<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Browser not prompting/selecting client cert for GP portal in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/browser-not-prompting-selecting-client-cert-for-gp-portal/m-p/1236027#M124960</link>
    <description>&lt;P&gt;Thanks for this! This solved the issue for me as well.&lt;/P&gt;</description>
    <pubDate>Thu, 14 Aug 2025 20:04:01 GMT</pubDate>
    <dc:creator>TErwineFIATech</dc:creator>
    <dc:date>2025-08-14T20:04:01Z</dc:date>
    <item>
      <title>Browser not prompting/selecting client cert for GP portal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/browser-not-prompting-selecting-client-cert-for-gp-portal/m-p/222183#M63909</link>
      <description>&lt;P&gt;Does anyone know exactly what is needed for browser to either select or prompt for client certificae when connecting to GP portal?&lt;/P&gt;&lt;P&gt;I know you need a client sert in personal user store and certificate profile on GP portal.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But still i find the behaviour very random.&lt;/P&gt;&lt;P&gt;I have 3 GP portals with self signed CA. And a few test machines.&lt;/P&gt;&lt;P&gt;For 1st portal get prompted if I have the correct CA in trusted root and a client certificate from the same root from every machine.&lt;/P&gt;&lt;P&gt;For&amp;nbsp;2nd portal i have mixed situation; some machines get prompted, some don't.&lt;/P&gt;&lt;P&gt;For 3rd portal I don't get prompted anywhere.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There is never any difference between different browsers. Either all prompt or none.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I also have one test machine which prompts for 1st portal, but doesn't prompt for 2nd even tho it doesn't have either of those 2 CAs as trusted root.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So what are all the required components to have a browser either use or prompt for user certificate?&lt;/P&gt;&lt;P&gt;From my testing; you need client cert in user store, cert from the same CA in trusted root, appropriate cert profile on GP portal. But in some cases even when you have all those the browser doesn't use or prompt for client cert. What else is missing?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I know it's not PA issue, but non-PA self signed CA is the one on first portal which works the best. And most issues are happeneing on PA self signed CAs. .&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Jul 2018 12:00:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/browser-not-prompting-selecting-client-cert-for-gp-portal/m-p/222183#M63909</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2018-07-13T12:00:24Z</dc:date>
    </item>
    <item>
      <title>Re: Browser not prompting/selecting client cert for GP portal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/browser-not-prompting-selecting-client-cert-for-gp-portal/m-p/222196#M63912</link>
      <description>&lt;P&gt;Just to add; I don't have neither CRL nor OCSP checking and all 3 'block session' options in certificate profile are off.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Jul 2018 13:29:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/browser-not-prompting-selecting-client-cert-for-gp-portal/m-p/222196#M63912</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2018-07-13T13:29:20Z</dc:date>
    </item>
    <item>
      <title>Re: Browser not prompting/selecting client cert for GP portal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/browser-not-prompting-selecting-client-cert-for-gp-portal/m-p/222480#M63983</link>
      <description>&lt;P&gt;After some packet capture I think it comes down to whther GP portal sends 'certificate request' during TLS handshake or doesn't. But I can't figure out why it does sometimes and why it doesn't.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyone knows what conditions must be met for GP portal to send&amp;nbsp;&lt;SPAN&gt;'certificate request' during TLS handshake? Only certificate profile isn't enough.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Jul 2018 06:57:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/browser-not-prompting-selecting-client-cert-for-gp-portal/m-p/222480#M63983</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2018-07-17T06:57:36Z</dc:date>
    </item>
    <item>
      <title>Re: Browser not prompting/selecting client cert for GP portal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/browser-not-prompting-selecting-client-cert-for-gp-portal/m-p/565939#M114408</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/10238"&gt;@santonic&lt;/a&gt;&amp;nbsp;, did you find something?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am trying to find out what is the logic. I have 2 PAs, each with just 1 portal, both are sending the&amp;nbsp;&lt;SPAN&gt;certificate request during TLS handshake (self signed certificate). If i create a second portal on both PA, using the same certificate profile, the&amp;nbsp;certificate request is missing.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I am now testing on a old PA3050 creating a similar configuration, but&amp;nbsp;certificate request is not sent&amp;nbsp;during TLS handshake.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Regards&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Christian&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Nov 2023 07:09:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/browser-not-prompting-selecting-client-cert-for-gp-portal/m-p/565939#M114408</guid>
      <dc:creator>Cbrasolin</dc:creator>
      <dc:date>2023-11-16T07:09:00Z</dc:date>
    </item>
    <item>
      <title>Re: Browser not prompting/selecting client cert for GP portal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/browser-not-prompting-selecting-client-cert-for-gp-portal/m-p/566815#M114539</link>
      <description>&lt;P&gt;Hey &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/125105"&gt;@Cbrasolin&lt;/a&gt;&amp;nbsp;. I'm afraid I don't remember how this story ended back in 2018, I guess I'm getting old...&amp;nbsp;&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Nov 2023 08:20:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/browser-not-prompting-selecting-client-cert-for-gp-portal/m-p/566815#M114539</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2023-11-23T08:20:52Z</dc:date>
    </item>
    <item>
      <title>Re: Browser not prompting/selecting client cert for GP portal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/browser-not-prompting-selecting-client-cert-for-gp-portal/m-p/566970#M114555</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/10238"&gt;@santonic&lt;/a&gt;&amp;nbsp;, i found the problem.&lt;/P&gt;
&lt;P&gt;Both portal and gateway (in the same interface) must use the same certificate profile under authentication-&amp;gt;certificate profile. If the portal has a certificate profile configured, but the gateway not, the request in the tls handshake is missing. I suppose that since the portal and gateway share the same web server daemon, the configuration must be consistent.&lt;/P&gt;
&lt;P&gt;It seem also that if certificate is verified under the agent configuration "machine device check", is not enough to have the certificate profile under the portal data collection tab, the profile is needed also on the authentication tab.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Anyway, my case was that the gateway was not configured with the certificate profile.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Fri, 24 Nov 2023 10:16:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/browser-not-prompting-selecting-client-cert-for-gp-portal/m-p/566970#M114555</guid>
      <dc:creator>Cbrasolin</dc:creator>
      <dc:date>2023-11-24T10:16:08Z</dc:date>
    </item>
    <item>
      <title>Re: Browser not prompting/selecting client cert for GP portal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/browser-not-prompting-selecting-client-cert-for-gp-portal/m-p/567379#M114599</link>
      <description>&lt;P&gt;Ok, thanx for the info. But I think I have some deployments, where certificate is required to connect to gateway but not required when connecting to portal. But as I said I am not certain, I will have to check.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Nov 2023 11:30:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/browser-not-prompting-selecting-client-cert-for-gp-portal/m-p/567379#M114599</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2023-11-28T11:30:41Z</dc:date>
    </item>
    <item>
      <title>Re: Browser not prompting/selecting client cert for GP portal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/browser-not-prompting-selecting-client-cert-for-gp-portal/m-p/1236027#M124960</link>
      <description>&lt;P&gt;Thanks for this! This solved the issue for me as well.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Aug 2025 20:04:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/browser-not-prompting-selecting-client-cert-for-gp-portal/m-p/1236027#M124960</guid>
      <dc:creator>TErwineFIATech</dc:creator>
      <dc:date>2025-08-14T20:04:01Z</dc:date>
    </item>
  </channel>
</rss>

