<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Difference between 2FA certificate configuration methods in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/difference-between-2fa-certificate-configuration-methods/m-p/596644#M118703</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would generally match the authentication between the gateway and the portal. If you dont want users to have to enter their credentials on both the gateway and the portal, you could do something like just requiring certificates for the gateway authentication otherwise you should look at GlobalProtect Cookie Authentication&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/globalprotect/10-1/globalprotect-admin/globalprotect-user-authentication/how-does-the-app-know-what-credentials-to-supply/cookie-authentication-on-the-portal-or-gateway" target="_blank"&gt;Cookie Authentication on the Portal or Gateway (paloaltonetworks.com)&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 03 Sep 2024 18:41:33 GMT</pubDate>
    <dc:creator>Claw4609</dc:creator>
    <dc:date>2024-09-03T18:41:33Z</dc:date>
    <item>
      <title>Difference between 2FA certificate configuration methods</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/difference-between-2fa-certificate-configuration-methods/m-p/596244#M118616</link>
      <description>&lt;P&gt;Hi folks - very grateful for some support on this one.&lt;/P&gt;
&lt;P&gt;I've been led to believe that establishing 2FA on GlobalProtect using credentials and certificates as the authentication methods requires setting up a certificate profile and selecting "No" on the setting&amp;nbsp;&lt;SPAN&gt;"Allow Authentication with User&amp;nbsp;&lt;/SPAN&gt;Credentials OR Client Certificate&lt;SPAN&gt;".&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;My questions is, should that setting be selected on the Portal, the Gateway, or both? Is there any real difference? If, for instance, I selected the setting on the Portal only, could that interfere with the ability to reset Windows passwords on endpoint devices?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Thu, 29 Aug 2024 04:47:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/difference-between-2fa-certificate-configuration-methods/m-p/596244#M118616</guid>
      <dc:creator>bancomedia</dc:creator>
      <dc:date>2024-08-29T04:47:09Z</dc:date>
    </item>
    <item>
      <title>Re: Difference between 2FA certificate configuration methods</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/difference-between-2fa-certificate-configuration-methods/m-p/596644#M118703</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would generally match the authentication between the gateway and the portal. If you dont want users to have to enter their credentials on both the gateway and the portal, you could do something like just requiring certificates for the gateway authentication otherwise you should look at GlobalProtect Cookie Authentication&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/globalprotect/10-1/globalprotect-admin/globalprotect-user-authentication/how-does-the-app-know-what-credentials-to-supply/cookie-authentication-on-the-portal-or-gateway" target="_blank"&gt;Cookie Authentication on the Portal or Gateway (paloaltonetworks.com)&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Sep 2024 18:41:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/difference-between-2fa-certificate-configuration-methods/m-p/596644#M118703</guid>
      <dc:creator>Claw4609</dc:creator>
      <dc:date>2024-09-03T18:41:33Z</dc:date>
    </item>
  </channel>
</rss>

