<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ADSSP Integration for Cached PW Update in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/adssp-integration-for-cached-pw-update/m-p/244272#M69729</link>
    <description>&lt;P&gt;Wondering if anyone has successfully integrated ADSSP Cached Credential Updating with PAN VPN and GlobalProtect client.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have tried to find command line references for the GP client but am coming up blank.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ADSSP needs to call the VPN connection during a password reset so that it can update cached credentials for a remote user.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 21 Dec 2018 17:02:10 GMT</pubDate>
    <dc:creator>mcarter_ssllc</dc:creator>
    <dc:date>2018-12-21T17:02:10Z</dc:date>
    <item>
      <title>ADSSP Integration for Cached PW Update</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/adssp-integration-for-cached-pw-update/m-p/244272#M69729</link>
      <description>&lt;P&gt;Wondering if anyone has successfully integrated ADSSP Cached Credential Updating with PAN VPN and GlobalProtect client.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have tried to find command line references for the GP client but am coming up blank.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ADSSP needs to call the VPN connection during a password reset so that it can update cached credentials for a remote user.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Dec 2018 17:02:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/adssp-integration-for-cached-pw-update/m-p/244272#M69729</guid>
      <dc:creator>mcarter_ssllc</dc:creator>
      <dc:date>2018-12-21T17:02:10Z</dc:date>
    </item>
    <item>
      <title>Re: ADSSP Integration for Cached PW Update</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/adssp-integration-for-cached-pw-update/m-p/245292#M69923</link>
      <description>&lt;P&gt;I am working on this same issue. Any luck?&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jan 2019 03:10:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/adssp-integration-for-cached-pw-update/m-p/245292#M69923</guid>
      <dc:creator>csanchez</dc:creator>
      <dc:date>2019-01-09T03:10:23Z</dc:date>
    </item>
    <item>
      <title>Re: ADSSP Integration for Cached PW Update</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/adssp-integration-for-cached-pw-update/m-p/245752#M70020</link>
      <description>&lt;P&gt;So far, no.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In my testing with ManageEngine devs, we have not been able to find a command that will initiate a user connection.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ManageEngine concluded GP doesnt support command line mode&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My fallback is to set up PAN Pre-Logon which is of course a certificate based session, and will turn cached credential updating into a two-step process for remote users. One to initiate the pre-logon VPN, and two to complete the password change with the GINA client. The user should then be able to logon and switch the GP client to a user session.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would think pre-logon could be automated via CLI since there is no user info involved. Perhaps someone will have an answer for that.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There is an OpenConnect client user build floating around that supports command line session initiation with PAN-OS, however I cannot install unofficial clients on our machines so it doesnt help my use case.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Jan 2019 21:37:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/adssp-integration-for-cached-pw-update/m-p/245752#M70020</guid>
      <dc:creator>mcarter_ssllc</dc:creator>
      <dc:date>2019-01-11T21:37:47Z</dc:date>
    </item>
  </channel>
</rss>

