<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Moving from GP to Prisma access - Prisma prompts client to choose a certificate. in Prisma Access Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/moving-from-gp-to-prisma-access-prisma-prompts-client-to-choose/m-p/582342#M734</link>
    <description>&lt;P&gt;Hello, yes that was the first thing we have tried.&lt;/P&gt;
&lt;P&gt;But the issue is that:&lt;/P&gt;
&lt;P&gt;- We are using the same certificates as on-prem.&lt;/P&gt;
&lt;P&gt;- The Prisma configuration is identical with the one on-prem, since they are both being managed by our Panorama.&lt;/P&gt;
&lt;P&gt;- The GP client is the same version.&lt;/P&gt;
&lt;P&gt;- The "Confirm certificate" popup only appears when we try to connect to prisma.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Therefore, if we deduct that:&lt;/P&gt;
&lt;P&gt;- The VPN client is not the issue because we are using the same version and app.&lt;/P&gt;
&lt;P&gt;- Configuration is not the issue since it is the same.&lt;/P&gt;
&lt;P&gt;- The certificates are identical.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I guess the only difference is that on-prem is connected to our local AD, whereas Prisma is on Azure. Could that be the issue?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 02 Apr 2024 08:13:03 GMT</pubDate>
    <dc:creator>N.Nicolaides</dc:creator>
    <dc:date>2024-04-02T08:13:03Z</dc:date>
    <item>
      <title>Moving from GP to Prisma access - Prisma prompts client to choose a certificate.</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/moving-from-gp-to-prisma-access-prisma-prompts-client-to-choose/m-p/581900#M724</link>
      <description>&lt;P&gt;We are trying to replicate our on-prem GP setup on Prisma, since we are migrating to that.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The issue is when we try to connect to Prisma portal, the user gets asked to verify the certificate.&lt;/P&gt;
&lt;P&gt;However the same setup exists for on-prem GlobalProtect and the certificate does not happen.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have tried various techniques with PA Prof. Services and an active TAC case.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am using GP 6.2.2.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;EDIT&lt;/P&gt;
&lt;P&gt;--------&lt;/P&gt;
&lt;P&gt;Resolved. The issue was under Windows Internet settings. We had the &amp;lt;domain.com&amp;gt; as a trusted site, but we also had to add prisma.domain.com through the registry for it to get resolved.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Apr 2024 12:41:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/moving-from-gp-to-prisma-access-prisma-prompts-client-to-choose/m-p/581900#M724</guid>
      <dc:creator>N.Nicolaides</dc:creator>
      <dc:date>2024-04-04T12:41:17Z</dc:date>
    </item>
    <item>
      <title>Re: Moving from GP to Prisma access - Prisma prompts client to choose a certificate.</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/moving-from-gp-to-prisma-access-prisma-prompts-client-to-choose/m-p/582024#M725</link>
      <description>&lt;P&gt;in the portal/gateway &lt;STRONG&gt;authentication&lt;/STRONG&gt; tab, is the "&lt;SPAN&gt;Allow Authentication with User Credentials OR Client Certificate" set to 'no'?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;try setting that to yes (or remove the&amp;nbsp;Certificate Profile)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Mar 2024 10:02:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/moving-from-gp-to-prisma-access-prisma-prompts-client-to-choose/m-p/582024#M725</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2024-03-28T10:02:19Z</dc:date>
    </item>
    <item>
      <title>Re: Moving from GP to Prisma access - Prisma prompts client to choose a certificate.</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/moving-from-gp-to-prisma-access-prisma-prompts-client-to-choose/m-p/582027#M726</link>
      <description>&lt;P&gt;We want both user and certificate authentication. That is the point. We want the user to authenticate on the corporate machines.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Mar 2024 11:07:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/moving-from-gp-to-prisma-access-prisma-prompts-client-to-choose/m-p/582027#M726</guid>
      <dc:creator>N.Nicolaides</dc:creator>
      <dc:date>2024-03-28T11:07:48Z</dc:date>
    </item>
    <item>
      <title>Re: Moving from GP to Prisma access - Prisma prompts client to choose a certificate.</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/moving-from-gp-to-prisma-access-prisma-prompts-client-to-choose/m-p/582066#M728</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/218334601"&gt;@N.Nicolaides&lt;/a&gt;&amp;nbsp;, do you have a copy of the server certificate imported and pushed to your Prisma Access MU SPN and not just to your on-premise firewall?&lt;/P&gt;</description>
      <pubDate>Thu, 28 Mar 2024 21:00:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/moving-from-gp-to-prisma-access-prisma-prompts-client-to-choose/m-p/582066#M728</guid>
      <dc:creator>Vickynet</dc:creator>
      <dc:date>2024-03-28T21:00:09Z</dc:date>
    </item>
    <item>
      <title>Re: Moving from GP to Prisma access - Prisma prompts client to choose a certificate.</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/moving-from-gp-to-prisma-access-prisma-prompts-client-to-choose/m-p/582183#M730</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;If by MU SPN you mean the cloud based Prisma firewall configuration, then yes, the certificate is the same as the on-prem ones.&lt;/P&gt;
&lt;P&gt;We are using certificate and user authentication. If Prisma did not have the root CAs installed, it would have not logged in at all, correct?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We seem to be getting an issue similar to this.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000HBVpCAO" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000HBVpCAO&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 30 Mar 2024 21:49:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/moving-from-gp-to-prisma-access-prisma-prompts-client-to-choose/m-p/582183#M730</guid>
      <dc:creator>N.Nicolaides</dc:creator>
      <dc:date>2024-03-30T21:49:00Z</dc:date>
    </item>
    <item>
      <title>Re: Moving from GP to Prisma access - Prisma prompts client to choose a certificate.</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/moving-from-gp-to-prisma-access-prisma-prompts-client-to-choose/m-p/582190#M731</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/230833"&gt;@Vickynet&lt;/a&gt; , apologies, my writing looks a bit blunt and rude, I assure you it was not my intention.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 31 Mar 2024 11:21:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/moving-from-gp-to-prisma-access-prisma-prompts-client-to-choose/m-p/582190#M731</guid>
      <dc:creator>N.Nicolaides</dc:creator>
      <dc:date>2024-03-31T11:21:38Z</dc:date>
    </item>
    <item>
      <title>Re: Moving from GP to Prisma access - Prisma prompts client to choose a certificate.</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/moving-from-gp-to-prisma-access-prisma-prompts-client-to-choose/m-p/582288#M732</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/218334601"&gt;@N.Nicolaides&lt;/a&gt;&amp;nbsp;, not a problem at all and thank you for getting back to me. I reviewed the knowledge based article you referenced, that may also be related. Did you try out what was suggested in the article? I would love to know the outcome.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you,&lt;/P&gt;</description>
      <pubDate>Mon, 01 Apr 2024 21:46:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/moving-from-gp-to-prisma-access-prisma-prompts-client-to-choose/m-p/582288#M732</guid>
      <dc:creator>Vickynet</dc:creator>
      <dc:date>2024-04-01T21:46:48Z</dc:date>
    </item>
    <item>
      <title>Re: Moving from GP to Prisma access - Prisma prompts client to choose a certificate.</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/moving-from-gp-to-prisma-access-prisma-prompts-client-to-choose/m-p/582342#M734</link>
      <description>&lt;P&gt;Hello, yes that was the first thing we have tried.&lt;/P&gt;
&lt;P&gt;But the issue is that:&lt;/P&gt;
&lt;P&gt;- We are using the same certificates as on-prem.&lt;/P&gt;
&lt;P&gt;- The Prisma configuration is identical with the one on-prem, since they are both being managed by our Panorama.&lt;/P&gt;
&lt;P&gt;- The GP client is the same version.&lt;/P&gt;
&lt;P&gt;- The "Confirm certificate" popup only appears when we try to connect to prisma.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Therefore, if we deduct that:&lt;/P&gt;
&lt;P&gt;- The VPN client is not the issue because we are using the same version and app.&lt;/P&gt;
&lt;P&gt;- Configuration is not the issue since it is the same.&lt;/P&gt;
&lt;P&gt;- The certificates are identical.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I guess the only difference is that on-prem is connected to our local AD, whereas Prisma is on Azure. Could that be the issue?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Apr 2024 08:13:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/moving-from-gp-to-prisma-access-prisma-prompts-client-to-choose/m-p/582342#M734</guid>
      <dc:creator>N.Nicolaides</dc:creator>
      <dc:date>2024-04-02T08:13:03Z</dc:date>
    </item>
    <item>
      <title>Re: Moving from GP to Prisma access - Prisma prompts client to choose a certificate.</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/moving-from-gp-to-prisma-access-prisma-prompts-client-to-choose/m-p/582451#M735</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/218334601"&gt;@N.Nicolaides&lt;/a&gt;, everything looks right based on the procedures you itemized in your previous notes. I don't really believe using Azure AD for Prisma should cause this behavior as well. Do you want to try Palo Alto TAC support team so they can have a deeper look on your settings to see if they could narrow down the root cause of the issue? Looking for more info on my side as well in the meantime if I could see you may pay attention to.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Apr 2024 04:58:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/moving-from-gp-to-prisma-access-prisma-prompts-client-to-choose/m-p/582451#M735</guid>
      <dc:creator>Vickynet</dc:creator>
      <dc:date>2024-04-03T04:58:19Z</dc:date>
    </item>
  </channel>
</rss>

