<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HIPs check for Client Side Certificate in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/hips-check-for-client-side-certificate/m-p/513783#M106690</link>
    <description>&lt;PRE class="" dir="ltr" data-placeholder="Traducción"&gt;&lt;SPAN class=""&gt;hello, I have not found information associated with being able to implement any hip control associated with a particular certificate, I need to separate the external and internal users of a client but we need to validate the certificate, internal and external will have a different certificate, there will be some documentation available for Current versions? Is it possible for the globalprotect client to take the data from the certificate installed on the pc device and compare these data with the hip profile validate certificate and comply or not with the posture?&lt;BR /&gt;thanks&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;PRE id="tw-target-text" class="" dir="ltr" data-placeholder="Traducción"&gt;&amp;nbsp;&lt;/PRE&gt;</description>
    <pubDate>Thu, 01 Sep 2022 20:42:11 GMT</pubDate>
    <dc:creator>jmsepulveda</dc:creator>
    <dc:date>2022-09-01T20:42:11Z</dc:date>
    <item>
      <title>HIPs check for Client Side Certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/hips-check-for-client-side-certificate/m-p/195979#M58452</link>
      <description>&lt;P&gt;Is it possible to use HIPs to verify the presence of a Client Side Certificate such as GlobalProtect cert for a computer and also check for cert on a mobile device? If the device has the cert then we would allow it through a firewall policy.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jan 2018 19:36:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/hips-check-for-client-side-certificate/m-p/195979#M58452</guid>
      <dc:creator>CZellars</dc:creator>
      <dc:date>2018-01-19T19:36:45Z</dc:date>
    </item>
    <item>
      <title>Re: HIPs check for Client Side Certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/hips-check-for-client-side-certificate/m-p/195987#M58454</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Would this device you are attempting to check behind the firewall or connecting via a client VPN connection?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jan 2018 19:42:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/hips-check-for-client-side-certificate/m-p/195987#M58454</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-01-19T19:42:06Z</dc:date>
    </item>
    <item>
      <title>Re: HIPs check for Client Side Certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/hips-check-for-client-side-certificate/m-p/195989#M58456</link>
      <description>&lt;P&gt;Thanks for replying and it would be connecting via a GlobalProtect VPN client.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jan 2018 19:43:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/hips-check-for-client-side-certificate/m-p/195989#M58456</guid>
      <dc:creator>CZellars</dc:creator>
      <dc:date>2018-01-19T19:43:44Z</dc:date>
    </item>
    <item>
      <title>Re: HIPs check for Client Side Certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/hips-check-for-client-side-certificate/m-p/195990#M58457</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;GP has a certificate it can use to verify the client. Check this article out and see if it meets your requirements.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-GlobalProtect-Portal-with-Client-Cert/tac-p/58923#M684" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-GlobalProtect-Portal-with-Client-Cert/tac-p/58923#M684&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/80/globalprotect/globalprotect-admin-guide/get-started/enable-ssl-between-globalprotect-components/globalprotect-certificate-best-practices" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/80/globalprotect/globalprotect-admin-guide/get-started/enable-ssl-between-globalprotect-components/globalprotect-certificate-best-practices&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers!&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jan 2018 19:49:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/hips-check-for-client-side-certificate/m-p/195990#M58457</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-01-19T19:49:14Z</dc:date>
    </item>
    <item>
      <title>Re: HIPs check for Client Side Certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/hips-check-for-client-side-certificate/m-p/195999#M58458</link>
      <description>&lt;P&gt;Thanks for that info. The issue is that we would need to check for a specfic certificate:&amp;nbsp;the machine certificate and I cannot seem to find a registry entry that allows me to do that. I believe I need to open a case with Palo Alto Support and I will report back with results if possible. Thank You&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jan 2018 20:25:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/hips-check-for-client-side-certificate/m-p/195999#M58458</guid>
      <dc:creator>CZellars</dc:creator>
      <dc:date>2018-01-19T20:25:09Z</dc:date>
    </item>
    <item>
      <title>Re: HIPs check for Client Side Certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/hips-check-for-client-side-certificate/m-p/196713#M58560</link>
      <description>&lt;P&gt;Well in the end we did not find a way to use HIPs custom checks in order to verify a machine certificate. The issue being that the certificate stuff is stored in the registry in blob format which doesnt allow parsing for specifics.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have convinced the team to move forward by using GlobalProtect Certificate check against our PKI&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jan 2018 19:38:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/hips-check-for-client-side-certificate/m-p/196713#M58560</guid>
      <dc:creator>CZellars</dc:creator>
      <dc:date>2018-01-24T19:38:42Z</dc:date>
    </item>
    <item>
      <title>Re: HIPs check for Client Side Certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/hips-check-for-client-side-certificate/m-p/513783#M106690</link>
      <description>&lt;PRE class="" dir="ltr" data-placeholder="Traducción"&gt;&lt;SPAN class=""&gt;hello, I have not found information associated with being able to implement any hip control associated with a particular certificate, I need to separate the external and internal users of a client but we need to validate the certificate, internal and external will have a different certificate, there will be some documentation available for Current versions? Is it possible for the globalprotect client to take the data from the certificate installed on the pc device and compare these data with the hip profile validate certificate and comply or not with the posture?&lt;BR /&gt;thanks&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;PRE id="tw-target-text" class="" dir="ltr" data-placeholder="Traducción"&gt;&amp;nbsp;&lt;/PRE&gt;</description>
      <pubDate>Thu, 01 Sep 2022 20:42:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/hips-check-for-client-side-certificate/m-p/513783#M106690</guid>
      <dc:creator>jmsepulveda</dc:creator>
      <dc:date>2022-09-01T20:42:11Z</dc:date>
    </item>
    <item>
      <title>Re: HIPs check for Client Side Certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/hips-check-for-client-side-certificate/m-p/514016#M106726</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/36153"&gt;@jmsepulveda&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As from PAN-OS 9.0, &lt;SPAN class="news-body-text"&gt;&lt;SPAN&gt;GlobalProtect introduced Certificate as an element in HIP Object. &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="news-body-text"&gt;&lt;SPAN&gt;This allows customers to identify managed devices and control access based on the device based on the specific machine certificate (including certificate attributes) present on the device.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="news-body-text"&gt;&lt;SPAN&gt;source: &lt;A href="https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-web-interface-help/globalprotect/objects-globalprotect-hip-objects/hip-objects-certificate-tab" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-web-interface-help/globalprotect/objects-globalprotect-hip-objects/hip-objects-certificate-tab&lt;/A&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="news-body-text"&gt;&lt;SPAN&gt;Hope this helps,&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="news-body-text"&gt;&lt;SPAN&gt;-Kiwi.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV id="ConnectiveDocSignExtentionInstalled" data-extension-version="1.0.4"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Tue, 06 Sep 2022 09:30:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/hips-check-for-client-side-certificate/m-p/514016#M106726</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2022-09-06T09:30:29Z</dc:date>
    </item>
    <item>
      <title>Re: HIPs check for Client Side Certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/hips-check-for-client-side-certificate/m-p/514732#M106825</link>
      <description>&lt;PRE class="" dir="ltr" data-placeholder="Traducción"&gt;&lt;SPAN class=""&gt;Hello, but that kb does not provide much information, I had already seen it before, it does not indicate what type of certificates can be used and if&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;PRE class="" dir="ltr" data-placeholder="Traducción"&gt;&lt;SPAN class=""&gt;yo need to place this certificate in some other firewall configuration, the globalprotect agent is able to read the certificate information , whenever I look at the globalprotect I see the certificate section blank&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Sep 2022 15:40:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/hips-check-for-client-side-certificate/m-p/514732#M106825</guid>
      <dc:creator>jmsepulveda</dc:creator>
      <dc:date>2022-09-13T15:40:36Z</dc:date>
    </item>
  </channel>
</rss>

