<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Pre-logon on Apple Mac in Automation/API Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/pre-logon-on-apple-mac/m-p/221687#M1723</link>
    <description>&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/GlobalProtect-Requests-System-Keychain-Access-on-Mac-OS-X/ta-p/53332" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/GlobalProtect-Requests-System-Keychain-Access-on-Mac-OS-X/ta-p/53332&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Issue&lt;BR /&gt;&lt;BR /&gt;Machine Certificate authentication is used on MAC OS X clients. During the GlobalProtect connection process, the user needs to enter the Local Administrator account credentials to allow access to the System keychain twice.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cause&lt;BR /&gt;&lt;BR /&gt;When using Machine Certificates with GlobalProtect on Mac OS X Clients, the certificate must be accessed from the "System" keychain in MAC OS X.&amp;nbsp; This will cause a Keychain Access prompt to appear twice when the client attempts to access the certificate for verification against both portal and gateway.&lt;BR /&gt;&lt;BR /&gt;Workaround&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Open the Keychain Access application and locate the Machine Certificate issued to Mac OS X Client in the System keychain.&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Right-click on the private key associated with Certificate and click Get Info, then go to the Access Control tab&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Click '+' to select an Application to allow&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Press key combination &amp;lt;Command&amp;gt; + &amp;lt;Shift&amp;gt; + G to open Go to Folder&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Enter '/Applications/GlobalProtect.app/Contents/Resources' and click Go&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Find PanGPS and click it, and then press Add&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Save Changes to private key&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;PS: our MAC begin connecting only after all apps access were given to the key file.&lt;/EM&gt;&lt;BR /&gt;&lt;BR /&gt;The steps above allows GlobalProtect access to only THIS certificate and private key.&amp;nbsp; It will no longer prompt for keychain access, giving users a seamless, no-touch experience with Palo Alto Networks GlobalProtect.&lt;BR /&gt;&lt;BR /&gt;Note:&lt;BR /&gt;&lt;BR /&gt;The procedure has to be done again every time client is updated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/macOS-X-10-13-amp-iOS-11-New-Requirements-for-GlobalProtect/ta-p/179049" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/macOS-X-10-13-amp-iOS-11-New-Requirements-for-GlobalProtect/ta-p/179049&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 11 Jul 2018 08:32:20 GMT</pubDate>
    <dc:creator>MaximAvtonenko</dc:creator>
    <dc:date>2018-07-11T08:32:20Z</dc:date>
    <item>
      <title>Pre-logon on Apple Mac</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/pre-logon-on-apple-mac/m-p/39914#M936</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I can't get it working Mac. Can someone please help?&lt;/P&gt;&lt;P&gt;I've the company issued certificated installed on Mac. Do I need to enable something on the Mac itself?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Touqeer&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Aug 2015 18:42:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/pre-logon-on-apple-mac/m-p/39914#M936</guid>
      <dc:creator>Touqeer</dc:creator>
      <dc:date>2015-08-10T18:42:27Z</dc:date>
    </item>
    <item>
      <title>Re: Pre-logon on Apple Mac</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/pre-logon-on-apple-mac/m-p/221687#M1723</link>
      <description>&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/GlobalProtect-Requests-System-Keychain-Access-on-Mac-OS-X/ta-p/53332" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/GlobalProtect-Requests-System-Keychain-Access-on-Mac-OS-X/ta-p/53332&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Issue&lt;BR /&gt;&lt;BR /&gt;Machine Certificate authentication is used on MAC OS X clients. During the GlobalProtect connection process, the user needs to enter the Local Administrator account credentials to allow access to the System keychain twice.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cause&lt;BR /&gt;&lt;BR /&gt;When using Machine Certificates with GlobalProtect on Mac OS X Clients, the certificate must be accessed from the "System" keychain in MAC OS X.&amp;nbsp; This will cause a Keychain Access prompt to appear twice when the client attempts to access the certificate for verification against both portal and gateway.&lt;BR /&gt;&lt;BR /&gt;Workaround&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Open the Keychain Access application and locate the Machine Certificate issued to Mac OS X Client in the System keychain.&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Right-click on the private key associated with Certificate and click Get Info, then go to the Access Control tab&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Click '+' to select an Application to allow&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Press key combination &amp;lt;Command&amp;gt; + &amp;lt;Shift&amp;gt; + G to open Go to Folder&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Enter '/Applications/GlobalProtect.app/Contents/Resources' and click Go&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Find PanGPS and click it, and then press Add&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Save Changes to private key&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;PS: our MAC begin connecting only after all apps access were given to the key file.&lt;/EM&gt;&lt;BR /&gt;&lt;BR /&gt;The steps above allows GlobalProtect access to only THIS certificate and private key.&amp;nbsp; It will no longer prompt for keychain access, giving users a seamless, no-touch experience with Palo Alto Networks GlobalProtect.&lt;BR /&gt;&lt;BR /&gt;Note:&lt;BR /&gt;&lt;BR /&gt;The procedure has to be done again every time client is updated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/macOS-X-10-13-amp-iOS-11-New-Requirements-for-GlobalProtect/ta-p/179049" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/macOS-X-10-13-amp-iOS-11-New-Requirements-for-GlobalProtect/ta-p/179049&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Jul 2018 08:32:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/pre-logon-on-apple-mac/m-p/221687#M1723</guid>
      <dc:creator>MaximAvtonenko</dc:creator>
      <dc:date>2018-07-11T08:32:20Z</dc:date>
    </item>
  </channel>
</rss>

