 NetworkDiscoverThread: wait for network discover event.&lt;BR /&gt;(T15632)Debug( 25): 02/08/21 10:26:11:039 create thread 0x6d4 with thread ID 15744&lt;BR /&gt;(T15744)Debug(5811): 02/08/21 10:26:11:039 HipReportThread: HipReportThread starts up.&lt;BR /&gt;(T15744)Debug(5844): 02/08/21 10:26:11:039 HipReportThread: wait for HIP report ready event.&lt;BR /&gt;(T15632)Debug( 25): 02/08/21 10:26:11:039 create thread 0x698 with thread ID 15876&lt;BR /&gt;(T15876)Debug(6159): 02/08/21 10:26:11:039 NetworkConnectionMonitorThread: network connection monitor thread starts.&lt;BR /&gt;(T15632)Debug( 25): 02/08/21 10:26:11:039 create thread 0x554 with thread ID 15872&lt;BR /&gt;(T15872)Debug( 167): 02/08/21 10:26:11:039 Start HipCheckThread&lt;BR /&gt;(T15872)Debug( 210): 02/08/21 10:26:11:039 HipCheckThread started...&lt;BR /&gt;(T15872)Debug( 216): 02/08/21 10:26:11:039 HipCheckThread: wait for hip check event for 3600000 ms);&lt;BR /&gt;(T15872)Dump ( 231): 02/08/21 10:26:11:039 HipCheckThread WinUWP: wait for hip check event for 60000 ms;&lt;BR /&gt;(T15632)Debug( 25): 02/08/21 10:26:11:039 create thread 0x528 with thread ID 15856&lt;BR /&gt;(T15856)Debug( 176): 02/08/21 10:26:11:039 Start HipMissingPatchThread&lt;BR /&gt;(T15856)Debug( 409): 02/08/21 10:26:11:039 HipMissingPatchThread started...&lt;BR /&gt;(T15632)Debug( 25): 02/08/21 10:26:11:039 create thread 0x6ec with thread ID 2516&lt;BR /&gt;(T2516)Debug( 186): 02/08/21 10:26:11:039 Start HipMonitorThread&lt;BR /&gt;(T2516)Info ( 759): 02/08/21 10:26:11:039 HipMonitorThread starts&lt;BR /&gt;(T2516)Dump ( 397): 02/08/21 10:26:11:039 Wscapi.dll is loaded.&lt;BR /&gt;(T15632)Dump (12252): 02/08/21 10:26:11:039 CPanMSServiceWin::UpdateDisableGPSetting() - bDisabled=0.&lt;BR /&gt;(T2516)Dump ( 411): 02/08/21 10:26:11:039 Register -- WscRegisterForChanges&lt;BR /&gt;(T15632)Dump (2592): 02/08/21 10:26:11:039 pid is 11068&lt;BR /&gt;(T15632)Dump ( 218): 02/08/21 10:26:11:039 pid of PanGPA is 11068, m_dwPanGpAgentPid is 11068&lt;BR /&gt;(T15632)Debug(2630): 02/08/21 10:26:11:039 No user, using SSO&lt;BR /&gt;(T15632)Debug(10290): 02/08/21 10:26:11:039 Saved password is empty.&lt;BR /&gt;(T15632)Debug(2690): 02/08/21 10:26:11:039 Portal vpn.csinfra.nsw.gov.au, user , logonDomain GOVNET, saved user , path C:\Users\MINDLINM\AppData\Local\Palo Alto Networks\GlobalProtect\&lt;BR /&gt;(T15632)Debug(2756): 02/08/21 10:26:11:039 use proxy is 1&lt;BR /&gt;(T15632)Debug(2814): 02/08/21 10:26:11:039 Pre-logon-then-on-demand value is no&lt;BR /&gt;(T15632)Debug(1500): 02/08/21 10:26:11:039 SSO starts.&lt;BR /&gt;(T15632)Info (1529): 02/08/21 10:26:11:039 SSO ----- PanCredGet failed with error Element not found.&lt;BR /&gt;(T15632)Debug(1540): 02/08/21 10:26:11:039 SSO GetSsoCredential starts.&lt;BR /&gt;(T15632)Info (1570): 02/08/21 10:26:11:039 SSO ----- PanCredGet failed with error Element not found.&lt;/P&gt;&lt;P&gt;(T15632)Debug(10307): 02/08/21 10:26:11:039 SSO password is empty&lt;BR /&gt;(T15632)Debug(2920): 02/08/21 10:26:11:039 Empty username&lt;BR /&gt;(T15632)Dump (2938): 02/08/21 10:26:11:039 empty domain name.&lt;BR /&gt;(T15632)Debug(2952): 02/08/21 10:26:11:039 m_preUsername ___empty_username___&lt;BR /&gt;(T15632)Debug(10267): 02/08/21 10:26:11:039 Password is empty.&lt;BR /&gt;(T15632)Debug(7634): 02/08/21 10:26:11:039 Empty user for GetCachedPortalCfgOldNewFileName&lt;BR /&gt;(T15632)Debug(2973): 02/08/21 10:26:11:039 CheckCachedPortalForPrelogon 0, PrelogonNeedTimeout 0, RenameTimeout -1, userName ___empty_username___, preUsername ___empty_username___&lt;BR /&gt;(T15632)Debug(3135): 02/08/21 10:26:11:039 Use ssl tunnel is no&lt;BR /&gt;(T15632)Debug(3145): 02/08/21 10:26:11:039 bCheckCachedPortalForPrelogon: 0, m_bOnDemand: 0&lt;BR /&gt;(T15632)Debug(6645): 02/08/21 10:26:11:039 --Set state to Retrieving configuration...&lt;BR /&gt;(T15632)Dump ( 865): 02/08/21 10:26:11:039 status is Disconnected&lt;BR /&gt;(T15632)Dump ( 905): 02/08/21 10:26:11:039 stats.b_connected is 0, GetBestGateway is NULL.&lt;BR /&gt;(T15632)Debug(1964): 02/08/21 10:26:11:039 unknown network type.&lt;BR /&gt;(T15632)Debug(1057): 02/08/21 10:26:11:039 Display hip report V4 on the UI&lt;BR /&gt;(T15632)Dump (6394): 02/08/21 10:26:11:039&lt;BR /&gt;ResponseToClient.txt_output: &amp;lt;?xml version="1.0" encoding="UTF-8"?&amp;gt;&lt;BR /&gt;&amp;lt;response&amp;gt;&lt;BR /&gt;&amp;lt;type&amp;gt;status&amp;lt;/type&amp;gt;&lt;BR /&gt;&amp;lt;status&amp;gt;Disconnected&amp;lt;/status&amp;gt;&lt;BR /&gt;&amp;lt;protocol/&amp;gt;&lt;BR /&gt;&amp;lt;portal-config-version&amp;gt;0&amp;lt;/portal-config-version&amp;gt;&lt;BR /&gt;&amp;lt;error-must-show/&amp;gt;&lt;BR /&gt;&amp;lt;error-must-show-level&amp;gt;error&amp;lt;/error-must-show-level&amp;gt;&lt;BR /&gt;&amp;lt;error/&amp;gt;&lt;BR /&gt;&amp;lt;product-version&amp;gt;5.2.4-21&amp;lt;/product-version&amp;gt;&lt;BR /&gt;&amp;lt;product-code&amp;gt;&amp;amp;quot;{717E7B2D-F4DF-4707-8024-E346F2E64F4F}&amp;amp;quot;&amp;lt;/product-code&amp;gt;&lt;BR /&gt;&amp;lt;portal-status&amp;gt;Client Cert Required&amp;lt;/portal-status&amp;gt;&lt;BR /&gt;&amp;lt;user-name/&amp;gt;&lt;BR /&gt;&amp;lt;username-type&amp;gt;sso&amp;lt;/username-type&amp;gt;&lt;BR /&gt;&amp;lt;state&amp;gt;Retrieving configuration...&amp;lt;/state&amp;gt;&lt;BR /&gt;&amp;lt;check-version&amp;gt;no&amp;lt;/check-version&amp;gt;&lt;BR /&gt;&amp;lt;portal&amp;gt;vpn.csinfra.nsw.gov.au&amp;lt;/portal&amp;gt;&lt;BR /&gt;&amp;lt;discover-ready&amp;gt;no&amp;lt;/discover-ready&amp;gt;&lt;BR /&gt;&amp;lt;mdm-is-enabled&amp;gt;no&amp;lt;/mdm-is-enabled&amp;gt;&lt;BR /&gt;&amp;lt;/response&amp;gt;&lt;/P&gt;&lt;P&gt;(T15632)Dump (1603): 02/08/21 10:26:11:039 Send response to client for request status&lt;BR /&gt;(T15632)Dump (7183): 02/08/21 10:26:11:039 ServerThread: ProcessServerPortal -- GetConfigFromPortal&lt;BR /&gt;(T15632)Dump (3472): 02/08/21 10:26:11:039 Machine's device id is dbd72264-fbb9-4aab-9b99-ce2e9146660e&lt;BR /&gt;(T15632)Dump ( 162): 02/08/21 10:26:11:039 CPanRegKey GetValueString subKey is Software\Palo Alto Networks\GlobalProtect\Settings\pre-vpn-connect, value name is command&lt;BR /&gt;(T2516)Debug( 413): 02/08/21 10:26:11:039 HipMonitorThread wait for exit event.&lt;BR /&gt;(T2516)Dump ( 415): 02/08/21 10:26:11:039 before WaitForMultipleObjects&lt;BR /&gt;(T15632)Dump ( 162): 02/08/21 10:26:11:039 CPanRegKey GetValueString subKey is Software\Palo Alto Networks\GlobalProtect\Settings\pre-vpn-connect, value name is context&lt;BR /&gt;(T15632)Dump ( 162): 02/08/21 10:26:11:039 CPanRegKey GetValueString subKey is Software\Palo Alto Networks\GlobalProtect\Settings\pre-vpn-connect, value name is timeout&lt;BR /&gt;(T15632)Dump ( 162): 02/08/21 10:26:11:039 CPanRegKey GetValueString subKey is Software\Palo Alto Networks\GlobalProtect\Settings\pre-vpn-connect, value name is file&lt;BR /&gt;(T15632)Dump ( 162): 02/08/21 10:26:11:039 CPanRegKey GetValueString subKey is Software\Palo Alto Networks\GlobalProtect\Settings\pre-vpn-connect, value name is checksum&lt;BR /&gt;(T15632)Dump ( 162): 02/08/21 10:26:11:039 CPanRegKey GetValueString subKey is Software\Palo Alto Networks\GlobalProtect\Settings\pre-vpn-connect, value name is error-msg&lt;BR /&gt;(T15632)Dump ( 162): 02/08/21 10:26:11:039 CPanRegKey GetValueString subKey is Software\Palo Alto Networks\GlobalProtect\Settings\post-vpn-connect, value name is command&lt;BR /&gt;(T15632)Dump ( 162): 02/08/21 10:26:11:039 CPanRegKey GetValueString subKey is Software\Palo Alto Networks\GlobalProtect\Settings\post-vpn-connect, value name is context&lt;BR /&gt;(T15632)Dump ( 162): 02/08/21 10:26:11:039 CPanRegKey GetValueString subKey is Software\Palo Alto Networks\GlobalProtect\Settings\post-vpn-connect, value name is file&lt;BR /&gt;(T15632)Dump ( 162): 02/08/21 10:26:11:039 CPanRegKey GetValueString subKey is Software\Palo Alto Networks\GlobalProtect\Settings\post-vpn-connect, value name is checksum&lt;BR /&gt;(T15632)Dump ( 162): 02/08/21 10:26:11:039 CPanRegKey GetValueString subKey is Software\Palo Alto Networks\GlobalProtect\Settings\post-vpn-connect, value name is error-msg&lt;BR /&gt;(T15632)Dump ( 162): 02/08/21 10:26:11:039 CPanRegKey GetValueString subKey is Software\Palo Alto Networks\GlobalProtect\Settings\pre-vpn-disconnect, value name is command&lt;BR /&gt;(T15632)Dump ( 162): 02/08/21 10:26:11:039 CPanRegKey GetValueString subKey is Software\Palo Alto Networks\GlobalProtect\Settings\pre-vpn-disconnect, value name is context&lt;BR /&gt;(T15632)Dump ( 162): 02/08/21 10:26:11:039 CPanRegKey GetValueString subKey is Software\Palo Alto Networks\GlobalProtect\Settings\pre-vpn-disconnect, value name is timeout&lt;BR /&gt;(T15632)Dump ( 162): 02/08/21 10:26:11:039 CPanRegKey GetValueString subKey is Software\Palo Alto Networks\GlobalProtect\Settings\pre-vpn-disconnect, value name is file&lt;BR /&gt;(T15632)Dump ( 162): 02/08/21 10:26:11:039 CPanRegKey GetValueString subKey is Software\Palo Alto Networks\GlobalProtect\Settings\pre-vpn-disconnect, value name is checksum&lt;BR /&gt;(T15632)Dump ( 162): 02/08/21 10:26:11:039 CPanRegKey GetValueString subKey is Software\Palo Alto Networks\GlobalProtect\Settings\pre-vpn-disconnect, value name is error-msg&lt;BR /&gt;(T15632)Dump (7687): 02/08/21 10:26:11:039 entering.&lt;BR /&gt;(T15632)Dump ( 789): 02/08/21 10:26:11:039 vpn.csinfra.nsw.gov.au is not ipv6&lt;BR /&gt;(T15632)Debug(12844): 02/08/21 10:26:11:039 Portal's ipv4 address 143.119.161.5&lt;BR /&gt;(T15632)Debug(7734): 02/08/21 10:26:11:039 SSO enable status is 1, user name is ___empty_username___, domain name is .&lt;BR /&gt;(T15632)Dump (7737): 02/08/21 10:26:11:039 reset user authentication status to true.&lt;BR /&gt;(T15632)Dump ( 362): 02/08/21 10:26:11:039 COSVersion::OSProductName - fetch OS productName successful = Windows 10 Enterprise&lt;BR /&gt;(T15632)Dump ( 362): 02/08/21 10:26:11:039 COSVersion::OSProductName - fetch OS productName successful = Windows 10 Enterprise&lt;BR /&gt;(T15632)Dump ( 127): 02/08/21 10:26:11:039 Skip calling GetProductInfo for Windows 10&lt;BR /&gt;(T15632)Debug(2214): 02/08/21 10:26:11:039 open http session. agent is PAN GlobalProtect/5.2.4-21 (Microsoft Windows 10 Enterprise , 64-bit)&lt;BR /&gt;(T15632)Dump ( 362): 02/08/21 10:26:11:039 COSVersion::OSProductName - fetch OS productName successful = Windows 10 Enterprise&lt;BR /&gt;(T15632)Dump ( 362): 02/08/21 10:26:11:039 COSVersion::OSProductName - fetch OS productName successful = Windows 10 Enterprise&lt;BR /&gt;(T15632)Dump ( 127): 02/08/21 10:26:11:039 Skip calling GetProductInfo for Windows 10&lt;BR /&gt;(T15632)Debug( 465): 02/08/21 10:26:11:039 winhttp SetSecureProtocol, hSession=2bf0a370, bAllProtocol=0, gbFips=0&lt;BR /&gt;(T15632)Dump (1618): 02/08/21 10:26:11:039 Auto detect proxy for host vpn.csinfra.nsw.gov.au&lt;BR /&gt;(T15632)Dump ( 90): 02/08/21 10:26:11:039 GetProxyInfo&lt;BR /&gt;(T15632)Dump ( 362): 02/08/21 10:26:11:039 COSVersion::OSProductName - fetch OS productName successful = Windows 10 Enterprise&lt;BR /&gt;(T15632)Dump ( 362): 02/08/21 10:26:11:039 COSVersion::OSProductName - fetch OS productName successful = Windows 10 Enterprise&lt;BR /&gt;(T15632)Dump ( 127): 02/08/21 10:26:11:039 Skip calling GetProductInfo for Windows 10&lt;BR /&gt;(T15632)Debug( 465): 02/08/21 10:26:11:039 winhttp SetSecureProtocol, hSession=2b383240, bAllProtocol=0, gbFips=0&lt;BR /&gt;(T15632)Dump ( 102): 02/08/21 10:26:11:039 Proxy auto detect timeout 5 seconds&lt;BR /&gt;(T15632)Dump ( 106): 02/08/21 10:26:11:039 dwAveTimeout 1333 ms&lt;BR /&gt;(T15632)Dump ( 116): 02/08/21 10:26:11:039 Auto detect proxy url&lt;BR /&gt;(T15632)Debug( 120): 02/08/21 10:26:11:039 GetProxyInfo, autoConfigUrl=&lt;A href="http://proxy.govconnect.nsw.gov.au:9090/proxy.pac" target="_blank"&gt;http://proxy.govconnect.nsw.gov.au:9090/proxy.pac&lt;/A&gt;&lt;BR /&gt;(T15632)Debug( 128): 02/08/21 10:26:11:039 GetProxyInfo, winhttpgetproxyforurl failed, lastError=12167&lt;BR /&gt;(T15632)Dump ( 134): 02/08/21 10:26:11:039 Auto detect proxy&lt;BR /&gt;(T15632)Debug(1635): 02/08/21 10:26:11:039 SetProxyForHost(&lt;A href="https://vpn.csinfra.nsw.gov.au/" target="_blank"&gt;https://vpn.csinfra.nsw.gov.au/&lt;/A&gt;&lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt; timeout:5 AutoDetect:1 url:&lt;A href="http://proxy.govconnect.nsw.gov.au:9090/proxy.pac" target="_blank"&gt;http://proxy.govconnect.nsw.gov.au:9090/proxy.pac&lt;/A&gt; proxy: bypass: proxystr:&lt;BR /&gt;(T15632)Dump (1660): 02/08/21 10:26:11:039 m_proxyInfo.dwAccessType is 0, m_proxyInfo.lpszProxy is (null)&lt;BR /&gt;(T15632)Dump (11713): 02/08/21 10:26:11:039 Scep clean&lt;BR /&gt;(T15632)Dump (11715): 02/08/21 10:26:11:039 Clean m_pScepCert&lt;BR /&gt;(T15632)Dump (3715): 02/08/21 10:26:11:039 Clean m_szScepCertPanName&lt;BR /&gt;(T15632)Debug(6693): 02/08/21 10:26:11:039 ----Portal Pre-login starts----&lt;BR /&gt;(T15632)Debug(4891): 02/08/21 10:26:11:039 TriggerCaptivePortalDetection() return due to captive portal detection is in progress (0) or PreLogin is Done (1)&lt;BR /&gt;(T15632)Debug( 559): 02/08/21 10:26:11:062 Network is reachable&lt;BR /&gt;(T15632)Debug(6726): 02/08/21 10:26:11:063 Pre-login...,verifyportalcert=yes&lt;BR /&gt;(T15632)Dump ( 789): 02/08/21 10:26:11:063 vpn.csinfra.nsw.gov.au is not ipv6&lt;BR /&gt;(T15632)Debug(10696): 02/08/21 10:26:11:063 Check cert of server 143.119.161.5&lt;BR /&gt;(T15632)Dump ( 146): 02/08/21 10:26:11:063 pan_get_full_path(): full path in multibyte char is C:\Program Files\Palo Alto Networks\GlobalProtect\tca.cer&lt;BR /&gt;(T15632)Dump (1463): 02/08/21 10:26:11:063 File C:\Program Files\Palo Alto Networks\GlobalProtect\tca.cer does not exist.&lt;BR /&gt;(T15632)Debug(10711): 02/08/21 10:26:11:063 File C:\Program Files\Palo Alto Networks\GlobalProtect\tca.cer does not exist.&lt;BR /&gt;(T15632)Debug( 780): 02/08/21 10:26:11:063 SSL connecting to 143.119.161.5&lt;BR /&gt;(T15632)Dump ( 789): 02/08/21 10:26:11:063 143.119.161.5 is not ipv6&lt;BR /&gt;(T15632)Dump ( 469): 02/08/21 10:26:11:063 Receive timeout is 30&lt;BR /&gt;(T15632)Dump ( 516): 02/08/21 10:26:11:063 Connect timeout is 5&lt;BR /&gt;(T15632)Dump ( 572): 02/08/21 10:26:11:063 ii: 0 res-&amp;gt;ai_family: 2&lt;BR /&gt;(T15632)Dump ( 575): 02/08/21 10:26:11:063 Found IPv4 address&lt;BR /&gt;(T15632)Debug( 559): 02/08/21 10:26:11:070 Network is reachable&lt;BR /&gt;(T15632)Dump ( 64): 02/08/21 10:26:11:072 connect returns 10035(A non-blocking socket operation could not be completed immediately.)&lt;BR /&gt;(T15632)Dump (1315): 02/08/21 10:26:11:086 SSL_connect: initialization&lt;BR /&gt;(T15632)Dump (1315): 02/08/21 10:26:11:086 SSL_connect: write client hello A&lt;BR /&gt;(T15632)Dump (1315): 02/08/21 10:26:11:097 SSL_connect: read server hello A&lt;BR /&gt;(T15632)Dump (1315): 02/08/21 10:26:11:097 SSL_connect: read server certificate A&lt;BR /&gt;(T15632)Dump (1315): 02/08/21 10:26:11:097 SSL_connect: read server certificate request A&lt;BR /&gt;(T15632)Dump (1315): 02/08/21 10:26:11:097 SSL_connect: read server done A&lt;BR /&gt;(T15632)Dump (1315): 02/08/21 10:26:11:097 SSL_connect: write client certificate A&lt;BR /&gt;(T15632)Dump (1315): 02/08/21 10:26:11:097 SSL_connect: write client key exchange A&lt;BR /&gt;(T15632)Dump (1315): 02/08/21 10:26:11:097 SSL_connect: write change cipher spec A&lt;BR /&gt;(T15632)Dump (1315): 02/08/21 10:26:11:097 SSL_connect: write finished A&lt;BR /&gt;(T15632)Dump (1315): 02/08/21 10:26:11:097 SSL_connect: flush data&lt;BR /&gt;(T15632)Dump (1315): 02/08/21 10:26:11:113 SSL_connect: read finished A&lt;BR /&gt;(T15632)Debug(1247): 02/08/21 10:26:11:113 Failed to X509_LOOKUP_load_file&lt;BR /&gt;(T15632)Debug( 366): 02/08/21 10:26:11:113 Open_SSL_connection: subject '/C=AU/ST=New South Wales/L=Sydney/O=Department of Customer Service/CN=*.csinfra.nsw.gov.au'&lt;BR /&gt;(T15632)Debug( 370): 02/08/21 10:26:11:113 Open_SSL_connection: issuer '/C=US/O=Entrust, Inc./OU=See &lt;A href="http://www.entrust.net/legal-terms/OU=(c" target="_blank"&gt;www.entrust.net/legal-terms/OU=(c&lt;/A&gt;) 2012 Entrust, Inc. - for authorized use only/CN=Entrust Certification Authority - L1K'&lt;BR /&gt;(T15632)Dump ( 826): 02/08/21 10:26:11:113 StandardizeIpv6Format host=vpn.csinfra.nsw.gov.au&lt;BR /&gt;(T15632)Dump ( 789): 02/08/21 10:26:11:113 vpn.csinfra.nsw.gov.au is not ipv6&lt;BR /&gt;(T15632)Dump ( 895): 02/08/21 10:26:11:113 standardized name is vpn.csinfra.nsw.gov.au&lt;BR /&gt;(T15632)Dump ( 907): 02/08/21 10:26:11:113 count = 1&lt;BR /&gt;(T15632)Dump ( 914): 02/08/21 10:26:11:113 alt current_name_type=2&lt;BR /&gt;(T15632)Dump ( 917): 02/08/21 10:26:11:113 alt name=*.csinfra.nsw.gov.au&lt;BR /&gt;(T15632)Dump ( 962): 02/08/21 10:26:11:113 sub alt name=*.csinfra.nsw.gov.au&lt;BR /&gt;(T15632)Dump (1067): 02/08/21 10:26:11:113 MFAuthHandleMsg: Check domain name vpn.csinfra.nsw.gov.au versus CN name *.csinfra.nsw.gov.au&lt;BR /&gt;(T15632)Dump ( 789): 02/08/21 10:26:11:113 vpn.csinfra.nsw.gov.au is not ipv6&lt;BR /&gt;(T15632)Dump (1044): 02/08/21 10:26:11:113 vpn.csinfra.nsw.gov.au is not ipv4&lt;BR /&gt;(T15632)Debug(1113): 02/08/21 10:26:11:113 Name vpn.csinfra.nsw.gov.au matches pattern *.csinfra.nsw.gov.au&lt;BR /&gt;(T15632)Debug( 967): 02/08/21 10:26:11:113 Hostname vpn.csinfra.nsw.gov.au matches sub alt name *.csinfra.nsw.gov.au&lt;BR /&gt;(T15632)Dump ( 977): 02/08/21 10:26:11:113 check subalt returns 1&lt;BR /&gt;(T15632)Dump ( 803): 02/08/21 10:26:11:113 Disconnect SSL&lt;BR /&gt;(T15632)Debug(1323): 02/08/21 10:26:11:113 OpenSSL alert write:warning:close notify&lt;BR /&gt;(T15632)Dump ( 814): 02/08/21 10:26:11:113 Disconnect tcp socket&lt;BR /&gt;(T15632)Dump (10835): 02/08/21 10:26:11:113 CheckServerCert() returns 0x1002&lt;BR /&gt;(T15632)Dump (1044): 02/08/21 10:26:11:113 vpn.csinfra.nsw.gov.au is not ipv4&lt;BR /&gt;(T15632)Dump ( 789): 02/08/21 10:26:11:113 vpn.csinfra.nsw.gov.au is not ipv6&lt;BR /&gt;(T15632)Dump ( 767): 02/08/21 10:26:11:113 vpn.csinfra.nsw.gov.au is fqdn&lt;BR /&gt;(T15632)Dump (2750): 02/08/21 10:26:11:113 portal proxyparam is empty&lt;BR /&gt;(T15632)Dump (2772): 02/08/21 10:26:11:113 OID, oid=&lt;BR /&gt;(T15632)Debug(2669): 02/08/21 10:26:11:113 encpostdata, encpostdata=000002302BFA2790, encpostdatalen=176&lt;BR /&gt;(T15632)Debug(2838): 02/08/21 10:26:11:113 REQID=2,IPADDR=vpn.csinfra.nsw.gov.au,PORT=443,URL=/global-protect/prelogin.esp,POST=1,PROXY_AUTO=1,PROXY_CFGURL=&lt;A href="http://proxy.govconnect.nsw.gov.au:9090/proxy.pac,PROXY=NULL,PROXY_BYPASS=NULL,PROXY_USER=NULL,PROXY_PASS=****,VERIFY_CERT=1,ADDITIONAL_CHECK=1,SCEP_CERT=,oid=" target="_blank"&gt;http://proxy.govconnect.nsw.gov.au:9090/proxy.pac,PROXY=NULL,PROXY_BYPASS=NULL,PROXY_USER=NULL,PROXY_PASS=****,VERIFY_CERT=1,ADDITIONAL_CHECK=1,SCEP_CERT=,oid=&lt;/A&gt;&lt;BR /&gt;(T15632)Dump ( 865): 02/08/21 10:26:11:113 status is Disconnected&lt;BR /&gt;(T15632)Dump ( 905): 02/08/21 10:26:11:113 stats.b_connected is 0, GetBestGateway is NULL.&lt;BR /&gt;(T15632)Debug(1605): 02/08/21 10:26:11:129 Send response to client for request https_request&lt;BR /&gt;(T15632)Dump (2868): 02/08/21 10:26:11:129 gpapintimeout not set, set it to 600 seconds&lt;BR /&gt;(T15632)Debug(2948): 02/08/21 10:26:11:231 receive pan_msg_ping, 3&lt;BR /&gt;(T15632)Debug(2948): 02/08/21 10:26:11:331 receive pan_msg_ping, 2&lt;BR /&gt;(T15632)Dump (2954): 02/08/21 10:26:11:331 retid =2&lt;BR /&gt;(T15632)Dump (2960): 02/08/21 10:26:11:331 reqid matchs, continue...&lt;BR /&gt;(T15632)Debug(6838): 02/08/21 10:26:11:331 prelogin to portal result is&lt;BR /&gt;&amp;lt;?xml version="1.0" encoding="UTF-8" ?&amp;gt;&lt;BR /&gt;&amp;lt;prelogin-response&amp;gt;&lt;BR /&gt;&amp;lt;status&amp;gt;Error&amp;lt;/status&amp;gt;&lt;BR /&gt;&amp;lt;ccusername&amp;gt;&amp;lt;/ccusername&amp;gt;&lt;BR /&gt;&amp;lt;autosubmit&amp;gt;&amp;lt;/autosubmit&amp;gt;&lt;BR /&gt;&amp;lt;msg&amp;gt;Valid client certificate is required&amp;lt;/msg&amp;gt;&lt;BR /&gt;&amp;lt;newmsg&amp;gt;Required client certificate not found. Please contact your IT administrator.&amp;lt;/newmsg&amp;gt;&lt;BR /&gt;&amp;lt;authentication-message&amp;gt;&amp;lt;/authentication-message&amp;gt;&lt;BR /&gt;&amp;lt;username-label&amp;gt;&amp;lt;/username-label&amp;gt;&lt;BR /&gt;&amp;lt;password-label&amp;gt;&amp;lt;/password-label&amp;gt;&lt;BR /&gt;&amp;lt;panos-version&amp;gt;1&amp;lt;/panos-version&amp;gt;&amp;lt;region&amp;gt;AU&amp;lt;/region&amp;gt;&lt;BR /&gt;&amp;lt;/prelogin-response&amp;gt;&lt;BR /&gt;(T15632)Debug(6873): 02/08/21 10:26:11:331 REGION-PRIO, region code is AU&lt;BR /&gt;(T15632)Debug(12657): 02/08/21 10:26:11:331 REGION-PRIO, save region code AU&lt;BR /&gt;(T15632)Debug(7088): 02/08/21 10:26:11:331 prelogin status is Error&lt;BR /&gt;(T15632)Error(7091): 02/08/21 10:26:11:331 pre-login error message: Valid client certificate is required&lt;BR /&gt;(T15632)Dump (2241): 02/08/21 10:26:11:331 close WinHttp close handle.&lt;BR /&gt;(T15632)Debug(7917): 02/08/21 10:26:11:331 Non-OnDemand mode valid client cert is required.&lt;BR /&gt;(T15632)Info (9558): 02/08/21 10:26:11:331 Portal config does not exist, try registry/plist&lt;BR /&gt;(T15632)Dump (9568): 02/08/21 10:26:11:331 Failed to get version from config, try local&lt;BR /&gt;(T15632)Info (7931): 02/08/21 10:26:11:331 failed to retrieve value of the tag version.&lt;BR /&gt;(T15632)Debug(7942): 02/08/21 10:26:11:331 Failed to get portal config from portal vpn.csinfra.nsw.gov.au.&lt;BR /&gt;(T15632)Debug(7973): 02/08/21 10:26:11:331 Try to restore last portal config from file.&lt;BR /&gt;(T15632)Dump ( 146): 02/08/21 10:26:11:331 pan_get_full_path(): full path in multibyte char is C:\Program Files\Palo Alto Networks\GlobalProtect\PanSCEP_c34f377586ce2187f2acba2566f4b655.cer&lt;BR /&gt;(T15632)Dump ( 146): 02/08/21 10:26:11:331 pan_get_full_path(): full path in multibyte char is C:\Program Files\Palo Alto Networks\GlobalProtect\PanSCEP_c34f377586ce2187f2acba2566f4b655.pfx&lt;BR /&gt;(T15632)Debug(8020): 02/08/21 10:26:11:331 Skip retrieve cached portal configuration for empty user&lt;BR /&gt;(T15632)Debug(7952): 02/08/21 10:26:11:331 Set portal status to valid client cert needed.&lt;BR /&gt;(T15632)Debug(7962): 02/08/21 10:26:11:331 portal status is Client Cert Required.&lt;BR /&gt;(T15632)Dump (7966): 02/08/21 10:26:11:331 returns 0.&lt;BR /&gt;(T15632)Debug(7233): 02/08/21 10:26:11:331 Portal required client certificate is not found.&lt;BR /&gt;(T15632)Dump (4358): 02/08/21 10:26:11:331 Set registry LastErrorString as Required client certificate not found. Please contact your IT administrator.&lt;BR /&gt;(T15632)Dump ( 865): 02/08/21 10:26:11:331 status is Disconnected&lt;BR /&gt;(T15632)Dump ( 905): 02/08/21 10:26:11:331 stats.b_connected is 0, GetBestGateway is NULL.&lt;BR /&gt;(T15632)Debug(1964): 02/08/21 10:26:11:331 unknown network type.&lt;BR /&gt;(T15632)Debug(1057): 02/08/21 10:26:11:331 Display hip report V4 on the UI&lt;BR /&gt;(T15628)Debug(2381): 02/08/21 10:26:11:331 Setting debug level to 6&lt;BR /&gt;(T15632)Dump (6394): 02/08/21 10:26:11:331&lt;BR /&gt;ResponseToClient.txt_output: &amp;lt;?xml version="1.0" encoding="UTF-8"?&amp;gt;&lt;BR /&gt;&amp;lt;response&amp;gt;&lt;BR /&gt;&amp;lt;type&amp;gt;status&amp;lt;/type&amp;gt;&lt;BR /&gt;&amp;lt;status&amp;gt;Disconnected&amp;lt;/status&amp;gt;&lt;BR /&gt;&amp;lt;protocol/&amp;gt;&lt;BR /&gt;&amp;lt;portal-config-version&amp;gt;0&amp;lt;/portal-config-version&amp;gt;&lt;BR /&gt;&amp;lt;error-must-show/&amp;gt;&lt;BR /&gt;&amp;lt;error-must-show-level&amp;gt;error&amp;lt;/error-must-show-level&amp;gt;&lt;BR /&gt;&amp;lt;error&amp;gt;Required client certificate not found. Please contact your IT administrator.&amp;lt;/error&amp;gt;&lt;BR /&gt;&amp;lt;product-version&amp;gt;5.2.4-21&amp;lt;/product-version&amp;gt;&lt;BR /&gt;&amp;lt;product-code&amp;gt;&amp;amp;quot;{717E7B2D-F4DF-4707-8024-E346F2E64F4F}&amp;amp;quot;&amp;lt;/product-code&amp;gt;&lt;BR /&gt;&amp;lt;portal-status&amp;gt;Client Cert Required&amp;lt;/portal-status&amp;gt;&lt;BR /&gt;&amp;lt;user-name/&amp;gt;&lt;BR /&gt;&amp;lt;username-type&amp;gt;sso&amp;lt;/username-type&amp;gt;&lt;BR /&gt;&amp;lt;state&amp;gt;Disconnected&amp;lt;/state&amp;gt;&lt;BR /&gt;&amp;lt;check-version&amp;gt;no&amp;lt;/check-version&amp;gt;&lt;BR /&gt;&amp;lt;portal&amp;gt;vpn.csinfra.nsw.gov.au&amp;lt;/portal&amp;gt;&lt;BR /&gt;&amp;lt;discover-ready&amp;gt;no&amp;lt;/discover-ready&amp;gt;&lt;BR /&gt;&amp;lt;mdm-is-enabled&amp;gt;no&amp;lt;/mdm-is-enabled&amp;gt;&lt;BR /&gt;&amp;lt;/response&amp;gt;&lt;/P&gt;&lt;P&gt;(T15632)Dump (1603): 02/08/21 10:26:11:331 Send response to client for request status&lt;BR /&gt;(T15632)Dump (11128): 02/08/21 10:26:11:331 Set m_bPreviousSwitchOffMsg to 0&lt;/P&gt;</description>
      <pubDate>Mon, 08 Feb 2021 00:50:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-required-client-certificate-not-found-export/m-p/384387#M894</guid>
      <dc:creator>mark236</dc:creator>
      <dc:date>2021-02-08T00:50:31Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Required client certificate not found - Export-Import certificate(s)</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-required-client-certificate-not-found-export/m-p/384489#M897</link>
      <description>&lt;P&gt;on the device that is not working.&lt;/P&gt;&lt;P&gt;open up IE, settings, internet options, content, certificates.&lt;/P&gt;&lt;P&gt;check that you have a personal certificate that has been issued by the same root CA as on the working device and that it has not expired.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It may be that the certificates are used from the machine store... so you may also need to check that location with mmc snap-in.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MickBall_0-1612790093307.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/29849i4B562FED3B92B7ED/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="MickBall_0-1612790093307.png" alt="MickBall_0-1612790093307.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Feb 2021 13:17:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-required-client-certificate-not-found-export/m-p/384489#M897</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2021-02-08T13:17:31Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Required client certificate not found - Export-Import certificate(s)</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-required-client-certificate-not-found-export/m-p/384490#M898</link>
      <description>&lt;P&gt;also...&amp;nbsp; &amp;nbsp;try to browse to the portal address from IE https. see if you get the same error...&lt;/P&gt;</description>
      <pubDate>Mon, 08 Feb 2021 13:18:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-required-client-certificate-not-found-export/m-p/384490#M898</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2021-02-08T13:18:46Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Required client certificate not found - Export-Import certificate(s)</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-required-client-certificate-not-found-export/m-p/384653#M900</link>
      <description>Thank you for your response&lt;BR /&gt;&lt;BR /&gt;In IE, I do not see any personal certificate.&lt;BR /&gt;When I try to import (.cer, p7b) - it says imported successfully, but a&lt;BR /&gt;certificate does NOT appear in the list.&lt;BR /&gt;&lt;BR /&gt;I cannot export from a working device, when using the file format "Personal&lt;BR /&gt;Information Exchange". Error says: "the export failed. Key not valid for&lt;BR /&gt;use in specified state."&lt;BR /&gt;</description>
      <pubDate>Mon, 08 Feb 2021 23:54:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-required-client-certificate-not-found-export/m-p/384653#M900</guid>
      <dc:creator>mark236</dc:creator>
      <dc:date>2021-02-08T23:54:41Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Required client certificate not found - Export-Import certificate(s)</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-required-client-certificate-not-found-export/m-p/384656#M901</link>
      <description>In IE, I cannot connect to the portal. It freezes endlessly "Waiting"&lt;BR /&gt;&lt;BR /&gt;"so you may also need to check that location with mmc snap-in."&lt;BR /&gt;&lt;BR /&gt;How I check it?&lt;BR /&gt;</description>
      <pubDate>Mon, 08 Feb 2021 23:59:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-required-client-certificate-not-found-export/m-p/384656#M901</guid>
      <dc:creator>mark236</dc:creator>
      <dc:date>2021-02-08T23:59:41Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Required client certificate not found - Export-Import certificate(s)</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-required-client-certificate-not-found-export/m-p/384657#M902</link>
      <description>&lt;P&gt;I see the certificates in IE - Internet Options - Content - Certificates - Other People&lt;/P&gt;</description>
      <pubDate>Tue, 09 Feb 2021 00:46:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-required-client-certificate-not-found-export/m-p/384657#M902</guid>
      <dc:creator>mark236</dc:creator>
      <dc:date>2021-02-09T00:46:55Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Required client certificate not found - Export-Import certificate(s)</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-required-client-certificate-not-found-export/m-p/384693#M903</link>
      <description>&lt;P&gt;The certificate cannot be used from the “other people” store.&lt;/P&gt;&lt;P&gt;The cert needs to be in personal or machine store.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;where exactly are you getting that cert from and how was that cert originally imported.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;it sounds like it may have been a cert for a specific domain member, if so then you will struggle with export/import.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;mmc can be run from command prompt. Select certificates and then local. &amp;nbsp; You can perform various tasks via right click but you will still be limited to what you can do with an intended user certificate.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Feb 2021 06:15:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-required-client-certificate-not-found-export/m-p/384693#M903</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2021-02-09T06:15:55Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Required client certificate not found - Export-Import certificate(s)</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-required-client-certificate-not-found-export/m-p/384732#M904</link>
      <description>&lt;P&gt;The certificate cannot be used from the “other people” store.&lt;/P&gt;&lt;P&gt;The cert needs to be in personal or machine store.&lt;/P&gt;&lt;P&gt;&lt;FONT color="#339966"&gt;&amp;gt;&amp;gt;&amp;gt;How I transfer from "other people" to "personal"?&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;where exactly are you getting that cert from and how was that cert originally imported.&lt;/P&gt;&lt;P&gt;&lt;FONT color="#339966"&gt;&amp;gt;&amp;gt;&amp;gt;The certificates should come from a central place (I do not know). They should be "downloaded automatically", as our support says.&lt;BR /&gt;Just one day, GlobalProtect started to show the error (see the topic).&lt;BR /&gt;The second device was created recently, after the first device stopped to connect due to the error with certificates.&lt;BR /&gt;Actually, I tried to export/import them from a new device. No success.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;it sounds like it may have been a cert for a specific domain member, if so then you will struggle with export/import.&lt;/P&gt;&lt;P&gt;&lt;FONT color="#339966"&gt;&amp;gt;&amp;gt;&amp;gt;My question is can we export/import the certificates? Yes, it is&amp;nbsp;&lt;SPAN&gt;cert for a specific domain member.&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;mmc can be run from command prompt. Select certificates and then local. &amp;nbsp; You can perform various tasks via right click but you will still be limited to what you can do with an intended user certificate.&lt;/P&gt;&lt;P&gt;&lt;FONT color="#339966"&gt;&amp;gt;&amp;gt;&amp;gt;What I do with mmc?&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Feb 2021 10:32:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-required-client-certificate-not-found-export/m-p/384732#M904</guid>
      <dc:creator>mark236</dc:creator>
      <dc:date>2021-02-09T10:32:02Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Required client certificate not found - Export-Import certificate(s)</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-required-client-certificate-not-found-export/m-p/384742#M906</link>
      <description>&lt;P&gt;no you cannot import export domain certs for specific users.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;is the user certificate on the failing laptop in date or perhaps it has expired.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;try to compare the certificate on the failing laptop with the certificate on a laptop that connects without errors.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;mmc certificate snap-in can be used to view and move certificates around but this will not help because of the certificate type. (domain)&lt;/P&gt;</description>
      <pubDate>Tue, 09 Feb 2021 10:45:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-required-client-certificate-not-found-export/m-p/384742#M906</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2021-02-09T10:45:28Z</dc:date>
    </item>
  </channel>
</rss>

