<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Global Protect with VeriSign Certificates. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-with-verisign-certificates/m-p/28953#M21163</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P class="MsoNormal"&gt;Hello,&lt;/P&gt;&lt;P class="MsoNormal"&gt;Can someone please let me know which certificate’s to purchase from VeriSign for Global Protect and if there are any special methods to import them for my portal, gateway and client?&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 26 Mar 2012 19:09:15 GMT</pubDate>
    <dc:creator>pan123</dc:creator>
    <dc:date>2012-03-26T19:09:15Z</dc:date>
    <item>
      <title>Global Protect with VeriSign Certificates.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-with-verisign-certificates/m-p/28953#M21163</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P class="MsoNormal"&gt;Hello,&lt;/P&gt;&lt;P class="MsoNormal"&gt;Can someone please let me know which certificate’s to purchase from VeriSign for Global Protect and if there are any special methods to import them for my portal, gateway and client?&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Mar 2012 19:09:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-with-verisign-certificates/m-p/28953#M21163</guid>
      <dc:creator>pan123</dc:creator>
      <dc:date>2012-03-26T19:09:15Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect with VeriSign Certificates.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-with-verisign-certificates/m-p/28954#M21164</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Personally I wouldnt put the core of my security into the hands of some foreigner, no matter if that foreigner is spelled "Verisign" or something else (on the other hand you are putting your security into the hands of PAN but still :P).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Setting up your own CA is pretty simply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;There is TinyCA (&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://tinyca.sm-zone.net/"&gt;http://tinyca.sm-zone.net/&lt;/A&gt;&lt;SPAN&gt;) and also bootable usb-drives who can act as CA (I forgot its name) unless you wish to do this manually with openssl on a ubuntu box or whatever you prefer.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The main thing is then to protect your CA. Make sure you never connect it to any network and keep it locked up in a safebox when you are not around and it will be a better option than to use stuff from Verisign or any other public CA for your Global Protect needs. For added security make sure to use communication one way only (like dont use usb-drives to export the certs/keys, better to burn it on a blanc cdr or such).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then if you want to do this for real you can check the PCI compliance guidelines and stuff like that.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Mar 2012 19:54:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-with-verisign-certificates/m-p/28954#M21164</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-03-26T19:54:16Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect with VeriSign Certificates.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-with-verisign-certificates/m-p/28955#M21165</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To answer the certificate import portion, as long as the certificate you get from Verisign is PKCS12 or PEM format, you shouldn't have issues importing it on our gateway. You can do this on the gateway in the WebUI. Device tab -&amp;gt; Certificates -&amp;gt; Import.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For the client, it's different on each OS and each browser, but as long as you import the client certificate in their browser's certificate store, it should be fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;BR /&gt;&lt;BR /&gt;Jason Seals &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Mar 2012 20:11:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-with-verisign-certificates/m-p/28955#M21165</guid>
      <dc:creator>jseals</dc:creator>
      <dc:date>2012-03-26T20:11:56Z</dc:date>
    </item>
  </channel>
</rss>

