<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Global Protect Portal with Certificate Profile - client certificate required after upgrading to 6.0 in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-portal-with-certificate-profile-client/m-p/16019#M11703</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Okay I finally got it to work. I followed the config in the global protect admin guide for 6.0 and download the latest client and I can see that it works now&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 17 Jun 2014 16:44:37 GMT</pubDate>
    <dc:creator>ahpadmin</dc:creator>
    <dc:date>2014-06-17T16:44:37Z</dc:date>
    <item>
      <title>Global Protect Portal with Certificate Profile - client certificate required after upgrading to 6.0</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-portal-with-certificate-profile-client/m-p/16017#M11701</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are running Global Protect with pre-logon. The GP Portal needs to allow users to login from "clean" computers without machine certificates, and at the same time allow pre-logon user(and other users) to authenticate with machine certificate. This has in 5.0 been done by using a certificate profile with the username field set to "none".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This was working fine in 5.0, but after upgrading to 6.0 I get a "valid certificate is required" when accessing the GP portal page through a web-browser.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I found the following article describing change in default behavior from 4.1 to 5.0 due to implementation of pre-logon.&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-4257"&gt;GP Portal No Longer Prompting for Client Certificates Following PAN-OS v5.0.x Upgrade&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has this been changed again in 6.0? How can I get a Global Protect Portal to support both user/password and machine certificate authentication in 6.0?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Tor&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Jun 2014 13:12:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-portal-with-certificate-profile-client/m-p/16017#M11701</guid>
      <dc:creator>torm</dc:creator>
      <dc:date>2014-06-12T13:12:19Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect Portal with Certificate Profile - client certificate required after upgrading to 6.0</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-portal-with-certificate-profile-client/m-p/16018#M11702</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm trying to figure this out as well. I've been working on this for a day or so now with no luck. I'll let you know if I am able to figure it out. Hopefully someone from PA can offer some assistance.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Jun 2014 15:41:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-portal-with-certificate-profile-client/m-p/16018#M11702</guid>
      <dc:creator>ahpadmin</dc:creator>
      <dc:date>2014-06-17T15:41:26Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect Portal with Certificate Profile - client certificate required after upgrading to 6.0</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-portal-with-certificate-profile-client/m-p/16019#M11703</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Okay I finally got it to work. I followed the config in the global protect admin guide for 6.0 and download the latest client and I can see that it works now&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Jun 2014 16:44:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-portal-with-certificate-profile-client/m-p/16019#M11703</guid>
      <dc:creator>ahpadmin</dc:creator>
      <dc:date>2014-06-17T16:44:37Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect Portal with Certificate Profile - client certificate required after upgrading to 6.0</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-portal-with-certificate-profile-client/m-p/16020#M11704</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your reply!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are able to authenticate to the portal using bot username/password and computer/client certificate?&lt;/P&gt;&lt;P&gt;Or are you using just username/password for the portal? Read through the admin guide one more time, and it seems like I got it wrong, and that you donæt need a certificate profile on the portal for pre-logon after all. Is this correct?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"After authentication succeeds, the portal pushes the client configuration to the agent along with a &lt;/P&gt;&lt;P&gt;cookie that will be used for portal authentication to receive a configuration refresh. Then, when a client system &lt;/P&gt;&lt;P&gt;attempts to connect in pre-logon mode, it will use cookie to authenticate to the portal and receive its pre-logon &lt;/P&gt;&lt;P&gt;client configuration."&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Jun 2014 19:53:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-portal-with-certificate-profile-client/m-p/16020#M11704</guid>
      <dc:creator>torm</dc:creator>
      <dc:date>2014-06-17T19:53:38Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect Portal with Certificate Profile - client certificate required after upgrading to 6.0</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-portal-with-certificate-profile-client/m-p/16021#M11705</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ensure that the certificates and their signer certificates (in a chain) are all included in the GP Portal &amp;gt;&amp;gt; Client Configuration &amp;gt;&amp;gt; Root CA section. That became mandatory in the later versions of PAN OS v5.0x&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Jun 2014 21:45:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-portal-with-certificate-profile-client/m-p/16021#M11705</guid>
      <dc:creator>sjamaluddin</dc:creator>
      <dc:date>2014-06-17T21:45:31Z</dc:date>
    </item>
  </channel>
</rss>

