<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GP on Windows 11 - client certificate issue in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/gp-on-windows-11-client-certificate-issue/m-p/489940#M104897</link>
    <description>&lt;P&gt;&amp;nbsp;I had this exact same problem a few weeks ago on a PC which the user had upgraded to Win11 (without permission but..).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The problem is that the upgrade broke permissions for the GP client to access the private key, but it could read the public portion of the certificate just fine. Using MMC, nothing was apparent as being wrong. The fix is to manually export the user's certificate, including the private key, and save it. Delete the certificate from the user's cert store. Then re-import the saved key back into the certificate store. The GP client will now be able to read the private key. Alternatively, you can delete the old certificate and regenerate it (though you probably need to be connected/domain joined to do that in most cases).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;See my previous thread:&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/globalprotect-discussions/windows11-fails-to-connect-to-portal-with-client-certificate/m-p/484315/thread-id/2718" target="_blank" rel="noopener"&gt;https://live.paloaltonetworks.com/t5/globalprotect-discussions/windows11-fails-to-connect-to-portal-with-client-certificate/m-p/484315/thread-id/2718&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 23 May 2022 20:37:34 GMT</pubDate>
    <dc:creator>Adrian_Jensen</dc:creator>
    <dc:date>2022-05-23T20:37:34Z</dc:date>
    <item>
      <title>GP on Windows 11 - client certificate issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-on-windows-11-client-certificate-issue/m-p/489605#M104882</link>
      <description>&lt;P&gt;Our customer is having issues with GP&amp;nbsp;5.2.10-6 on Windows 11. They are using client certificates for authentication and after a while a connection fails due to no client certificate present. If we check MMC the certificate is present, valid and has private key.&amp;nbsp;&lt;/P&gt;&lt;P&gt;But GP logs say:&lt;/P&gt;&lt;P&gt;(P9292-T12792)Error(2290): 05/23/22 07:03:00:014 error = ERROR_WINHTTP_CLIENT_CERT_NO_ACCESS_PRIVATE_KEY&lt;/P&gt;&lt;P&gt;(P9292-T12792)Debug(2377): 05/23/22 07:03:00:014 winhttpObj, got ERROR_WINHTTP_CLIENT_CERT_NO_ACCESS_PRIVATE_KEY, clean cert cache now&lt;/P&gt;&lt;P&gt;(P9292-T12792)Debug(4578): 05/23/22 07:03:00:014 winhttpobj, cert do not has private key???? clean lastIssuerName now, data = 0000000000000000&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There is a reddit post about it:&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.reddit.com/r/sysadmin/comments/sd3m6v/windows_11_tpm_and_vpn_issue/" target="_blank"&gt;https://www.reddit.com/r/sysadmin/comments/sd3m6v/windows_11_tpm_and_vpn_issue/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But nothing on PA forums or KB. How many ppl are having similar issues? Any more info from PA support about this?&lt;/P&gt;</description>
      <pubDate>Mon, 23 May 2022 09:47:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-on-windows-11-client-certificate-issue/m-p/489605#M104882</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2022-05-23T09:47:28Z</dc:date>
    </item>
    <item>
      <title>Re: GP on Windows 11 - client certificate issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-on-windows-11-client-certificate-issue/m-p/489940#M104897</link>
      <description>&lt;P&gt;&amp;nbsp;I had this exact same problem a few weeks ago on a PC which the user had upgraded to Win11 (without permission but..).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The problem is that the upgrade broke permissions for the GP client to access the private key, but it could read the public portion of the certificate just fine. Using MMC, nothing was apparent as being wrong. The fix is to manually export the user's certificate, including the private key, and save it. Delete the certificate from the user's cert store. Then re-import the saved key back into the certificate store. The GP client will now be able to read the private key. Alternatively, you can delete the old certificate and regenerate it (though you probably need to be connected/domain joined to do that in most cases).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;See my previous thread:&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/globalprotect-discussions/windows11-fails-to-connect-to-portal-with-client-certificate/m-p/484315/thread-id/2718" target="_blank" rel="noopener"&gt;https://live.paloaltonetworks.com/t5/globalprotect-discussions/windows11-fails-to-connect-to-portal-with-client-certificate/m-p/484315/thread-id/2718&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 23 May 2022 20:37:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-on-windows-11-client-certificate-issue/m-p/489940#M104897</guid>
      <dc:creator>Adrian_Jensen</dc:creator>
      <dc:date>2022-05-23T20:37:34Z</dc:date>
    </item>
    <item>
      <title>Re: GP on Windows 11 - client certificate issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-on-windows-11-client-certificate-issue/m-p/490156#M104902</link>
      <description>&lt;P&gt;Thank you for info&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/184804"&gt;@Adrian_Jensen&lt;/a&gt;&lt;/P&gt;&lt;P&gt;In our case it's fresh installations of Windows 11. First the access with GP works for a couple of days, weeks, months... and then it stops. After that the new client certificate has to be installed and the access starts working again.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 May 2022 06:31:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-on-windows-11-client-certificate-issue/m-p/490156#M104902</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2022-05-24T06:31:17Z</dc:date>
    </item>
    <item>
      <title>Re: GP on Windows 11 - client certificate issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-on-windows-11-client-certificate-issue/m-p/490696#M104913</link>
      <description>&lt;P&gt;If you export/re-import the old certificate does it work again? Or does it have to be a new certificate?&lt;/P&gt;</description>
      <pubDate>Tue, 24 May 2022 15:27:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-on-windows-11-client-certificate-issue/m-p/490696#M104913</guid>
      <dc:creator>Adrian_Jensen</dc:creator>
      <dc:date>2022-05-24T15:27:58Z</dc:date>
    </item>
    <item>
      <title>Re: GP on Windows 11 - client certificate issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-on-windows-11-client-certificate-issue/m-p/491311#M104943</link>
      <description>&lt;P&gt;The certificates are marked as non exportable so they can't in a 'normal' way. I know there is a way with MimiKatz... &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 25 May 2022 07:15:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-on-windows-11-client-certificate-issue/m-p/491311#M104943</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2022-05-25T07:15:57Z</dc:date>
    </item>
  </channel>
</rss>

