<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Avoiding Certificate Error With Captive Portal in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/avoiding-certificate-error-with-captive-portal/m-p/43868#M32205</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you are using a self-signed certificate with Captive Portal and IE8 you will see slow page load times.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is a browser issue. One way that you can solve this problem is by putting a valid cert on the Captive Portal and using redirect mode for Captive Portal.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 03 Dec 2010 15:59:15 GMT</pubDate>
    <dc:creator>bpappas</dc:creator>
    <dc:date>2010-12-03T15:59:15Z</dc:date>
    <item>
      <title>Avoiding Certificate Error With Captive Portal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/avoiding-certificate-error-with-captive-portal/m-p/43861#M32198</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I was able to get Captive Portal setup successfully, but is there a way to prevent IE from complaining about a certificate error to get to the captive portal?&amp;nbsp; I probably won't be able to use it because of this error, it would be too confusing to some of my users.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for any help.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Jul 2010 22:01:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/avoiding-certificate-error-with-captive-portal/m-p/43861#M32198</guid>
      <dc:creator>kevin.shain</dc:creator>
      <dc:date>2010-07-26T22:01:01Z</dc:date>
    </item>
    <item>
      <title>Re: Avoiding Certificate Error With Captive Portal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/avoiding-certificate-error-with-captive-portal/m-p/43862#M32199</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You will need to switch to redirect mode to remove the browser warnings. This allows the device to forward the browser to an interface IP address that will have a matching certificate and then, once properly authenticated, it will forward them back to the originally desired destination.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;https://live.paloaltonetworks.com/docs/DOC-1516&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Jul 2010 22:05:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/avoiding-certificate-error-with-captive-portal/m-p/43862#M32199</guid>
      <dc:creator>mjacobsen</dc:creator>
      <dc:date>2010-07-26T22:05:55Z</dc:date>
    </item>
    <item>
      <title>Re: Avoiding Certificate Error With Captive Portal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/avoiding-certificate-error-with-captive-portal/m-p/43863#M32200</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I switched to redirect mode to 10.2.0.1, which is one of my L3 interfaces and I still receive a certificate error -- I've tried both a self generated certificate and using that Server Certificate and just leaving the Server Certificate blank.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am seeing this in IE8, I don't have any other browsers installed on the machine I am testing with.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any thing else I can try?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Jul 2010 22:26:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/avoiding-certificate-error-with-captive-portal/m-p/43863#M32200</guid>
      <dc:creator>kevin.shain</dc:creator>
      <dc:date>2010-07-26T22:26:04Z</dc:date>
    </item>
    <item>
      <title>Re: Avoiding Certificate Error With Captive Portal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/avoiding-certificate-error-with-captive-portal/m-p/43864#M32201</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In order to eliminate the errors you will need to install a cert that matches the IP address of the interface. Otherwise, the browser will still give certificate warnings.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Jul 2010 15:21:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/avoiding-certificate-error-with-captive-portal/m-p/43864#M32201</guid>
      <dc:creator>mjacobsen</dc:creator>
      <dc:date>2010-07-27T15:21:08Z</dc:date>
    </item>
    <item>
      <title>Re: Avoiding Certificate Error With Captive Portal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/avoiding-certificate-error-with-captive-portal/m-p/43865#M32202</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I did that.&amp;nbsp; Problem is that IE8 doesn't like the fact that it is a self-generated certificate, guess I am out of luck unless I want to purchase a certificate.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Jul 2010 00:21:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/avoiding-certificate-error-with-captive-portal/m-p/43865#M32202</guid>
      <dc:creator>kevin.shain</dc:creator>
      <dc:date>2010-07-29T00:21:16Z</dc:date>
    </item>
    <item>
      <title>Re: Avoiding Certificate Error With Captive Portal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/avoiding-certificate-error-with-captive-portal/m-p/43866#M32203</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You don't necessarily need to purchase a cert, but you do need it to be a cert signed by a CA that your browsers trust. If you have a CA in place for creating certs for internal services, the same could be used for this. Alternatively, you could create a CA and tell your browsers to trust certs signed by it.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Jul 2010 04:19:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/avoiding-certificate-error-with-captive-portal/m-p/43866#M32203</guid>
      <dc:creator>mjacobsen</dc:creator>
      <dc:date>2010-07-29T04:19:56Z</dc:date>
    </item>
    <item>
      <title>Re: Avoiding Certificate Error With Captive Portal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/avoiding-certificate-error-with-captive-portal/m-p/43867#M32204</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;PAM OS: 3.1.6&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I use IE browser 8 for captvie portal but IE get cert very slowly. If I use firefox, It is OK.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has captvie portal problems with IE 8?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank You&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Dec 2010 04:00:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/avoiding-certificate-error-with-captive-portal/m-p/43867#M32204</guid>
      <dc:creator>mindterra</dc:creator>
      <dc:date>2010-12-03T04:00:50Z</dc:date>
    </item>
    <item>
      <title>Re: Avoiding Certificate Error With Captive Portal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/avoiding-certificate-error-with-captive-portal/m-p/43868#M32205</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you are using a self-signed certificate with Captive Portal and IE8 you will see slow page load times.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is a browser issue. One way that you can solve this problem is by putting a valid cert on the Captive Portal and using redirect mode for Captive Portal.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Dec 2010 15:59:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/avoiding-certificate-error-with-captive-portal/m-p/43868#M32205</guid>
      <dc:creator>bpappas</dc:creator>
      <dc:date>2010-12-03T15:59:15Z</dc:date>
    </item>
    <item>
      <title>Re: Avoiding Certificate Error With Captive Portal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/avoiding-certificate-error-with-captive-portal/m-p/43869#M32206</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;For IE8, I found a problem. IE8 &lt;STRONG&gt;can not&lt;/STRONG&gt; trust valid cert but other browser as Firefox can trust cert.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have you ever found this issue? How solved?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank You&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Dec 2010 01:26:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/avoiding-certificate-error-with-captive-portal/m-p/43869#M32206</guid>
      <dc:creator>mindterra</dc:creator>
      <dc:date>2010-12-06T01:26:10Z</dc:date>
    </item>
    <item>
      <title>Re: Avoiding Certificate Error With Captive Portal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/avoiding-certificate-error-with-captive-portal/m-p/43870#M32207</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When you say "IE 8 cannot trust a valid cert" what does that mean exactly?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Public CA or Internal CA?&lt;/P&gt;&lt;P&gt;certificate details? (format, key length, etc etc)&lt;/P&gt;&lt;P&gt;What error(s)/symptom(s) does IE 8 display?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Dec 2010 14:57:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/avoiding-certificate-error-with-captive-portal/m-p/43870#M32207</guid>
      <dc:creator>bpappas</dc:creator>
      <dc:date>2010-12-06T14:57:32Z</dc:date>
    </item>
    <item>
      <title>Re: Avoiding Certificate Error With Captive Portal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/avoiding-certificate-error-with-captive-portal/m-p/43871#M32208</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;IE 8 display as ie_cp_error.jpg&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Dec 2010 07:53:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/avoiding-certificate-error-with-captive-portal/m-p/43871#M32208</guid>
      <dc:creator>mindterra</dc:creator>
      <dc:date>2010-12-15T07:53:31Z</dc:date>
    </item>
    <item>
      <title>Re: Avoiding Certificate Error With Captive Portal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/avoiding-certificate-error-with-captive-portal/m-p/43872#M32209</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If I use redirect mode for Captive Portal, NTLM required for CP or not.&lt;/P&gt;&lt;P&gt;I am using Radius authentication.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What a way for captive portal does without NTLM but Radius only?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Dec 2010 08:07:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/avoiding-certificate-error-with-captive-portal/m-p/43872#M32209</guid>
      <dc:creator>mindterra</dc:creator>
      <dc:date>2010-12-17T08:07:36Z</dc:date>
    </item>
    <item>
      <title>Re: Avoiding Certificate Error With Captive Portal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/avoiding-certificate-error-with-captive-portal/m-p/43873#M32210</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi There,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can just select an authentication profile, that you will have created for RADIUS.&amp;nbsp; This will allow Captive Portal to work with RADIUS and not NTLM - you need not select the User ID Agent in this case (you can leave it blank).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;James&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Dec 2010 09:11:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/avoiding-certificate-error-with-captive-portal/m-p/43873#M32210</guid>
      <dc:creator>James</dc:creator>
      <dc:date>2010-12-17T09:11:54Z</dc:date>
    </item>
    <item>
      <title>Re: Avoiding Certificate Error With Captive Portal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/avoiding-certificate-error-with-captive-portal/m-p/43874#M32211</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;it should be of note that older browsers you could do this (redirect with a self signed) and there was no issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;example if you take firefox 3 and try this it works with no errors.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;however newer browsers wont allow a self signed certificate they will show errors, this is something that the browser manuifacture's have chosen to do to prevent macicious behavior. to "undo this feature" you would have to contact your browser manuifacture or google around for a way to defete this "protection" should you want to use a self signed cert....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ideally your not using a self signed certificate for this behavior as your complications go beyond firefox and IE ...aka BlackBerry Chrome Safari etc all of which will be enabling protection like this..&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Aug 2011 18:27:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/avoiding-certificate-error-with-captive-portal/m-p/43874#M32211</guid>
      <dc:creator>kkeeton</dc:creator>
      <dc:date>2011-08-24T18:27:57Z</dc:date>
    </item>
  </channel>
</rss>

