<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Globalprotect client authenticate with a certificate not working anymore in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-authenticate-with-a-certificate-not-working/m-p/90789#M43590</link>
    <description>&lt;P&gt;Since we use our Palo Alto firewall, our users there Global Protect Client authenticate with the firewall through a certificate that is deployed thorugh Active Directory. Our Global Protect Client version is 3.0.2.&lt;/P&gt;&lt;P&gt;Since we updated our Pan-Os version to 7.0.6 this method of authentication does not work anymore.&lt;/P&gt;&lt;P&gt;THe client tries to authenticate and than there is a message: Enter username and password to login.&lt;/P&gt;&lt;P&gt;When to user fills in his credentials everything works, but this is not how we want it. The authentication need to go through the certificate.&lt;/P&gt;&lt;P&gt;I checked the Portal Gateway and it seems it has been modified with the update to 7.0.6. There is now a field SSL/TLS.&lt;/P&gt;&lt;P&gt;How can I fix this issue?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PA.JPG" style="width: 791px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/4509i2BD84DE48FE38259/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="PA.JPG" alt="PA.JPG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PA_Portal.JPG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/4510i2BC585088DECF067/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="PA_Portal.JPG" alt="PA_Portal.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 22 Jun 2016 06:32:33 GMT</pubDate>
    <dc:creator>ZEBIT</dc:creator>
    <dc:date>2016-06-22T06:32:33Z</dc:date>
    <item>
      <title>Globalprotect client authenticate with a certificate not working anymore</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-authenticate-with-a-certificate-not-working/m-p/90789#M43590</link>
      <description>&lt;P&gt;Since we use our Palo Alto firewall, our users there Global Protect Client authenticate with the firewall through a certificate that is deployed thorugh Active Directory. Our Global Protect Client version is 3.0.2.&lt;/P&gt;&lt;P&gt;Since we updated our Pan-Os version to 7.0.6 this method of authentication does not work anymore.&lt;/P&gt;&lt;P&gt;THe client tries to authenticate and than there is a message: Enter username and password to login.&lt;/P&gt;&lt;P&gt;When to user fills in his credentials everything works, but this is not how we want it. The authentication need to go through the certificate.&lt;/P&gt;&lt;P&gt;I checked the Portal Gateway and it seems it has been modified with the update to 7.0.6. There is now a field SSL/TLS.&lt;/P&gt;&lt;P&gt;How can I fix this issue?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PA.JPG" style="width: 791px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/4509i2BD84DE48FE38259/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="PA.JPG" alt="PA.JPG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PA_Portal.JPG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/4510i2BC585088DECF067/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="PA_Portal.JPG" alt="PA_Portal.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jun 2016 06:32:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-authenticate-with-a-certificate-not-working/m-p/90789#M43590</guid>
      <dc:creator>ZEBIT</dc:creator>
      <dc:date>2016-06-22T06:32:33Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect client authenticate with a certificate not working anymore</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-authenticate-with-a-certificate-not-working/m-p/90799#M43591</link>
      <description>&lt;P&gt;But you have LDAP profile also chosen so it is expected that user/password is asked.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jun 2016 06:52:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-authenticate-with-a-certificate-not-working/m-p/90799#M43591</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2016-06-22T06:52:53Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect client authenticate with a certificate not working anymore</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-authenticate-with-a-certificate-not-working/m-p/90800#M43592</link>
      <description>&lt;P&gt;Our vendor did this and said it was a bckup in case the certificate does not work.&lt;/P&gt;&lt;P&gt;So how I can make everything work again?&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jun 2016 07:03:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-authenticate-with-a-certificate-not-working/m-p/90800#M43592</guid>
      <dc:creator>ZEBIT</dc:creator>
      <dc:date>2016-06-22T07:03:01Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect client authenticate with a certificate not working anymore</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-authenticate-with-a-certificate-not-working/m-p/90801#M43593</link>
      <description>&lt;P&gt;If both are chosen both are asked.&lt;/P&gt;&lt;P&gt;If cert fails then just login fails.&lt;/P&gt;&lt;P&gt;Maybe someone will correct me &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jun 2016 07:01:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-authenticate-with-a-certificate-not-working/m-p/90801#M43593</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2016-06-22T07:01:30Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect client authenticate with a certificate not working anymore</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-authenticate-with-a-certificate-not-working/m-p/90802#M43594</link>
      <description>&lt;P&gt;Raido, you are correct.&lt;/P&gt;&lt;P&gt;His configuration is two-factor auth. (cert and ldap)&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jun 2016 07:04:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-authenticate-with-a-certificate-not-working/m-p/90802#M43594</guid>
      <dc:creator>emr_1</dc:creator>
      <dc:date>2016-06-22T07:04:30Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect client authenticate with a certificate not working anymore</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-authenticate-with-a-certificate-not-working/m-p/90803#M43595</link>
      <description>&lt;P&gt;It is no problem that the LDAP is the backup solution but if the client has the certificate no ldap is required.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jun 2016 07:06:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-authenticate-with-a-certificate-not-working/m-p/90803#M43595</guid>
      <dc:creator>ZEBIT</dc:creator>
      <dc:date>2016-06-22T07:06:36Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect client authenticate with a certificate not working anymore</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-authenticate-with-a-certificate-not-working/m-p/90822#M43597</link>
      <description>&lt;P&gt;ZEBIT your current setup does not set LDAP as backup.&lt;/P&gt;&lt;P&gt;There is AND between those profiles.&lt;/P&gt;&lt;P&gt;You require certificate AND credentials.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jun 2016 07:46:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-authenticate-with-a-certificate-not-working/m-p/90822#M43597</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2016-06-22T07:46:09Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect client authenticate with a certificate not working anymore</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-authenticate-with-a-certificate-not-working/m-p/90825#M43599</link>
      <description>&lt;P&gt;Ok, than our vendor did a mis configuration. Strange that it worked before we updated to PAN OS 7.0.6.&lt;/P&gt;&lt;P&gt;How can I make it work when the client has the certificate it can authenticate?&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jun 2016 08:04:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-authenticate-with-a-certificate-not-working/m-p/90825#M43599</guid>
      <dc:creator>ZEBIT</dc:creator>
      <dc:date>2016-06-22T08:04:34Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect client authenticate with a certificate not working anymore</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-authenticate-with-a-certificate-not-working/m-p/90959#M43618</link>
      <description>&lt;P&gt;Your internal users who have cert use one portal address with portal/gateway config that authenticates with certificate and third parties use different portal id that points to different gateway. Portal/gateway set up for third parties who don't have client cert authenticate only using LDAP.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jun 2016 12:33:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-authenticate-with-a-certificate-not-working/m-p/90959#M43618</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2016-06-22T12:33:08Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect client authenticate with a certificate not working anymore</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-authenticate-with-a-certificate-not-working/m-p/91460#M43642</link>
      <description>&lt;P&gt;Yesterday we found the solution. Due the update the settings for cert authentication are a bit different.&lt;/P&gt;&lt;P&gt;In the certificate profile you need to choose on what detail in the cert it has to check: CN, Principel name, Email.&lt;/P&gt;&lt;P&gt;We check for the principel name, because the principel name has to be in a specific group before it can login through the certificate.&lt;/P&gt;&lt;P&gt;Now everything works.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jun 2016 07:59:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-authenticate-with-a-certificate-not-working/m-p/91460#M43642</guid>
      <dc:creator>ZEBIT</dc:creator>
      <dc:date>2016-06-23T07:59:29Z</dc:date>
    </item>
  </channel>
</rss>

