<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: client cert invalid message when connecting global protect with client cert in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/client-cert-invalid-message-when-connecting-global-protect-with/m-p/27059#M19769</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think you have to chain the certificat on the paloalto&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;see &lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/docs/DOC-1937"&gt;https://live.paloaltonetworks.com/docs/DOC-1937&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;page 32 you could find an example to chain the certificat&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and on your device you need to install the trust root CA and the intermediate&lt;/P&gt;&lt;P&gt;you could obtain more information about your issue if you activate the troubleshooting on the global protect agent on your user device.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 20 Jun 2013 11:47:52 GMT</pubDate>
    <dc:creator>Gregoux</dc:creator>
    <dc:date>2013-06-20T11:47:52Z</dc:date>
    <item>
      <title>client cert invalid message when connecting global protect with client cert</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/client-cert-invalid-message-when-connecting-global-protect-with/m-p/27051#M19761</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I had tested to connect global protect with client cert successful in my lab.(PANOS-5.0.x)&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;I am installing global protect on my custom device.(PANOS-5.0.x)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;But I don't connect with 'client cert invalid' message.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I had installed the following in my lab at old days.&lt;/P&gt;&lt;P&gt;&lt;IMG alt="1.png" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/6989_1.png" /&gt;&lt;/P&gt;&lt;P&gt;1. self generated certificate.&lt;/P&gt;&lt;P&gt;&lt;IMG alt="2.png" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/6990_2.png" width="450" /&gt;&lt;/P&gt;&lt;P&gt;2. subject &amp;gt; common-name. profile name is 'test'&lt;/P&gt;&lt;P&gt;3. Portal configuration (authentication profile : local DB , client certificate : none , certificate profile : none)&lt;/P&gt;&lt;P&gt;4. Gateway configuration (authentication profile : none , certificate profile : 'test')&lt;/P&gt;&lt;P&gt;5. import certificate into my laptop.&lt;/P&gt;&lt;P&gt;6. connecting GP -&amp;gt; portal auth localdb(id/pw) successful -&amp;gt; gateway auth client cert(username : uquest) successful &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am installing the following in my custom device.&lt;/P&gt;&lt;P&gt;1. FW is imported certificate issuer by window CA server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; subject : /C=KR/ST=Seoul/O=paloalto/OU=paloalto/CN=pa.paloalto.co.kr&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; issuer : /DC=local/DC=paloalto/CN=paloalto-CA&lt;/P&gt;&lt;P&gt;2. certificate profile : name 'test01' &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; username field - subject&amp;nbsp; - common name&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; domain : pa.paloalto.co.kr&lt;/P&gt;&lt;P&gt;3. Portal configuration (authentication profile local DB , client certificate : none , certificate profile : none)&lt;/P&gt;&lt;P&gt;4. Gateway configuration (authentication profile : none , certificate profile : 'test01')&lt;/P&gt;&lt;P&gt;5. import certificate into my laptop.&lt;/P&gt;&lt;P&gt;6. connecting GP -&amp;gt; portal auth localdb(id/pw) successful -&amp;gt; gateway auth client cert(username : none) fail.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Error message is client cert invalid.&lt;/P&gt;&lt;P&gt;&lt;IMG alt="3.png" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/6991_3.png" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't know what missed configuration and problem.&lt;/P&gt;&lt;P&gt;Please let me know resolved way.&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Jun 2013 13:34:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/client-cert-invalid-message-when-connecting-global-protect-with/m-p/27051#M19761</guid>
      <dc:creator>KiCheon.Lee</dc:creator>
      <dc:date>2013-06-19T13:34:03Z</dc:date>
    </item>
    <item>
      <title>Re: client cert invalid message when connecting global protect with client cert</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/client-cert-invalid-message-when-connecting-global-protect-with/m-p/27052#M19762</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;did you see that &lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/docs/DOC-1934"&gt;https://live.paloaltonetworks.com/docs/DOC-1934&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Jun 2013 15:16:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/client-cert-invalid-message-when-connecting-global-protect-with/m-p/27052#M19762</guid>
      <dc:creator>Gregoux</dc:creator>
      <dc:date>2013-06-19T15:16:52Z</dc:date>
    </item>
    <item>
      <title>Re: client cert invalid message when connecting global protect with client cert</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/client-cert-invalid-message-when-connecting-global-protect-with/m-p/27053#M19763</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;in step 3 &lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;3. Portal configuration (authentication profile local DB , client certificate : none , certificate profile : none)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;you forgot certificat profile &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Jun 2013 15:19:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/client-cert-invalid-message-when-connecting-global-protect-with/m-p/27053#M19763</guid>
      <dc:creator>Gregoux</dc:creator>
      <dc:date>2013-06-19T15:19:57Z</dc:date>
    </item>
    <item>
      <title>Re: client cert invalid message when connecting global protect with client cert</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/client-cert-invalid-message-when-connecting-global-protect-with/m-p/27054#M19764</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello gregory.screve1,&lt;/P&gt;&lt;P&gt;Thank you for your help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I had seen this document your recommend.&lt;/P&gt;&lt;P&gt;I have modified certificate profile in portal configuration.&lt;/P&gt;&lt;P&gt;But I don't still connect GP with same error message.&lt;/P&gt;&lt;P&gt;Please let me know other resolved way.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Jun 2013 08:06:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/client-cert-invalid-message-when-connecting-global-protect-with/m-p/27054#M19764</guid>
      <dc:creator>KiCheon.Lee</dc:creator>
      <dc:date>2013-06-20T08:06:30Z</dc:date>
    </item>
    <item>
      <title>Re: client cert invalid message when connecting global protect with client cert</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/client-cert-invalid-message-when-connecting-global-protect-with/m-p/27055#M19765</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In your portal config / Client Configuration, Have you well configure your Trusted root CA ?&lt;/P&gt;&lt;P&gt;Have you got either error or warning during commit ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;V.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Jun 2013 09:13:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/client-cert-invalid-message-when-connecting-global-protect-with/m-p/27055#M19765</guid>
      <dc:creator>VinceM</dc:creator>
      <dc:date>2013-06-20T09:13:43Z</dc:date>
    </item>
    <item>
      <title>Re: client cert invalid message when connecting global protect with client cert</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/client-cert-invalid-message-when-connecting-global-protect-with/m-p/27056#M19766</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;see &lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/message/26851#26851"&gt;https://live.paloaltonetworks.com/message/26851#26851&lt;/A&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;If you use a self-signed or in-house cert, this feature prevents the client from getting an 'untrusted issuer' prompt when connecting to that gateway. If you are using a public CA with your gateway, you won't need to use this feature.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;you need to define the CA root like that only if you use a trust&amp;nbsp; root Ca that is not deployed on your client machine.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;even you need it it doesn't block yours connection attempt, just a warning.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Jun 2013 10:12:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/client-cert-invalid-message-when-connecting-global-protect-with/m-p/27056#M19766</guid>
      <dc:creator>Gregoux</dc:creator>
      <dc:date>2013-06-20T10:12:58Z</dc:date>
    </item>
    <item>
      <title>Re: client cert invalid message when connecting global protect with client cert</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/client-cert-invalid-message-when-connecting-global-protect-with/m-p/27057#M19767</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello VinceM,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for your information.&lt;/P&gt;&lt;P&gt;I have installed to choose client certificate in portal config / Client configuration / Trust Root CA.&lt;/P&gt;&lt;P&gt;But result is same. I don't connect GP with same error message.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I guess that FW does not read common name in certificate.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Jun 2013 10:32:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/client-cert-invalid-message-when-connecting-global-protect-with/m-p/27057#M19767</guid>
      <dc:creator>KiCheon.Lee</dc:creator>
      <dc:date>2013-06-20T10:32:45Z</dc:date>
    </item>
    <item>
      <title>Re: client cert invalid message when connecting global protect with client cert</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/client-cert-invalid-message-when-connecting-global-protect-with/m-p/27058#M19768</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I had imported intermediate certificate for client certificate to FW.&lt;/P&gt;&lt;P&gt;My customer sent only this certificate issuer by private Window CA.&lt;/P&gt;&lt;P&gt;Do I need root certificate? Then Will I have to configure root certificate in portal config / Client configuration / Trust Root CA????&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Jun 2013 11:05:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/client-cert-invalid-message-when-connecting-global-protect-with/m-p/27058#M19768</guid>
      <dc:creator>KiCheon.Lee</dc:creator>
      <dc:date>2013-06-20T11:05:06Z</dc:date>
    </item>
    <item>
      <title>Re: client cert invalid message when connecting global protect with client cert</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/client-cert-invalid-message-when-connecting-global-protect-with/m-p/27059#M19769</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think you have to chain the certificat on the paloalto&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;see &lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/docs/DOC-1937"&gt;https://live.paloaltonetworks.com/docs/DOC-1937&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;page 32 you could find an example to chain the certificat&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and on your device you need to install the trust root CA and the intermediate&lt;/P&gt;&lt;P&gt;you could obtain more information about your issue if you activate the troubleshooting on the global protect agent on your user device.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Jun 2013 11:47:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/client-cert-invalid-message-when-connecting-global-protect-with/m-p/27059#M19769</guid>
      <dc:creator>Gregoux</dc:creator>
      <dc:date>2013-06-20T11:47:52Z</dc:date>
    </item>
  </channel>
</rss>

