<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to solve the Administrator Certificate-Based Authentication with issue of Redirection to prompt the username and password in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/how-to-solve-the-administrator-certificate-based-authentication/m-p/599154#M3829</link>
    <description>&lt;P&gt;Is there any option to customize a response page for admins who does not have certificates,&amp;nbsp;&lt;BR /&gt;we are getting error 400 bad request, we are expecting response like access denied&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 01 Oct 2024 07:48:12 GMT</pubDate>
    <dc:creator>C.Muniraju</dc:creator>
    <dc:date>2024-10-01T07:48:12Z</dc:date>
    <item>
      <title>How to solve the Administrator Certificate-Based Authentication with issue of Redirection to prompt the username and password</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/how-to-solve-the-administrator-certificate-based-authentication/m-p/571408#M2338</link>
      <description>&lt;P&gt;The Certificate-Based Authentication for administrators to access the firewall through the web interface transparently authenticates the admin with a client certificate instead of prompting and entering manually the username and password.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The Client Certificate must be generated and signed either by the built-in CA of the Firewall or an Enterprise CA. The Common Name that you enter in the CSR should be the username of the Admin and the same username should be also created in the firewall as non-local database account with the option &lt;STRONG&gt;"Use only client certificate authentication (Web)"&lt;/STRONG&gt; checked.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="6.png" style="width: 807px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56219i1E17DB8D5892F707/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="6.png" alt="6.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The Certificate Profile that defines which CA's certificate the firewall will use to verify the Client Certificate. This certificate profile contains the option &lt;STRONG&gt;"Username Field"&lt;/STRONG&gt;, In this field you need to select the option &lt;STRONG&gt;"Subject" &lt;/STRONG&gt;to instruct the firewall to use the Common Name defined in the client certificate as the username when authenticating through the Web Interface.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Without specifiying the Username Field in the Certificate Profile, the Admin will be redirected to enter a username and password as shown below because the firewall&amp;nbsp; is unable to find which field in the client certificate it must use to authenticate the adming, and this is not the goal of using Administrator Certificate-Based Authentication.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="3.png" style="width: 993px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56216i387F0EE0977CA16F/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="3.png" alt="3.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="1.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56217iD88F0EEE9BCD0215/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="1.png" alt="1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="2.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56218iE7BF99E09067FC2D/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="2.png" alt="2.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To fix this, specify the Username Field to be the Common Name or the Subject Alternative Name.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="4.png" style="width: 997px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56220i04186184E280C57F/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="4.png" alt="4.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="5.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56221i563D1E216C7EBBD0/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="5.png" alt="5.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jan 2024 08:39:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/how-to-solve-the-administrator-certificate-based-authentication/m-p/571408#M2338</guid>
      <dc:creator>rmeddane</dc:creator>
      <dc:date>2024-01-02T08:39:07Z</dc:date>
    </item>
    <item>
      <title>Re: How to solve the Administrator Certificate-Based Authentication with issue of Redirection to prompt the username and password</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/how-to-solve-the-administrator-certificate-based-authentication/m-p/599154#M3829</link>
      <description>&lt;P&gt;Is there any option to customize a response page for admins who does not have certificates,&amp;nbsp;&lt;BR /&gt;we are getting error 400 bad request, we are expecting response like access denied&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Oct 2024 07:48:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/how-to-solve-the-administrator-certificate-based-authentication/m-p/599154#M3829</guid>
      <dc:creator>C.Muniraju</dc:creator>
      <dc:date>2024-10-01T07:48:12Z</dc:date>
    </item>
  </channel>
</rss>

