<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Trusted Root CA Not Installed on Client? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/trusted-root-ca-not-installed-on-client/m-p/71586#M40841</link>
    <description>&lt;P&gt;Sorry for the delay.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So the choices become:&lt;/P&gt;
&lt;P&gt;1. Manually chained.&amp;nbsp; Then the Mac's keychain will show the certificate as complete.&lt;/P&gt;
&lt;P&gt;2.&amp;nbsp; Leave as is.&amp;nbsp; The client gets no error during GP login but the keychain on the machine just shows the cert signed by an unknown CA.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;User's don't actually go there to check anyway.&amp;nbsp; They just don't want to see those pesky pop-ups about untrusted cert.&amp;nbsp; So, I'm going to leave it as is.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for the response.&lt;/P&gt;</description>
    <pubDate>Tue, 26 Jan 2016 00:57:25 GMT</pubDate>
    <dc:creator>CafNetMatt</dc:creator>
    <dc:date>2016-01-26T00:57:25Z</dc:date>
    <item>
      <title>Trusted Root CA Not Installed on Client?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/trusted-root-ca-not-installed-on-client/m-p/70944#M40626</link>
      <description>&lt;P&gt;This is on a PA-3020 running PAN-OS 7.0.4.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've always manually chained certificates when installed an SSL certificate for Global Protect. &amp;nbsp;I decided to see if I could install the SSL certificate and the Intermediate certificates separately and see if it would work. &amp;nbsp;I configured Global Protect Portal &amp;gt; Agent Configuration &amp;gt; Trusted Root CA with the GoDaddy G2_G1 certificate provided by GoDaddy.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When I log into Global Protect, I do not get the 'untrusted certificate' error. &amp;nbsp;However, when I check Keychain on my Mac, it only shows the client certificate installed, not the GoDaddy intermediate, and the certificate is labeled as 'signed by unknow authority'.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My questions:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. Does the Global Protect client just check the Trusted Root CA but not push the certificate down to the client?&lt;/P&gt;
&lt;P&gt;2. Is it still recommended to manually create the certificate chain or use this method? &amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The reason I'm trying not to chain them is because the client wants his SSL certificate to update via OCSP and it just doesn't do that if it's manually chained.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jan 2016 01:45:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/trusted-root-ca-not-installed-on-client/m-p/70944#M40626</guid>
      <dc:creator>CafNetMatt</dc:creator>
      <dc:date>2016-01-15T01:45:12Z</dc:date>
    </item>
    <item>
      <title>Re: Trusted Root CA Not Installed on Client?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/trusted-root-ca-not-installed-on-client/m-p/70956#M40629</link>
      <description>&lt;P&gt;1. Does the Global Protect client just check the Trusted Root CA but not push the certificate down to the client?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It pushes the root ca to client. Client performs certificate checks when user connect to the GlobalProtect gateway.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2. Is it still recommended to manually create the certificate chain or use this method? &amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/How-to-Install-a-Chained-Certificate-Signed-by-a-Public-CA/ta-p/55523" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/How-to-Install-a-Chained-Certificate-Signed-by-a-Public-CA/ta-p/55523&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps!&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jan 2016 06:19:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/trusted-root-ca-not-installed-on-client/m-p/70956#M40629</guid>
      <dc:creator>pankaku</dc:creator>
      <dc:date>2016-01-15T06:19:56Z</dc:date>
    </item>
    <item>
      <title>Re: Trusted Root CA Not Installed on Client?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/trusted-root-ca-not-installed-on-client/m-p/70961#M40632</link>
      <description>&lt;P&gt;That's what's weird.&amp;nbsp; I thought it pushed the Root CA to the client.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When I check Keychain on my Mac, the client's certificate is there but the CA Root is not.&amp;nbsp; The client certificate just shows that's it's signed by an unknown signer.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I searched the keychain and could not find the Root CAs that should be being pushed down.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Matt&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jan 2016 05:54:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/trusted-root-ca-not-installed-on-client/m-p/70961#M40632</guid>
      <dc:creator>CafNetMatt</dc:creator>
      <dc:date>2016-01-15T05:54:29Z</dc:date>
    </item>
    <item>
      <title>Re: Trusted Root CA Not Installed on Client?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/trusted-root-ca-not-installed-on-client/m-p/70964#M40633</link>
      <description>&lt;P&gt;It pushes the root ca to client. Client performs certificate checks when user connect to the GlobalProtect gateway.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jan 2016 06:06:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/trusted-root-ca-not-installed-on-client/m-p/70964#M40633</guid>
      <dc:creator>pankaku</dc:creator>
      <dc:date>2016-01-15T06:06:30Z</dc:date>
    </item>
    <item>
      <title>Re: Trusted Root CA Not Installed on Client?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/trusted-root-ca-not-installed-on-client/m-p/70965#M40634</link>
      <description>&lt;P&gt;But I'm seeing it doesn't add it to the local keychain on the PC.&amp;nbsp; Only the client certificate is being added.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Shouldn't the Root CA be added to the keychain?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Matt&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jan 2016 06:11:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/trusted-root-ca-not-installed-on-client/m-p/70965#M40634</guid>
      <dc:creator>CafNetMatt</dc:creator>
      <dc:date>2016-01-15T06:11:19Z</dc:date>
    </item>
    <item>
      <title>Re: Trusted Root CA Not Installed on Client?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/trusted-root-ca-not-installed-on-client/m-p/70966#M40635</link>
      <description>&lt;P&gt;It will not be added.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;From the admin guide:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;"As a best practice, always deploy the trusted root CA certificates in the client configuration to ensure that the agents/apps perform the certificate checks to validate the identity of the gateway before establishing a connection. This prevents the agents/apps from falling prey to man-in-the-middle attacks"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Have you tried in windows system? May be godaddy intermediate root ca is not present on the local machine that's why it is showing was unknow signing authority.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jan 2016 06:15:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/trusted-root-ca-not-installed-on-client/m-p/70966#M40635</guid>
      <dc:creator>pankaku</dc:creator>
      <dc:date>2016-01-15T06:15:38Z</dc:date>
    </item>
    <item>
      <title>Re: Trusted Root CA Not Installed on Client?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/trusted-root-ca-not-installed-on-client/m-p/70967#M40636</link>
      <description>&lt;P&gt;Check this doc:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/How-to-Install-a-Chained-Certificate-Signed-by-a-Public-CA/ta-p/55523" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/How-to-Install-a-Chained-Certificate-Signed-by-a-Public-CA/ta-p/55523&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jan 2016 06:19:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/trusted-root-ca-not-installed-on-client/m-p/70967#M40636</guid>
      <dc:creator>pankaku</dc:creator>
      <dc:date>2016-01-15T06:19:14Z</dc:date>
    </item>
    <item>
      <title>Re: Trusted Root CA Not Installed on Client?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/trusted-root-ca-not-installed-on-client/m-p/70968#M40637</link>
      <description>&lt;P&gt;I guess certificate chain will help here.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jan 2016 07:15:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/trusted-root-ca-not-installed-on-client/m-p/70968#M40637</guid>
      <dc:creator>pankaku</dc:creator>
      <dc:date>2016-01-15T07:15:39Z</dc:date>
    </item>
    <item>
      <title>Re: Trusted Root CA Not Installed on Client?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/trusted-root-ca-not-installed-on-client/m-p/71586#M40841</link>
      <description>&lt;P&gt;Sorry for the delay.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So the choices become:&lt;/P&gt;
&lt;P&gt;1. Manually chained.&amp;nbsp; Then the Mac's keychain will show the certificate as complete.&lt;/P&gt;
&lt;P&gt;2.&amp;nbsp; Leave as is.&amp;nbsp; The client gets no error during GP login but the keychain on the machine just shows the cert signed by an unknown CA.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;User's don't actually go there to check anyway.&amp;nbsp; They just don't want to see those pesky pop-ups about untrusted cert.&amp;nbsp; So, I'm going to leave it as is.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for the response.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jan 2016 00:57:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/trusted-root-ca-not-installed-on-client/m-p/71586#M40841</guid>
      <dc:creator>CafNetMatt</dc:creator>
      <dc:date>2016-01-26T00:57:25Z</dc:date>
    </item>
  </channel>
</rss>

