<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GlobalProtect  - Client Certificates Deployment in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-certificates-deployment/m-p/103570#M44632</link>
    <description>&lt;P&gt;Makes sense. Thanks for the response.&lt;/P&gt;</description>
    <pubDate>Tue, 16 Aug 2016 19:27:45 GMT</pubDate>
    <dc:creator>Creid</dc:creator>
    <dc:date>2016-08-16T19:27:45Z</dc:date>
    <item>
      <title>GlobalProtect  - Client Certificates Deployment</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-certificates-deployment/m-p/103446#M44621</link>
      <description>&lt;P&gt;Greetings,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have used the following article to distribute client certificates for GlobalProtect:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Issue-Certificates-to-GlobalProtect-Devices/ta-p/53642" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Issue-Certificates-to-GlobalProtect-Devices/ta-p/53642&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My understanding is that with this method of certificate distribution, all client machines will have the same client certificate.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I understand that with any system, there's always a risk with regards to security, and that the risk will have to be managed accordingly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My question is are there any major security concerns with each client machine having the same client certificate? If there's any documentation that I can reference, that would be helpful as well.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Aug 2016 13:53:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-certificates-deployment/m-p/103446#M44621</guid>
      <dc:creator>Creid</dc:creator>
      <dc:date>2016-08-16T13:53:31Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect  - Client Certificates Deployment</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-certificates-deployment/m-p/103536#M44630</link>
      <description>&lt;P&gt;Since they still have to sign into globalprotect with their credentials I wouldn't be to worried about having the same cert on all of their equipment, as anybody who gets the cert would still need the username and password. Most organziations use certs pretty heavily and many will have the same cert on all of their machines. We use a cert for one of our wireless SSIDS that uses a common cert, then have another SSID that uses the machine cert to authenticate.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Aug 2016 18:24:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-certificates-deployment/m-p/103536#M44630</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2016-08-16T18:24:18Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect  - Client Certificates Deployment</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-certificates-deployment/m-p/103570#M44632</link>
      <description>&lt;P&gt;Makes sense. Thanks for the response.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Aug 2016 19:27:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-certificates-deployment/m-p/103570#M44632</guid>
      <dc:creator>Creid</dc:creator>
      <dc:date>2016-08-16T19:27:45Z</dc:date>
    </item>
  </channel>
</rss>

