<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Mac OS X Keychain asks for password on every connect in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/mac-os-x-keychain-asks-for-password-on-every-connect/m-p/1995#M1467</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;GlobalProtect has separate portal and &lt;/P&gt;&lt;P&gt;gateway(s) that require separate authentication (even if they reside in the same physical PAN device). For users who &lt;/P&gt;&lt;P&gt;use one time password (OTP) to authenticate, this means they will need to type the OTP twice (one for portal and the &lt;/P&gt;&lt;P&gt;other for gateway in GP). At present, the only workaround is to use static user/password for portal authentication and ©2012, Palo Alto Networks, Inc. [4]&lt;/P&gt;&lt;P&gt;leave the gateway authentication to require OTP. Another workaround is to make the portal only reachable from &lt;/P&gt;&lt;P&gt;inside office. This will force GP client to use the cached portal config file and avoid requesting OTP twice.&lt;/P&gt;&lt;P&gt;Ref :&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/docs/DOC-2568"&gt;https://live.paloaltonetworks.com/docs/DOC-2568&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Ref &lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/docs/DOC-4560"&gt;https://live.paloaltonetworks.com/docs/DOC-4560&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 25 Apr 2013 01:30:13 GMT</pubDate>
    <dc:creator>UhMayYeah</dc:creator>
    <dc:date>2013-04-25T01:30:13Z</dc:date>
    <item>
      <title>Mac OS X Keychain asks for password on every connect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/mac-os-x-keychain-asks-for-password-on-every-connect/m-p/1994#M1466</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We have Machine Certificates on our Mac OS X Lion clients.&amp;nbsp; When the portal accesses the system keychain to verify the certificates, it prompts the users twice to allow this action.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this expected behavior?&amp;nbsp; How do we get it to stop asking for permission to access the machine certificate every time a client connects to portal?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Apr 2013 22:24:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/mac-os-x-keychain-asks-for-password-on-every-connect/m-p/1994#M1466</guid>
      <dc:creator>ManillaTechOps</dc:creator>
      <dc:date>2013-04-24T22:24:28Z</dc:date>
    </item>
    <item>
      <title>Re: Mac OS X Keychain asks for password on every connect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/mac-os-x-keychain-asks-for-password-on-every-connect/m-p/1995#M1467</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;GlobalProtect has separate portal and &lt;/P&gt;&lt;P&gt;gateway(s) that require separate authentication (even if they reside in the same physical PAN device). For users who &lt;/P&gt;&lt;P&gt;use one time password (OTP) to authenticate, this means they will need to type the OTP twice (one for portal and the &lt;/P&gt;&lt;P&gt;other for gateway in GP). At present, the only workaround is to use static user/password for portal authentication and ©2012, Palo Alto Networks, Inc. [4]&lt;/P&gt;&lt;P&gt;leave the gateway authentication to require OTP. Another workaround is to make the portal only reachable from &lt;/P&gt;&lt;P&gt;inside office. This will force GP client to use the cached portal config file and avoid requesting OTP twice.&lt;/P&gt;&lt;P&gt;Ref :&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/docs/DOC-2568"&gt;https://live.paloaltonetworks.com/docs/DOC-2568&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Ref &lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/docs/DOC-4560"&gt;https://live.paloaltonetworks.com/docs/DOC-4560&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Apr 2013 01:30:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/mac-os-x-keychain-asks-for-password-on-every-connect/m-p/1995#M1467</guid>
      <dc:creator>UhMayYeah</dc:creator>
      <dc:date>2013-04-25T01:30:13Z</dc:date>
    </item>
    <item>
      <title>Re: Mac OS X Keychain asks for password on every connect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/mac-os-x-keychain-asks-for-password-on-every-connect/m-p/1996#M1468</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We are not using a One Time Password.&amp;nbsp; The portal is requesting the x.509 certificate from the Mac OS X "system" keychain.&amp;nbsp; When it makes this request, the user is prompted to enter a local administrator username and password to allow Global Protect to verify this certificate.&amp;nbsp; Is there a way to have Global Protect ether a) cache the certificate b) "remember" decision to allow access to certificate in keychain.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Apr 2013 16:59:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/mac-os-x-keychain-asks-for-password-on-every-connect/m-p/1996#M1468</guid>
      <dc:creator>ManillaTechOps</dc:creator>
      <dc:date>2013-04-25T16:59:09Z</dc:date>
    </item>
    <item>
      <title>Re: Mac OS X Keychain asks for password on every connect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/mac-os-x-keychain-asks-for-password-on-every-connect/m-p/1997#M1469</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&amp;lt; sarcasm &amp;gt; Since support was awesome and got back to me on this.. &amp;lt; /sarcasm &amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Subject: GlobalProtect Requests System Keychain Access on Mac OS X Clients Every Time&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scenario: &lt;/P&gt;&lt;P&gt;User will need to enter in Local Administrator account to allow System keychain access twice during the GlobalProtect VPN Connection Process, when using Machine Certificate authentication.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cause: &lt;/P&gt;&lt;P&gt;When using Machine Certificates with GlobalProtect on Mac OS X Clients, the certificate must be accessed from the "System" Keychain in OS X.&amp;nbsp; This will cause a Keychain Access prompt to appear twice when the client attempts to access certificate for verification against to portal and gateway.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Workaround:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;In Keychain Access application, locate the Machine Certificate issued to Mac OS X Client in the System keychain.&amp;nbsp; &lt;/LI&gt;&lt;LI&gt;Right Click on the private key assoicated with Certificate and click Get Info, then click Access Control tab&lt;/LI&gt;&lt;LI&gt;Then click + sign to select an Application to allow&lt;/LI&gt;&lt;LI&gt;Then press key combiniation "&amp;lt;Command&amp;gt; + &amp;lt;Shift&amp;gt; + G" to open Go to Folder&lt;/LI&gt;&lt;LI&gt;Enter "/Applications/GlobalProtect.app/Contents/Resources and click Go&lt;/LI&gt;&lt;LI&gt;Find PanGPS and click, then press Add&lt;/LI&gt;&lt;LI&gt;Save Changes to private key&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;You have now allowed GlobalProtect access to only THIS certificate and private key.&amp;nbsp; It will no longer prompt for keychain access, giving user a seamless no touch experience with GlobalProtect.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 01 May 2013 18:13:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/mac-os-x-keychain-asks-for-password-on-every-connect/m-p/1997#M1469</guid>
      <dc:creator>ManillaTechOps</dc:creator>
      <dc:date>2013-05-01T18:13:19Z</dc:date>
    </item>
    <item>
      <title>Re: Mac OS X Keychain asks for password on every connect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/mac-os-x-keychain-asks-for-password-on-every-connect/m-p/1998#M1470</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Nice! Nice writeup. You could make a DOC- for this &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 01 May 2013 18:14:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/mac-os-x-keychain-asks-for-password-on-every-connect/m-p/1998#M1470</guid>
      <dc:creator>ericgearhart</dc:creator>
      <dc:date>2013-05-01T18:14:49Z</dc:date>
    </item>
  </channel>
</rss>

