<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: deploying ssl  decryption cert using global protect client in VM-Series in the Private Cloud</title>
    <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-private-cloud/deploying-ssl-decryption-cert-using-global-protect-client/m-p/494048#M45</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/216619"&gt;@Marcin_Jakubiec&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes there is!&amp;nbsp; If you navigate to Network &amp;gt; GlobalProtect &amp;gt; Portal &amp;gt; [edit portal] &amp;gt; Agent, you will see a TRUSTED ROOT CA section on the bottom.&amp;nbsp; Add your CA there.&amp;nbsp; If you check the INSTALL IN LOCAL ROOT CERTIFICATE STORE check box, the CA will be pushed to the client.&amp;nbsp; If you click on the ? in the upper right, then GlobalProtect Portals Agent Tab hyperlink, you will read "To install (transparently) the trusted root CA certificates that are required for SSL Forward Proxy decryption in the certificate store on the client, select &lt;SPAN class=""&gt;Install in Local Root Certificate Store&lt;/SPAN&gt;."&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tom&lt;/P&gt;</description>
    <pubDate>Fri, 27 May 2022 23:10:08 GMT</pubDate>
    <dc:creator>TomYoung</dc:creator>
    <dc:date>2022-05-27T23:10:08Z</dc:date>
    <item>
      <title>deploying ssl  decryption cert using global protect client</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-private-cloud/deploying-ssl-decryption-cert-using-global-protect-client/m-p/493739#M44</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am trying to implement URL filtering for all users on Global Protect VPN.&lt;/P&gt;&lt;P&gt;I have done some tests and figure it out that I need to have ssl decryption policy set, matching the URLs to be blocked. I am using self-signed cert for ssl forward proxy, have manually exported the cert and imported into my local trusted root, everything seems to be fine.&lt;/P&gt;&lt;P&gt;The only question is how will I deploy the cert to all users? I dont want to do it manually for everyone, we dont have on prem DC. Is there a way to push the cert to the client using global protect client?&lt;/P&gt;&lt;P&gt;I am using public sectigo cert to secure vpn connection.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 27 May 2022 16:01:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-private-cloud/deploying-ssl-decryption-cert-using-global-protect-client/m-p/493739#M44</guid>
      <dc:creator>Marcin_Jakubiec</dc:creator>
      <dc:date>2022-05-27T16:01:54Z</dc:date>
    </item>
    <item>
      <title>Re: deploying ssl  decryption cert using global protect client</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-private-cloud/deploying-ssl-decryption-cert-using-global-protect-client/m-p/494048#M45</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/216619"&gt;@Marcin_Jakubiec&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes there is!&amp;nbsp; If you navigate to Network &amp;gt; GlobalProtect &amp;gt; Portal &amp;gt; [edit portal] &amp;gt; Agent, you will see a TRUSTED ROOT CA section on the bottom.&amp;nbsp; Add your CA there.&amp;nbsp; If you check the INSTALL IN LOCAL ROOT CERTIFICATE STORE check box, the CA will be pushed to the client.&amp;nbsp; If you click on the ? in the upper right, then GlobalProtect Portals Agent Tab hyperlink, you will read "To install (transparently) the trusted root CA certificates that are required for SSL Forward Proxy decryption in the certificate store on the client, select &lt;SPAN class=""&gt;Install in Local Root Certificate Store&lt;/SPAN&gt;."&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Fri, 27 May 2022 23:10:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-private-cloud/deploying-ssl-decryption-cert-using-global-protect-client/m-p/494048#M45</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2022-05-27T23:10:08Z</dc:date>
    </item>
  </channel>
</rss>

