<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GlobalProtect with Certificate Profle in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-with-certificate-profle/m-p/229853#M66092</link>
    <description>&lt;P&gt;Do you have a Username Field specified in your Certificate Profile?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you do, the Username field in the GP Client should be locked and you would need to use UserB's password to log in.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 06 Sep 2018 23:54:09 GMT</pubDate>
    <dc:creator>asilliker</dc:creator>
    <dc:date>2018-09-06T23:54:09Z</dc:date>
    <item>
      <title>GlobalProtect with Certificate Profle</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-with-certificate-profle/m-p/229838#M66087</link>
      <description>&lt;P&gt;I have configured GlobalProtect to use Authentication Profile using LDAP (sAMAccountName) and a Certificate profile.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have user certificates pushed through Group Policy.&amp;nbsp; The configuration works. However, I noticed a few things&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1) If I login as UserA and delete the certificate from UserA's personal store, VPN will not connect&amp;nbsp; (this is expected)&lt;/P&gt;&lt;P&gt;2) If I login as UserA, delete UsersA certificate and import UserB's cerificate, VPN connects!&amp;nbsp; (this is unexpected)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The easy and obvious solution is don't allow export of certificates. I feel there should be a way to prevent this scenario from connecting, but haven't been able to figure it out.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Sep 2018 21:31:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-with-certificate-profle/m-p/229838#M66087</guid>
      <dc:creator>ce1028</dc:creator>
      <dc:date>2018-09-06T21:31:44Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect with Certificate Profle</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-with-certificate-profle/m-p/229853#M66092</link>
      <description>&lt;P&gt;Do you have a Username Field specified in your Certificate Profile?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you do, the Username field in the GP Client should be locked and you would need to use UserB's password to log in.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Sep 2018 23:54:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-with-certificate-profle/m-p/229853#M66092</guid>
      <dc:creator>asilliker</dc:creator>
      <dc:date>2018-09-06T23:54:09Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect with Certificate Profle</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-with-certificate-profle/m-p/229867#M66098</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/14490"&gt;@asilliker&lt;/a&gt;I tried setting the username field in the certificate profile to Subject Alt, It surely fixes the username issue, as it will cause the username to be username@mydomain.com and is greyed out. The problem is it will never accept the user's password, even if it's the right username/password combo.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Sep 2018 01:11:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-with-certificate-profle/m-p/229867#M66098</guid>
      <dc:creator>ce1028</dc:creator>
      <dc:date>2018-09-07T01:11:28Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect with Certificate Profle</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-with-certificate-profle/m-p/229868#M66099</link>
      <description>&lt;P&gt;duh me.&amp;nbsp;I figured it out, my authenticaiton profile needed to be changed from sAMAccountName to userPrincipalName&lt;/P&gt;</description>
      <pubDate>Fri, 07 Sep 2018 01:24:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-with-certificate-profle/m-p/229868#M66099</guid>
      <dc:creator>ce1028</dc:creator>
      <dc:date>2018-09-07T01:24:07Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect with Certificate Profle</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-with-certificate-profle/m-p/230935#M66324</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/71649"&gt;@ce1028&lt;/a&gt;&amp;nbsp;I am interested in getting the User certificate configured as well. Did you configure the user certificate yourself or was it done previously by someone else. Just curious if you have tips or a good reference guide to setup the user certificate correctly. I've only been able to setup device certificates with ADCS but I keep getting impersonation errors when trying to deploy user certificates. Any guide or reference point would be much appreciated.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Sep 2018 22:00:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-with-certificate-profle/m-p/230935#M66324</guid>
      <dc:creator>harevalo_eog</dc:creator>
      <dc:date>2018-09-14T22:00:21Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect with Certificate Profle</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-with-certificate-profle/m-p/231373#M66431</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/94987"&gt;@harevalo_eog&lt;/a&gt;&amp;nbsp;Yes, I did, it's been&amp;nbsp;a long time since I've touched certificate services.&amp;nbsp; See if this video helps you, at least from the ADCS side&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.youtube.com/watch?v=S7IFp8cGOLs" target="_blank"&gt;https://www.youtube.com/watch?v=S7IFp8cGOLs&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Sep 2018 01:23:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-with-certificate-profle/m-p/231373#M66431</guid>
      <dc:creator>ce1028</dc:creator>
      <dc:date>2018-09-19T01:23:39Z</dc:date>
    </item>
  </channel>
</rss>

