<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Global Protect - &amp;quot;A valid client certificate is required for authentication&amp;quot; but works correctly for X days after PA restart in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-quot-a-valid-client-certificate-is-required-for/m-p/520655#M107914</link>
    <description>&lt;P&gt;Thank you&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;It is good to hear that somebody else has seen this issue before - it's not just me!&lt;/P&gt;
&lt;P&gt;If support are unable to find the issue soon I will try reinstalling as you did.&amp;nbsp; Thanks for the tip!&lt;/P&gt;
&lt;P&gt;Best regards,&lt;/P&gt;
&lt;P&gt;Dave&lt;/P&gt;</description>
    <pubDate>Tue, 08 Nov 2022 15:07:00 GMT</pubDate>
    <dc:creator>DavePalo</dc:creator>
    <dc:date>2022-11-08T15:07:00Z</dc:date>
    <item>
      <title>Global Protect - "A valid client certificate is required for authentication" but works correctly for X days after PA restart</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-quot-a-valid-client-certificate-is-required-for/m-p/520569#M107882</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just putting this out there to see if anybody else has had similar issues.&amp;nbsp; If you have, I would really appreciate you letting me know please!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Palo Alto PA-820 - HA (active/passive) - PanOS 9.1.5&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For several months we have had intermittent problems with Global Protect rejecting client certificates when our users try to connect to one of our HA pairs of Palo Altos.&amp;nbsp; Things work fine for several days, then we see just the occasional rejection, but usually within 24 hours of the first rejection, all client certificates are rejected by Global Protect.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If we fail over to the HA peer, client certificates are accepted again for several days until the same thing happens and we need to fail back.&amp;nbsp; Reboot, Repeat.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This issue first appeared when we were running PanOS 8.1 and has remained following an upgrade to 9.1.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have several pairs of Palo Alto devices running PanOS 9.1 configured in the same way (although different models) and none of the others have suffered from this problem.&amp;nbsp; These all use the same client certificates / CAs and the Global Protect configuration is identical.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Some more relevant info:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Both certificate and credentials (AD / SAML) are required to connect to Global Protect.&lt;/LI&gt;
&lt;LI&gt;CRLs are used and we have confirmed that valid CRLs are present at the time of the issue (we use 2 CAs).&lt;/LI&gt;
&lt;LI&gt;Restarting the&amp;nbsp;&lt;SPAN&gt;sslvpn-web-server process does not help.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Recent issues such as DP/MP time sync have been eliminated.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN&gt;We have had a case open with Palo Alto support since August but little progress has been made.&amp;nbsp; The tech support file does not seem to contain any clues.&amp;nbsp; Additional debug level logs have been provided too but&amp;nbsp;have not proved useful so far.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If you have had similar issues or have any suggestions for things to check while Palo Alto are reviewing my uploads, it would be really appreciated.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you,&lt;/P&gt;
&lt;P&gt;Dave&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Nov 2022 23:55:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-quot-a-valid-client-certificate-is-required-for/m-p/520569#M107882</guid>
      <dc:creator>DavePalo</dc:creator>
      <dc:date>2022-11-07T23:55:53Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect - "A valid client certificate is required for authentication" but works correctly for X days after PA restart</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-quot-a-valid-client-certificate-is-required-for/m-p/520584#M107885</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9189"&gt;@DavePalo&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;I ran into this exact same issue a while backchat wasn't being solved by software and just got to be extremely annoying more than anything else. I eventually just reinstalled from maintenance mode on the two HA hosts and restored the configuration. That actually fixed it and I haven't had any issues with those two hosts since. Never did actually figure out what was causing the issue, but that thankfully fixed it.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Nov 2022 01:24:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-quot-a-valid-client-certificate-is-required-for/m-p/520584#M107885</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2022-11-08T01:24:38Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect - "A valid client certificate is required for authentication" but works correctly for X days after PA restart</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-quot-a-valid-client-certificate-is-required-for/m-p/520655#M107914</link>
      <description>&lt;P&gt;Thank you&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;It is good to hear that somebody else has seen this issue before - it's not just me!&lt;/P&gt;
&lt;P&gt;If support are unable to find the issue soon I will try reinstalling as you did.&amp;nbsp; Thanks for the tip!&lt;/P&gt;
&lt;P&gt;Best regards,&lt;/P&gt;
&lt;P&gt;Dave&lt;/P&gt;</description>
      <pubDate>Tue, 08 Nov 2022 15:07:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-quot-a-valid-client-certificate-is-required-for/m-p/520655#M107914</guid>
      <dc:creator>DavePalo</dc:creator>
      <dc:date>2022-11-08T15:07:00Z</dc:date>
    </item>
  </channel>
</rss>

