<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Is there a way to tie the Cert auth to AD username for AD auth? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/is-there-a-way-to-tie-the-cert-auth-to-ad-username-for-ad-auth/m-p/49604#M36552</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That's what I'm looking for.&amp;nbsp; I did test 6.0 (6.1) at one point and I remember that it was forcing me to use the username on the certificate but didn't realize this wasn't the case on version 5. I'm pretty sure it works on Windows so I need to confirm if it also works on non-windows machines. I'm hoping it will because this will be the solution.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks so much for your help! &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 09 Dec 2014 05:52:26 GMT</pubDate>
    <dc:creator>x</dc:creator>
    <dc:date>2014-12-09T05:52:26Z</dc:date>
    <item>
      <title>Is there a way to tie the Cert auth to AD username for AD auth?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-there-a-way-to-tie-the-cert-auth-to-ad-username-for-ad-auth/m-p/49599#M36547</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;Is there a way to make sure that the GP checks that the AD user name matches the certificate common name when using both AD and Cert profiles for authenticating users?&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Dec 2014 00:02:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-there-a-way-to-tie-the-cert-auth-to-ad-username-for-ad-auth/m-p/49599#M36547</guid>
      <dc:creator>x</dc:creator>
      <dc:date>2014-12-09T00:02:59Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a way to tie the Cert auth to AD username for AD auth?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-there-a-way-to-tie-the-cert-auth-to-ad-username-for-ad-auth/m-p/49600#M36548</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi x,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think you can, while creating a certificate profile you can provide the username field as (Subject) common name.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope it helps !&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Dec 2014 00:05:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-there-a-way-to-tie-the-cert-auth-to-ad-username-for-ad-auth/m-p/49600#M36548</guid>
      <dc:creator>bat</dc:creator>
      <dc:date>2014-12-09T00:05:17Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a way to tie the Cert auth to AD username for AD auth?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-there-a-way-to-tie-the-cert-auth-to-ad-username-for-ad-auth/m-p/49601#M36549</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks, that is what I have although, on IOS or Android, it doesn't seem to be doing that check. I will confirm.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Dec 2014 00:24:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-there-a-way-to-tie-the-cert-auth-to-ad-username-for-ad-auth/m-p/49601#M36549</guid>
      <dc:creator>x</dc:creator>
      <dc:date>2014-12-09T00:24:32Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a way to tie the Cert auth to AD username for AD auth?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-there-a-way-to-tie-the-cert-auth-to-ad-username-for-ad-auth/m-p/49602#M36550</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So as per TAC, there is no option to do this. They are two independent checks and are not tied together. I was told to submit a feature request. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Dec 2014 05:01:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-there-a-way-to-tie-the-cert-auth-to-ad-username-for-ad-auth/m-p/49602#M36550</guid>
      <dc:creator>x</dc:creator>
      <dc:date>2014-12-09T05:01:11Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a way to tie the Cert auth to AD username for AD auth?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-there-a-way-to-tie-the-cert-auth-to-ad-username-for-ad-auth/m-p/49603#M36551</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This should be possible in PanOS 6.0 - the following release notes describe a bug fix included in PanOS 6.0.0:&lt;/P&gt;&lt;P&gt;51091—Two-factor authentication (where both a client certificate profile and an&lt;/P&gt;&lt;P&gt;authentication profile are configured) was not functioning as expected. The client was&lt;/P&gt;&lt;P&gt;not required to provide the login credentials associated with the authentication profile&lt;/P&gt;&lt;P&gt;after successfully authenticating with the client certificate&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have you tested with Windows or Mac clients? maybe there is limitation with mobile clients.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Dec 2014 05:12:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-there-a-way-to-tie-the-cert-auth-to-ad-username-for-ad-auth/m-p/49603#M36551</guid>
      <dc:creator>sspringer</dc:creator>
      <dc:date>2014-12-09T05:12:21Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a way to tie the Cert auth to AD username for AD auth?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-there-a-way-to-tie-the-cert-auth-to-ad-username-for-ad-auth/m-p/49604#M36552</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That's what I'm looking for.&amp;nbsp; I did test 6.0 (6.1) at one point and I remember that it was forcing me to use the username on the certificate but didn't realize this wasn't the case on version 5. I'm pretty sure it works on Windows so I need to confirm if it also works on non-windows machines. I'm hoping it will because this will be the solution.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks so much for your help! &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Dec 2014 05:52:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-there-a-way-to-tie-the-cert-auth-to-ad-username-for-ad-auth/m-p/49604#M36552</guid>
      <dc:creator>x</dc:creator>
      <dc:date>2014-12-09T05:52:26Z</dc:date>
    </item>
  </channel>
</rss>

