<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Global Protect pre-logon and SSO in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-pre-logon-and-sso/m-p/4340#M3206</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Help me understand this better, on the global protect portal for the server cert i need a public cert from a place like godaddy?&amp;nbsp; For the client cert I can use a cert that issued from our internal cert authority which has a cert on all the domain workstations already? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What I want is a pre-logon to happen when a user is not logged in yet, but a network connection is in place, then when the user signs in i want it to switch over to the user name for user-id on the palo.&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 15 Jul 2015 02:51:40 GMT</pubDate>
    <dc:creator>markk96</dc:creator>
    <dc:date>2015-07-15T02:51:40Z</dc:date>
    <item>
      <title>Global Protect pre-logon and SSO</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-pre-logon-and-sso/m-p/4340#M3206</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Help me understand this better, on the global protect portal for the server cert i need a public cert from a place like godaddy?&amp;nbsp; For the client cert I can use a cert that issued from our internal cert authority which has a cert on all the domain workstations already? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What I want is a pre-logon to happen when a user is not logged in yet, but a network connection is in place, then when the user signs in i want it to switch over to the user name for user-id on the palo.&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Jul 2015 02:51:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-pre-logon-and-sso/m-p/4340#M3206</guid>
      <dc:creator>markk96</dc:creator>
      <dc:date>2015-07-15T02:51:40Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect pre-logon and SSO</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-pre-logon-and-sso/m-p/4341#M3207</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm not sure I follow the question, so forgive me if this answers the wrong questions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The portal certificate from a trusted third party like GoDaddy helps the connection from the user machine to the portal.&amp;nbsp; This prevents the users computer from issuing a certificate warning that the the portal certificate fails the trusted authority check.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you use a domain issued certificate for the portal your domain computers will still be just fine and have no warnings because the domain computers do trust the domain certificate authority.&amp;nbsp; But any user connecting from computers outside the domain would be given the warning unless you distribute to them a copy of your domain trust chain.&amp;nbsp; If your remote vpn policy requires users connect using only domain computers then you can use a domain certificate without any issues.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For certificate authentication of the connection we generally use domain issued certificates and install the domain trust chain onto the Palo Alto so that the certificates will be accepted.&amp;nbsp; The idea is to trust the computer using this method.&amp;nbsp; If you choose to accept this as the only authentication I don't believe you can make that location dependent but just on or off in total.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Jul 2015 12:04:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-pre-logon-and-sso/m-p/4341#M3207</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2015-07-15T12:04:08Z</dc:date>
    </item>
  </channel>
</rss>

