<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Pre-Logon without Windows credentials in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pre-logon-without-windows-credentials/m-p/42742#M31374</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;any idea?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 04 Nov 2013 10:46:30 GMT</pubDate>
    <dc:creator>Hithead</dc:creator>
    <dc:date>2013-11-04T10:46:30Z</dc:date>
    <item>
      <title>Pre-Logon without Windows credentials</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pre-logon-without-windows-credentials/m-p/42741#M31373</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I want to test the pre-logon feature of GlobalProtect in our environment.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Our clients are using two factor authentication (eToken) for the windows login. So they don't know their windows credentials.&lt;/P&gt;&lt;P&gt;We have already installed machine certificates on our clients and the authentication with this certificate works with GlobalProtect. Also when using Windows login without eToken, it works with SSO and LDAP auth.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But now, i have to get it working for the eToken-Users:&lt;/P&gt;&lt;P&gt;After the user logs into Windows with his eToken (two factor) he always gets prompt to enter the password of his eToken and the authentication fails.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there a way to configure Pre-Logon for Two-Factor-Auth-Users? GlobalProtect requires an username in the configuration; either in the certificate profile - (currently set to none) or selecting an secondary authentication profile - (currently set to LDAP).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Or is GlobalProtect Pre-Logon feature not optimized for this way of authentication? Or can we just use the machine certificate without any username or user authentication?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Oct 2013 08:44:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pre-logon-without-windows-credentials/m-p/42741#M31373</guid>
      <dc:creator>Hithead</dc:creator>
      <dc:date>2013-10-18T08:44:18Z</dc:date>
    </item>
    <item>
      <title>Re: Pre-Logon without Windows credentials</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pre-logon-without-windows-credentials/m-p/42742#M31374</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;any idea?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Nov 2013 10:46:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pre-logon-without-windows-credentials/m-p/42742#M31374</guid>
      <dc:creator>Hithead</dc:creator>
      <dc:date>2013-11-04T10:46:30Z</dc:date>
    </item>
    <item>
      <title>Re: Pre-Logon without Windows credentials</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pre-logon-without-windows-credentials/m-p/42743#M31375</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I don't know eToken. But your users do have a Windows account, right ? Even if they don't know...&lt;/P&gt;&lt;P&gt;Should work with SSO, but I guess GP needs to login manually once with the user login to get the client config file. Maybe you can deploy the client config file in another way...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Nov 2013 12:46:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pre-logon-without-windows-credentials/m-p/42743#M31375</guid>
      <dc:creator>dieter_b</dc:creator>
      <dc:date>2013-11-04T12:46:39Z</dc:date>
    </item>
    <item>
      <title>Re: Pre-Logon without Windows credentials</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pre-logon-without-windows-credentials/m-p/42744#M31376</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;our clients only have the PIN from their Token for the two factor authentication and not the windows password. So they are not able to authenticate via LDAP. So GP with LDAP Authentication wouldn't work.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Nov 2013 10:12:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pre-logon-without-windows-credentials/m-p/42744#M31376</guid>
      <dc:creator>Hithead</dc:creator>
      <dc:date>2013-11-05T10:12:26Z</dc:date>
    </item>
    <item>
      <title>Re: Pre-Logon without Windows credentials</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pre-logon-without-windows-credentials/m-p/42745#M31377</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;(May GP can authenticate without User-Authentication. Only with machine-certificate. Doesn't matter which user logins in....)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Nov 2013 10:13:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pre-logon-without-windows-credentials/m-p/42745#M31377</guid>
      <dc:creator>Hithead</dc:creator>
      <dc:date>2013-11-05T10:13:53Z</dc:date>
    </item>
    <item>
      <title>Re: Pre-Logon without Windows credentials</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pre-logon-without-windows-credentials/m-p/42746#M31378</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi I think tthat you can't use the etoken as second factor authentication method with prelogon method.&lt;/P&gt;&lt;P&gt;but you could use the client certificate as second factor method. but you need to use windows credential with prelogon it' a mandatory.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regard's&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Nov 2013 10:36:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pre-logon-without-windows-credentials/m-p/42746#M31378</guid>
      <dc:creator>Gregoux</dc:creator>
      <dc:date>2013-11-05T10:36:02Z</dc:date>
    </item>
    <item>
      <title>Re: Pre-Logon without Windows credentials</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pre-logon-without-windows-credentials/m-p/42747#M31379</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sadly not. Because I can only choose certificates with a private key. And we imported our CA - certificate without the key.&lt;/P&gt;&lt;P&gt;But anyway, I have to specify, where GP/PA can find the user information(/name) of the remote client.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So I guess, we can forget the pre-logon feature with our token clients. But I will request it as a feature request.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Nov 2013 12:12:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pre-logon-without-windows-credentials/m-p/42747#M31379</guid>
      <dc:creator>Hithead</dc:creator>
      <dc:date>2013-11-05T12:12:43Z</dc:date>
    </item>
  </channel>
</rss>

