<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Any idea about 3rd party verisign certificate with GlobalProtect ? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/any-idea-about-3rd-party-verisign-certificate-with-globalprotect/m-p/19519#M14251</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN&gt;User certificates were created from Window's Server Cert Authority - we obtain user certs this way &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://domaincontroller/certsrv"&gt;https://domaincontroller/certsrv&lt;/A&gt;&lt;SPAN&gt; since that is where our certificate authority is as the moment. If you are logged in with the user then they just simply walk through the process and it add's it to their machine. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm not sure I understand the Gateway cert question, we generated a third party cert and specified both in the portal / gateway this cert for our server cert. I also had to use our internal root cert to handle the user cert authentication.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 20 Feb 2013 16:03:43 GMT</pubDate>
    <dc:creator>cmateam</dc:creator>
    <dc:date>2013-02-20T16:03:43Z</dc:date>
    <item>
      <title>Any idea about 3rd party verisign certificate with GlobalProtect ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/any-idea-about-3rd-party-verisign-certificate-with-globalprotect/m-p/19507#M14239</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We were using sslvpn with PA 's certificate.Now we bought 3rd party cert. from Verisign and imported it as using server certificate&lt;/P&gt;&lt;P&gt;But Global Protect gives an error as "Protocol Error: Check server sertificate"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have searched KnowledgePoint but could not find anything for this error.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any idea ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Jul 2012 13:20:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/any-idea-about-3rd-party-verisign-certificate-with-globalprotect/m-p/19507#M14239</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2012-07-30T13:20:47Z</dc:date>
    </item>
    <item>
      <title>Re: Any idea about 3rd party verisign certificate with GlobalProtect ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/any-idea-about-3rd-party-verisign-certificate-with-globalprotect/m-p/19508#M14240</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think I've had the same problem.&amp;nbsp; PAN's documentation, and what others tell you to do is inaccurate. I happened to stumble on this forum thread, &lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/thread/4054" title="https://live.paloaltonetworks.com/thread/4054"&gt;https://live.paloaltonetworks.com/thread/4054&lt;/A&gt; and found this answer to be very helpful instead of generating a plain cert on the PA-FW, use your purchased cert instead:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote" modifiedtitle="true"&gt;
&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;1) Generate a plain Cert in Palo Alto(Not signed and not a Certificate Authority)&lt;/P&gt;
&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;2) Global Protect &amp;gt; Portals &amp;gt; Your Portal &amp;gt; Portal Configuration &amp;gt; Set "Client Certificate" and "Client Certificate Profile" to "None".&amp;nbsp; Set "Server Certificate" to the Cert you made in step 1.&lt;/P&gt;
&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;3) Move to Client Configuration tab &amp;gt; Delete any Root CA's that are set.&lt;/P&gt;
&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;4) Global Protect &amp;gt; Gateways &amp;gt; Your Gateway &amp;gt; General &amp;gt; Set "Server Certificate" to the Cert you created in step 1.&amp;nbsp; Set "Client Certificate Profile to "None".&lt;/P&gt;
&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was getting a very similar error doing it any other way, but this seemed to fix the problem.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Jul 2012 17:39:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/any-idea-about-3rd-party-verisign-certificate-with-globalprotect/m-p/19508#M14240</guid>
      <dc:creator>cmateam</dc:creator>
      <dc:date>2012-07-30T17:39:16Z</dc:date>
    </item>
    <item>
      <title>Re: Any idea about 3rd party verisign certificate with GlobalProtect ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/any-idea-about-3rd-party-verisign-certificate-with-globalprotect/m-p/19509#M14241</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for help but where is the cert that I have bought ? I could not find it at your answer.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 31 Jul 2012 00:59:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/any-idea-about-3rd-party-verisign-certificate-with-globalprotect/m-p/19509#M14241</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2012-07-31T00:59:17Z</dc:date>
    </item>
    <item>
      <title>Re: Any idea about 3rd party verisign certificate with GlobalProtect ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/any-idea-about-3rd-party-verisign-certificate-with-globalprotect/m-p/19510#M14242</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is typically provided to you either by an email or at time of purchase through the web browser.&amp;nbsp; You would save it to notepad and save it to a .crt file.&amp;nbsp; Then you upload the cert to Device-&amp;gt;Certificates&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 31 Jul 2012 15:36:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/any-idea-about-3rd-party-verisign-certificate-with-globalprotect/m-p/19510#M14242</guid>
      <dc:creator>cmateam</dc:creator>
      <dc:date>2012-07-31T15:36:21Z</dc:date>
    </item>
    <item>
      <title>Re: Any idea about 3rd party verisign certificate with GlobalProtect ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/any-idea-about-3rd-party-verisign-certificate-with-globalprotect/m-p/19511#M14243</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I know that.I have the file already.You mean the solution is like this :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;BLOCKQUOTE class="jive-quote"&gt;&lt;P style="font-size: 12px; font-family: Arial,Helvetica,sans-serif; color: #000000; background-color: #ffffff;"&gt;1) Upload cert. you &lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;bought&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial,Helvetica,sans-serif; color: #000000; background-color: #ffffff;"&gt;2) Global Protect &amp;gt; Portals &amp;gt; Your Portal &amp;gt; Portal Configuration &amp;gt; Set "Client Certificate" and "Client Certificate Profile" to "None".&amp;nbsp; Set "Server Certificate" to the Cert&amp;nbsp; you &lt;STRONG style="text-decoration: underline;"&gt;uploaded&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial,Helvetica,sans-serif; color: #000000; background-color: #ffffff;"&gt;3) Move to Client Configuration tab &amp;gt; Delete any Root CA's that are set.&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial,Helvetica,sans-serif; color: #000000; background-color: #ffffff;"&gt;4) Global Protect &amp;gt; Gateways &amp;gt; Your Gateway &amp;gt; General &amp;gt; Set "Server Certificate" to the Cert you &lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;uploaded&lt;/STRONG&gt;&lt;/SPAN&gt;. Set "Client Certificate Profile to "None".&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;is this the solution ? Because I will try it tomorrow &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 31 Jul 2012 15:58:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/any-idea-about-3rd-party-verisign-certificate-with-globalprotect/m-p/19511#M14243</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2012-07-31T15:58:57Z</dc:date>
    </item>
    <item>
      <title>Re: Any idea about 3rd party verisign certificate with GlobalProtect ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/any-idea-about-3rd-party-verisign-certificate-with-globalprotect/m-p/19512#M14244</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Correct.&amp;nbsp; Assuming that is what you are trying to accomplish.&amp;nbsp; Presenting the VPN portal in a way that does not give a certificate warning.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 31 Jul 2012 16:03:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/any-idea-about-3rd-party-verisign-certificate-with-globalprotect/m-p/19512#M14244</guid>
      <dc:creator>cmateam</dc:creator>
      <dc:date>2012-07-31T16:03:02Z</dc:date>
    </item>
    <item>
      <title>Re: Any idea about 3rd party verisign certificate with GlobalProtect ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/any-idea-about-3rd-party-verisign-certificate-with-globalprotect/m-p/19513#M14245</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks.I will try and write back.Thank you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 31 Jul 2012 16:06:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/any-idea-about-3rd-party-verisign-certificate-with-globalprotect/m-p/19513#M14245</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2012-07-31T16:06:41Z</dc:date>
    </item>
    <item>
      <title>Re: Any idea about 3rd party verisign certificate with GlobalProtect ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/any-idea-about-3rd-party-verisign-certificate-with-globalprotect/m-p/19514#M14246</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I tried that.Not selecting any client certificate fixed the problem.Thank you very much.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I wonder if we want to use client certificate also, what steps will we do.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for help&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Aug 2012 13:43:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/any-idea-about-3rd-party-verisign-certificate-with-globalprotect/m-p/19514#M14246</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2012-08-02T13:43:14Z</dc:date>
    </item>
    <item>
      <title>Re: Any idea about 3rd party verisign certificate with GlobalProtect ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/any-idea-about-3rd-party-verisign-certificate-with-globalprotect/m-p/19515#M14247</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The Client cert depends on how you want to setup that. We use AD in our environment, so we generate user certificates from our AD CA.&amp;nbsp; You can generate a signed cert within the PA too and use that.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Aug 2012 16:24:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/any-idea-about-3rd-party-verisign-certificate-with-globalprotect/m-p/19515#M14247</guid>
      <dc:creator>cmateam</dc:creator>
      <dc:date>2012-08-02T16:24:19Z</dc:date>
    </item>
    <item>
      <title>Re: Any idea about 3rd party verisign certificate with GlobalProtect ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/any-idea-about-3rd-party-verisign-certificate-with-globalprotect/m-p/19516#M14248</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ok.I understand AD.&lt;/P&gt;&lt;P&gt;can we use the certificate that we bought for clients also ?(it is wildcard cert)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Aug 2012 16:28:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/any-idea-about-3rd-party-verisign-certificate-with-globalprotect/m-p/19516#M14248</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2012-08-02T16:28:46Z</dc:date>
    </item>
    <item>
      <title>Re: Any idea about 3rd party verisign certificate with GlobalProtect ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/any-idea-about-3rd-party-verisign-certificate-with-globalprotect/m-p/19517#M14249</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You may be able to, but I don't know how to configure that.&amp;nbsp; We used AD CA certs, it was easier.&amp;nbsp; To sign individual certs with the purchased one, I don't think you can do that.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Aug 2012 04:59:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/any-idea-about-3rd-party-verisign-certificate-with-globalprotect/m-p/19517#M14249</guid>
      <dc:creator>cmateam</dc:creator>
      <dc:date>2012-08-15T04:59:35Z</dc:date>
    </item>
    <item>
      <title>Re: Any idea about 3rd party verisign certificate with GlobalProtect ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/any-idea-about-3rd-party-verisign-certificate-with-globalprotect/m-p/19518#M14250</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;How did you generate user certificates from AD?&lt;/P&gt;&lt;P&gt;Which template did you use?&lt;/P&gt;&lt;P&gt;Did you generate a Gateway Certificate too?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 16 Feb 2013 00:50:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/any-idea-about-3rd-party-verisign-certificate-with-globalprotect/m-p/19518#M14250</guid>
      <dc:creator>SistemasCajamar</dc:creator>
      <dc:date>2013-02-16T00:50:52Z</dc:date>
    </item>
    <item>
      <title>Re: Any idea about 3rd party verisign certificate with GlobalProtect ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/any-idea-about-3rd-party-verisign-certificate-with-globalprotect/m-p/19519#M14251</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN&gt;User certificates were created from Window's Server Cert Authority - we obtain user certs this way &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://domaincontroller/certsrv"&gt;https://domaincontroller/certsrv&lt;/A&gt;&lt;SPAN&gt; since that is where our certificate authority is as the moment. If you are logged in with the user then they just simply walk through the process and it add's it to their machine. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm not sure I understand the Gateway cert question, we generated a third party cert and specified both in the portal / gateway this cert for our server cert. I also had to use our internal root cert to handle the user cert authentication.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Feb 2013 16:03:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/any-idea-about-3rd-party-verisign-certificate-with-globalprotect/m-p/19519#M14251</guid>
      <dc:creator>cmateam</dc:creator>
      <dc:date>2013-02-20T16:03:43Z</dc:date>
    </item>
    <item>
      <title>Re: Any idea about 3rd party verisign certificate with GlobalProtect ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/any-idea-about-3rd-party-verisign-certificate-with-globalprotect/m-p/19520#M14252</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;My question is about the type of certificate you have to issue as there are several templates on the Windows CA&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Feb 2013 09:02:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/any-idea-about-3rd-party-verisign-certificate-with-globalprotect/m-p/19520#M14252</guid>
      <dc:creator>SistemasCajamar</dc:creator>
      <dc:date>2013-02-22T09:02:05Z</dc:date>
    </item>
    <item>
      <title>Re: Any idea about 3rd party verisign certificate with GlobalProtect ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/any-idea-about-3rd-party-verisign-certificate-with-globalprotect/m-p/19521#M14253</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I believe all you need is a user certificate.&amp;nbsp; When going to the certsrv in a web browser, logging in with the user name/password - for us just generates a user certificate.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 23 Feb 2013 14:13:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/any-idea-about-3rd-party-verisign-certificate-with-globalprotect/m-p/19521#M14253</guid>
      <dc:creator>cmateam</dc:creator>
      <dc:date>2013-02-23T14:13:45Z</dc:date>
    </item>
  </channel>
</rss>

