<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GlobalProtect Certificate Prompt in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-certificate-prompt/m-p/142616#M48568</link>
    <description>&lt;P&gt;I thought I would circle back and answer this:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In Windows, if you are using self-signed certificates, I found that both the CA and machine/client certificate must be put in both the Computer and User certificate stores. &amp;nbsp;I am not sure if this works for all variations of Windows, but it works in Win7, 8, and 10 from my testing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;On Windows machine, open MMC console.&lt;/LI&gt;&lt;LI&gt;File-&amp;gt;&lt;STRONG&gt;Add/Remove Snap-ins...&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;Click "&lt;STRONG&gt;Certificates&lt;/STRONG&gt;" and add the &lt;STRONG&gt;Computer Account &lt;/STRONG&gt;certificate store.&lt;/LI&gt;&lt;LI&gt;Close out of Add/Remove Snap-ins...&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;Expand Computer Account store in MMC window.&lt;OL&gt;&lt;LI&gt;Right click &lt;STRONG&gt;Personal&lt;/STRONG&gt;-&amp;gt;&lt;STRONG&gt;Import&lt;/STRONG&gt;&amp;nbsp;&lt;OL&gt;&lt;LI&gt;Import both the CA and the machine/client certificate individually.&lt;/LI&gt;&lt;/OL&gt;&lt;/LI&gt;&lt;LI&gt;Right click T&lt;STRONG&gt;rusted Root Certificates-&amp;gt;Import&lt;/STRONG&gt;&lt;OL&gt;&lt;LI&gt;Import both the CA and the machine/client certificate individually.&lt;/LI&gt;&lt;/OL&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;/LI&gt;&lt;LI&gt;Do steps 1-5 again, except select "&lt;STRONG&gt;My User Account&lt;/STRONG&gt;" certificate store in Step 3. &amp;nbsp;&lt;/LI&gt;&lt;/OL&gt;</description>
    <pubDate>Mon, 13 Feb 2017 01:13:45 GMT</pubDate>
    <dc:creator>mmclimans</dc:creator>
    <dc:date>2017-02-13T01:13:45Z</dc:date>
    <item>
      <title>GlobalProtect Certificate Prompt</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-certificate-prompt/m-p/76147#M42184</link>
      <description>&lt;P&gt;My users using GlobalProtect on Windows are experiencing a very strange problem when they connect with GlobalProtect. &amp;nbsp; I am stuck on this one, any tips, pointers, or possible solutions are much appreciated. &amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;Usage&lt;/STRONG&gt;:&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN&gt;Our GlobalProtect clients connect using pre-logon with certificates. &amp;nbsp;We are not using SSO. &amp;nbsp; &amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;Problem&lt;/STRONG&gt;:&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN&gt;Every once and a while, GlobalPrtect will throw a "certificate error" (see attached image of the error). &amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;Notes&lt;/STRONG&gt;:&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;When I check the Microsoft Certificate store, the certificate is installed correctly.&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;A reboot of the user's computer fixes the issue (certificate prompt does not come back)&lt;/LI&gt;
&lt;LI&gt;Error happens among all the clients, completely at random (typically when they start-up their computer).&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;PAN-OS 7.0.3&lt;/P&gt;
&lt;P&gt;GlobalProtect 2.2.1&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="certerror.png" style="width: 484px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/3486i6D55DDD6CF059695/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="certerror.png" alt="certerror.png" /&gt;&lt;/span&gt;﻿&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Apr 2016 13:04:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-certificate-prompt/m-p/76147#M42184</guid>
      <dc:creator>mmclimans</dc:creator>
      <dc:date>2016-04-11T13:04:58Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Certificate Prompt</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-certificate-prompt/m-p/142616#M48568</link>
      <description>&lt;P&gt;I thought I would circle back and answer this:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In Windows, if you are using self-signed certificates, I found that both the CA and machine/client certificate must be put in both the Computer and User certificate stores. &amp;nbsp;I am not sure if this works for all variations of Windows, but it works in Win7, 8, and 10 from my testing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;On Windows machine, open MMC console.&lt;/LI&gt;&lt;LI&gt;File-&amp;gt;&lt;STRONG&gt;Add/Remove Snap-ins...&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;Click "&lt;STRONG&gt;Certificates&lt;/STRONG&gt;" and add the &lt;STRONG&gt;Computer Account &lt;/STRONG&gt;certificate store.&lt;/LI&gt;&lt;LI&gt;Close out of Add/Remove Snap-ins...&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;Expand Computer Account store in MMC window.&lt;OL&gt;&lt;LI&gt;Right click &lt;STRONG&gt;Personal&lt;/STRONG&gt;-&amp;gt;&lt;STRONG&gt;Import&lt;/STRONG&gt;&amp;nbsp;&lt;OL&gt;&lt;LI&gt;Import both the CA and the machine/client certificate individually.&lt;/LI&gt;&lt;/OL&gt;&lt;/LI&gt;&lt;LI&gt;Right click T&lt;STRONG&gt;rusted Root Certificates-&amp;gt;Import&lt;/STRONG&gt;&lt;OL&gt;&lt;LI&gt;Import both the CA and the machine/client certificate individually.&lt;/LI&gt;&lt;/OL&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;/LI&gt;&lt;LI&gt;Do steps 1-5 again, except select "&lt;STRONG&gt;My User Account&lt;/STRONG&gt;" certificate store in Step 3. &amp;nbsp;&lt;/LI&gt;&lt;/OL&gt;</description>
      <pubDate>Mon, 13 Feb 2017 01:13:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-certificate-prompt/m-p/142616#M48568</guid>
      <dc:creator>mmclimans</dc:creator>
      <dc:date>2017-02-13T01:13:45Z</dc:date>
    </item>
  </channel>
</rss>

