<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Anyone run into a issue where Client Certificate does not get presented to GP if its in the Loca in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/anyone-run-into-a-issue-where-client-certificate-does-not-get/m-p/249881#M71060</link>
    <description>&lt;P&gt;In the portal config I do not, but in the gateway I do.&amp;nbsp; It is when I switch it from the prelogon-cert profile to the internal-PKI profile that I encounter the 'required client cert not found' error.&lt;/P&gt;</description>
    <pubDate>Tue, 12 Feb 2019 19:48:20 GMT</pubDate>
    <dc:creator>psouthwick</dc:creator>
    <dc:date>2019-02-12T19:48:20Z</dc:date>
    <item>
      <title>Anyone run into a issue where Client Certificate does not get presented to GP if its in the Local Ma</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/anyone-run-into-a-issue-where-client-certificate-does-not-get/m-p/190199#M57462</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyone run into a issue where Client Certificate does not get presented to GP if its in the Local Machine Store? I tired giving the user perm but this didnt fix it. Only way to resolve it is to move the cert to the user store, which I dont want to do.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Thaks&lt;/P&gt;</description>
      <pubDate>Tue, 05 Dec 2017 22:04:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/anyone-run-into-a-issue-where-client-certificate-does-not-get/m-p/190199#M57462</guid>
      <dc:creator>junior_r</dc:creator>
      <dc:date>2017-12-05T22:04:31Z</dc:date>
    </item>
    <item>
      <title>Re: Anyone run into a issue where Client Certificate does not get presented to GP if its in the Loca</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/anyone-run-into-a-issue-where-client-certificate-does-not-get/m-p/190210#M57465</link>
      <description>&lt;P&gt;Users with standard permissions don't have access to the machine store. It's not a condition specific to GP.&lt;/P&gt;&lt;P&gt;When you gave permission to the user for the machine cert, how did you do it?&lt;/P&gt;</description>
      <pubDate>Tue, 05 Dec 2017 22:37:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/anyone-run-into-a-issue-where-client-certificate-does-not-get/m-p/190210#M57465</guid>
      <dc:creator>rmfalconer</dc:creator>
      <dc:date>2017-12-05T22:37:39Z</dc:date>
    </item>
    <item>
      <title>Re: Anyone run into a issue where Client Certificate does not get presented to GP if its in the Loca</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/anyone-run-into-a-issue-where-client-certificate-does-not-get/m-p/190216#M57467</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/55733"&gt;@rmfalconer&lt;/a&gt; wrote:&lt;BR /&gt;&lt;P&gt;Users with standard permissions don't have access to the machine store. It's not a condition specific to GP.&lt;/P&gt;&lt;P&gt;When you gave permission to the user for the machine cert, how did you do it?&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Right click on the machine cert, Manage private keys and add user to read&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 06 Dec 2017 01:08:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/anyone-run-into-a-issue-where-client-certificate-does-not-get/m-p/190216#M57467</guid>
      <dc:creator>junior_r</dc:creator>
      <dc:date>2017-12-06T01:08:26Z</dc:date>
    </item>
    <item>
      <title>Re: Anyone run into a issue where Client Certificate does not get presented to GP if its in the Loca</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/anyone-run-into-a-issue-where-client-certificate-does-not-get/m-p/190250#M57471</link>
      <description>&lt;P&gt;Going back to basics,,,, have you checked your setting in the portal app...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Client Certificate Store Lookup.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Dec 2017 07:20:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/anyone-run-into-a-issue-where-client-certificate-does-not-get/m-p/190250#M57471</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2017-12-06T07:20:38Z</dc:date>
    </item>
    <item>
      <title>Re: Anyone run into a issue where Client Certificate does not get presented to GP if its in the Loca</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/anyone-run-into-a-issue-where-client-certificate-does-not-get/m-p/249763#M71025</link>
      <description>&lt;P&gt;Hate to res an old topic, but I am having this very issue as well.&amp;nbsp; Running 4.1.8 GP, have AD auto-enrolling workstations for certificates which only places the certificate in the machine store.&amp;nbsp; The GP Client is setup to look for certificates in the machine store (not both) and I am still getting errors connecting with an error stating 'required client cert not found'.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any thoughts?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Feb 2019 21:51:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/anyone-run-into-a-issue-where-client-certificate-does-not-get/m-p/249763#M71025</guid>
      <dc:creator>psouthwick</dc:creator>
      <dc:date>2019-02-11T21:51:24Z</dc:date>
    </item>
    <item>
      <title>Re: Anyone run into a issue where Client Certificate does not get presented to GP if its in the Loca</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/anyone-run-into-a-issue-where-client-certificate-does-not-get/m-p/249785#M71031</link>
      <description>&lt;P&gt;Can we assume you can see the cert in the machines personal store when using the mmc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;have you tried this firstly with a self signed cert, generate a user cert and manually import into comp store.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;pretty basic stuff but may be worth going back a few steps to see if its a cert read error or pki issue.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Feb 2019 06:29:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/anyone-run-into-a-issue-where-client-certificate-does-not-get/m-p/249785#M71031</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-02-12T06:29:23Z</dc:date>
    </item>
    <item>
      <title>Re: Anyone run into a issue where Client Certificate does not get presented to GP if its in the Loca</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/anyone-run-into-a-issue-where-client-certificate-does-not-get/m-p/249836#M71047</link>
      <description>&lt;P&gt;Thanks for the reply, and good call.&amp;nbsp; I re-imported the self-signed cert (generated by the firewall) I used as a PoC for pre-logon only in the machine store and was able to connect....&amp;nbsp; Though this leaves me scratching my head the certs permissions are identical, both have the private keys, share the same signature algorithms etc.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The only differences I see are the self-signed cert has an additional 'Intended Purpose' of IP Security end system, and the cert CN.&amp;nbsp; The self-signed is just some bogus name I made for testing purposes, and the PKI issued one is my machines FQDN.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The certificate profiles in use for the PKI has our Root and intermediate CAs defined with the rest as defaults, and the self-signed certificate profile has the firewalls CA defined with the rest of the options as default.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Feb 2019 17:04:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/anyone-run-into-a-issue-where-client-certificate-does-not-get/m-p/249836#M71047</guid>
      <dc:creator>psouthwick</dc:creator>
      <dc:date>2019-02-12T17:04:29Z</dc:date>
    </item>
    <item>
      <title>Re: Anyone run into a issue where Client Certificate does not get presented to GP if its in the Loca</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/anyone-run-into-a-issue-where-client-certificate-does-not-get/m-p/249837#M71048</link>
      <description>&lt;P&gt;OK so does the PKI cert on the Palo have "Trusted Root CA" ticked....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;kinda clutching at straws as you seem to have all you need.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I doubt if it's anything to do with the username field in the cert profile as that will cause a different error. "certificate invalid".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;do you get the same error when you browse to https:\\your-portaldotsumfink&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Feb 2019 17:13:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/anyone-run-into-a-issue-where-client-certificate-does-not-get/m-p/249837#M71048</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-02-12T17:13:35Z</dc:date>
    </item>
    <item>
      <title>Re: Anyone run into a issue where Client Certificate does not get presented to GP if its in the Loca</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/anyone-run-into-a-issue-where-client-certificate-does-not-get/m-p/249838#M71049</link>
      <description>&lt;P&gt;cancel my previous re trusted root ca. mines not even ticked and works OK, not sure why i&amp;nbsp;said that... hey ho....&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Feb 2019 17:22:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/anyone-run-into-a-issue-where-client-certificate-does-not-get/m-p/249838#M71049</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-02-12T17:22:38Z</dc:date>
    </item>
    <item>
      <title>Re: Anyone run into a issue where Client Certificate does not get presented to GP if its in the Loca</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/anyone-run-into-a-issue-where-client-certificate-does-not-get/m-p/249844#M71050</link>
      <description>&lt;P&gt;the PKI certificate with your device name, under the details tab, does it have "Client Authentication" in the enhanced key useage.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Feb 2019 17:32:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/anyone-run-into-a-issue-where-client-certificate-does-not-get/m-p/249844#M71050</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-02-12T17:32:17Z</dc:date>
    </item>
    <item>
      <title>Re: Anyone run into a issue where Client Certificate does not get presented to GP if its in the Loca</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/anyone-run-into-a-issue-where-client-certificate-does-not-get/m-p/249875#M71054</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="prelogon-cert.jpg" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/18771i6E36E7FAE31B6284/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="prelogon-cert.jpg" alt="prelogon-cert.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It does, I've attached a screen shot of my config.&amp;nbsp; The green is the self-signed, the blue is our root ca, and red is an intermediate that signed the cert that was deployed to the workstation.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Feb 2019 18:44:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/anyone-run-into-a-issue-where-client-certificate-does-not-get/m-p/249875#M71054</guid>
      <dc:creator>psouthwick</dc:creator>
      <dc:date>2019-02-12T18:44:21Z</dc:date>
    </item>
    <item>
      <title>Re: Anyone run into a issue where Client Certificate does not get presented to GP if its in the Loca</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/anyone-run-into-a-issue-where-client-certificate-does-not-get/m-p/249880#M71059</link>
      <description>&lt;P&gt;In your GP portal configuration, do you have a certificate profile applied?&lt;/P&gt;</description>
      <pubDate>Tue, 12 Feb 2019 19:21:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/anyone-run-into-a-issue-where-client-certificate-does-not-get/m-p/249880#M71059</guid>
      <dc:creator>rmfalconer</dc:creator>
      <dc:date>2019-02-12T19:21:24Z</dc:date>
    </item>
    <item>
      <title>Re: Anyone run into a issue where Client Certificate does not get presented to GP if its in the Loca</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/anyone-run-into-a-issue-where-client-certificate-does-not-get/m-p/249881#M71060</link>
      <description>&lt;P&gt;In the portal config I do not, but in the gateway I do.&amp;nbsp; It is when I switch it from the prelogon-cert profile to the internal-PKI profile that I encounter the 'required client cert not found' error.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Feb 2019 19:48:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/anyone-run-into-a-issue-where-client-certificate-does-not-get/m-p/249881#M71060</guid>
      <dc:creator>psouthwick</dc:creator>
      <dc:date>2019-02-12T19:48:20Z</dc:date>
    </item>
    <item>
      <title>Re: Anyone run into a issue where Client Certificate does not get presented to GP if its in the Loca</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/anyone-run-into-a-issue-where-client-certificate-does-not-get/m-p/250025#M71111</link>
      <description>&lt;P&gt;Do you have a way to distribute a cert to the user store? There could be a permission issue with accessing the computer cert store to verify the correct certificate.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Feb 2019 19:44:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/anyone-run-into-a-issue-where-client-certificate-does-not-get/m-p/250025#M71111</guid>
      <dc:creator>rmfalconer</dc:creator>
      <dc:date>2019-02-13T19:44:20Z</dc:date>
    </item>
    <item>
      <title>Re: Anyone run into a issue where Client Certificate does not get presented to GP if its in the Loca</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/anyone-run-into-a-issue-where-client-certificate-does-not-get/m-p/250032#M71117</link>
      <description>&lt;P&gt;I do not and would actually like to avoid that as I would prefer the machine certificate not follow the user, wherever they login.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Out of curiosity do you, or&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;, have pre-logon setup using certs auto-enrolled from AD; or are you using the SCEP functionality, or manually generating and importing certs?&lt;/P&gt;</description>
      <pubDate>Wed, 13 Feb 2019 20:52:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/anyone-run-into-a-issue-where-client-certificate-does-not-get/m-p/250032#M71117</guid>
      <dc:creator>psouthwick</dc:creator>
      <dc:date>2019-02-13T20:52:45Z</dc:date>
    </item>
    <item>
      <title>Re: Anyone run into a issue where Client Certificate does not get presented to GP if its in the Loca</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/anyone-run-into-a-issue-where-client-certificate-does-not-get/m-p/250055#M71125</link>
      <description>&lt;P&gt;&lt;SPAN&gt;We generate machine certs and user certs, both scoped to specific AD groups. We use certs for more than just VPN so we have a need to deploy both.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Feb 2019 00:09:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/anyone-run-into-a-issue-where-client-certificate-does-not-get/m-p/250055#M71125</guid>
      <dc:creator>rmfalconer</dc:creator>
      <dc:date>2019-02-14T00:09:37Z</dc:date>
    </item>
    <item>
      <title>Re: Anyone run into a issue where Client Certificate does not get presented to GP if its in the Loca</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/anyone-run-into-a-issue-where-client-certificate-does-not-get/m-p/250072#M71135</link>
      <description>&lt;P&gt;I do not use pre logon, it doesn’t really suit our requitements.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I use both pki and self signed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;pki user certs go into user store for globalprotect.&lt;/P&gt;&lt;P&gt;pki machine certs go into machine store for network access control.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;self signed certs are distributed to 3rd party support and non domain maccy stuff.....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;one thing i have noticed is that our machine certs cannot be used for gp as the cert profile is looking for subject field and the machine certs do not contain this information. Perhaps thats your issue...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Feb 2019 06:24:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/anyone-run-into-a-issue-where-client-certificate-does-not-get/m-p/250072#M71135</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-02-14T06:24:48Z</dc:date>
    </item>
    <item>
      <title>Re: Anyone run into a issue where Client Certificate does not get presented to GP if its in the Loca</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/anyone-run-into-a-issue-where-client-certificate-does-not-get/m-p/250768#M71309</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/55733"&gt;@rmfalconer&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just a follow up as I opened up a TAC case for this issue.&amp;nbsp; It turns out that the version of PanOS we are on 8.0.13 does not support SHA512, which is what our internal PKI CAs are hashed with.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Feb 2019 17:58:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/anyone-run-into-a-issue-where-client-certificate-does-not-get/m-p/250768#M71309</guid>
      <dc:creator>psouthwick</dc:creator>
      <dc:date>2019-02-21T17:58:35Z</dc:date>
    </item>
    <item>
      <title>Re: Anyone run into a issue where Client Certificate does not get presented</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/anyone-run-into-a-issue-where-client-certificate-does-not-get/m-p/344544#M86199</link>
      <description>&lt;P&gt;Did you upgrade OS , just to know if that fixed your issue ?&lt;/P&gt;</description>
      <pubDate>Wed, 19 Aug 2020 12:33:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/anyone-run-into-a-issue-where-client-certificate-does-not-get/m-p/344544#M86199</guid>
      <dc:creator>fatboy1607</dc:creator>
      <dc:date>2020-08-19T12:33:29Z</dc:date>
    </item>
  </channel>
</rss>

