<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Is that possible to verify client certificatie when SSL VPN connects? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/is-that-possible-to-verify-client-certificatie-when-ssl-vpn/m-p/36758#M27013</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I found there is a Client Certificate Profile Option, but I search around seems no Document or Manual description how to use it.&lt;/P&gt;&lt;P&gt;Can anyone help?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 11 May 2011 00:33:22 GMT</pubDate>
    <dc:creator>muratahk</dc:creator>
    <dc:date>2011-05-11T00:33:22Z</dc:date>
    <item>
      <title>Is that possible to verify client certificatie when SSL VPN connects?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-that-possible-to-verify-client-certificatie-when-ssl-vpn/m-p/36758#M27013</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I found there is a Client Certificate Profile Option, but I search around seems no Document or Manual description how to use it.&lt;/P&gt;&lt;P&gt;Can anyone help?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 May 2011 00:33:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-that-possible-to-verify-client-certificatie-when-ssl-vpn/m-p/36758#M27013</guid>
      <dc:creator>muratahk</dc:creator>
      <dc:date>2011-05-11T00:33:22Z</dc:date>
    </item>
    <item>
      <title>Re: Is that possible to verify client certificatie when SSL VPN connects?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-that-possible-to-verify-client-certificatie-when-ssl-vpn/m-p/36759#M27014</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I want to use client certificates for SSL VPN authentication too. Does anybody knows how to configure it?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 May 2011 22:05:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-that-possible-to-verify-client-certificatie-when-ssl-vpn/m-p/36759#M27014</guid>
      <dc:creator>mfe</dc:creator>
      <dc:date>2011-05-24T22:05:13Z</dc:date>
    </item>
    <item>
      <title>Re: Is that possible to verify client certificatie when SSL VPN connects?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-that-possible-to-verify-client-certificatie-when-ssl-vpn/m-p/36760#M27015</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here is an outline of what needs to be done:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. on your Windows CA create client certificates&lt;/P&gt;&lt;P&gt;2. install the client certificates in each user's browser (one cert per user)&lt;/P&gt;&lt;P&gt;3. import the root CA from Windows on the PAN device under the Client CA Cert (device tab -&amp;gt; certificates -&amp;gt; client CA Cert)&lt;/P&gt;&lt;P&gt;4. create a client certificate profile&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; a. select the username field&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; b. under CA cert select the one that you imported to the PAN in step 3 and then click add&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; c. check "use CRL" &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; d. click "OK"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;note: if you bought your client certs then you would want to check the OCSP checkbox&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;5. in your SSL VPN profile select the Client Certificate profile that you created in step 4 then click OK&lt;/P&gt;&lt;P&gt;6. commit&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;At this point when a user logs into the SSL VPN portal they should be asked to select the client certificate that they wish to use. This should be in their browser and available for them to select.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;note: make sure the management interface of the PAN device can access TCP:443 of the CRL server (or the internet if checking against a commercial CA).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Jun 2011 22:39:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-that-possible-to-verify-client-certificatie-when-ssl-vpn/m-p/36760#M27015</guid>
      <dc:creator>bpappas</dc:creator>
      <dc:date>2011-06-09T22:39:16Z</dc:date>
    </item>
  </channel>
</rss>

