<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GlobalProtect Client Certificate not Found in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-certificate-not-found/m-p/254040#M72129</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/52796"&gt;@LukeBullimore&lt;/a&gt;&amp;nbsp;, did you manage to sort this out...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the reason i ask is that i too am having issues with cert auth on V8 whereas i had no issues on V7.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i cannot get basic cert auth working, never mind the pre-logon stuff...&lt;/P&gt;</description>
    <pubDate>Mon, 18 Mar 2019 11:15:16 GMT</pubDate>
    <dc:creator>Mick_Ball</dc:creator>
    <dc:date>2019-03-18T11:15:16Z</dc:date>
    <item>
      <title>GlobalProtect Client Certificate not Found</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-certificate-not-found/m-p/253684#M72020</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am trying to demo pre-logon and am really struggling with the client certificate authentication side of things.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've generated a Root CA on the firewall which has been imported into the Personal and Trusted Root Stores of the machine.&lt;/P&gt;&lt;P&gt;The portal is set to use this certificate via a certificate profile which has been configured.&lt;/P&gt;&lt;P&gt;Connect method has been set to pre-logon always on.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I attempt to access the VPN on the desktop, I get the message "Required client certificate not found". Despite the fact that the cert specified in the certificate profile is in all the right certificate stores.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Help! (GP Version 4.1.8)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Luke.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Mar 2019 11:38:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-certificate-not-found/m-p/253684#M72020</guid>
      <dc:creator>LukeBullimore</dc:creator>
      <dc:date>2019-03-14T11:38:05Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Client Certificate not Found</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-certificate-not-found/m-p/253715#M72030</link>
      <description>&lt;P&gt;not sure about pre logon stuff but for my certificate auth i created a root CA on the Palo, i then genereated another certificate for a user that was signed by that CA.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I then exported the user cert in pks12 format and imported that cert into the computer&amp;nbsp;or user personal store.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the original CA is in the cert profile listed under portal and gateway auth.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;you will also need to ensure the GP portal app allows bot user and comp store.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Mar 2019 14:27:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-certificate-not-found/m-p/253715#M72030</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-03-14T14:27:14Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Client Certificate not Found</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-certificate-not-found/m-p/253716#M72031</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've just tried this and unfortunately, I still get the same result. Was your user cert marked as a CA? Mine currently isn't.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any other suggestions?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Luke.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Mar 2019 14:34:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-certificate-not-found/m-p/253716#M72031</guid>
      <dc:creator>LukeBullimore</dc:creator>
      <dc:date>2019-03-14T14:34:20Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Client Certificate not Found</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-certificate-not-found/m-p/253717#M72032</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Did you create a Root CA, Intermediate CA and Machine Cert so the whole certificatechain is complete?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Root and Intermediate needs to be marked as CA.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If so you should be able to export the Machine Certificate as PKCS as MickBall mentioned and import it to your local certificate (computer)store.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Section B in the below link should help you wuth all the steps for certificate authentication.&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClFoCAK" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClFoCAK&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Did you do any specific settings in the Certificate Profile? Ive seen some strange issues if some of the boxes are marked.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;/PV&lt;/P&gt;</description>
      <pubDate>Thu, 14 Mar 2019 14:47:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-certificate-not-found/m-p/253717#M72032</guid>
      <dc:creator>xen-pv</dc:creator>
      <dc:date>2019-03-14T14:47:08Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Client Certificate not Found</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-certificate-not-found/m-p/253719#M72033</link>
      <description>&lt;P&gt;no, my users certs are not CA they just show the CA as the issuer.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ok why dont you go back a step and forget the pre logon stuff and firstly just get the cert auth to work without pre logon.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the other info coming in fro&amp;nbsp; &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/77751"&gt;@xen-pv&lt;/a&gt;&amp;nbsp;may be more helpful for pre logon as we do not actually use it,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Mar 2019 14:54:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-certificate-not-found/m-p/253719#M72033</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-03-14T14:54:12Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Client Certificate not Found</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-certificate-not-found/m-p/253721#M72034</link>
      <description>&lt;P&gt;sorry i meant to say go back a step just to test your cert auth, once you've got that sussed then add pre-logon.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Mar 2019 15:00:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-certificate-not-found/m-p/253721#M72034</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-03-14T15:00:42Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Client Certificate not Found</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-certificate-not-found/m-p/253732#M72037</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I disabled prelogon&amp;nbsp;and still get the same result.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/77751"&gt;@xen-pv&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I just tried with the full chain and the still result. Self-signed root and intermediate on the firewall, both specified in the cert profile.&lt;/P&gt;&lt;P&gt;Generated a primary cert signed by the intermediate, exported to the client and stored in personal and trusted root and still get "Required client certificate not found"&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Am I doing something wrong?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Luke.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Mar 2019 15:50:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-certificate-not-found/m-p/253732#M72037</guid>
      <dc:creator>LukeBullimore</dc:creator>
      <dc:date>2019-03-14T15:50:05Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Client Certificate not Found</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-certificate-not-found/m-p/253734#M72038</link>
      <description>&lt;P&gt;do you get the same error when you browse https to the portal address&lt;/P&gt;</description>
      <pubDate>Thu, 14 Mar 2019 15:56:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-certificate-not-found/m-p/253734#M72038</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-03-14T15:56:49Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Client Certificate not Found</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-certificate-not-found/m-p/253739#M72042</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I do, yes.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Mar 2019 16:12:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-certificate-not-found/m-p/253739#M72042</guid>
      <dc:creator>LukeBullimore</dc:creator>
      <dc:date>2019-03-14T16:12:57Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Client Certificate not Found</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-certificate-not-found/m-p/253741#M72044</link>
      <description>&lt;P&gt;could you check the client machine cert to ensure it has something in the&amp;nbsp;subject field.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Mar 2019 16:37:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-certificate-not-found/m-p/253741#M72044</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-03-14T16:37:03Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Client Certificate not Found</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-certificate-not-found/m-p/253742#M72045</link>
      <description>&lt;P&gt;also lokk in IE under options/content/certificates just to make sure you can see this cert if you import to the users personal store.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Mar 2019 16:40:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-certificate-not-found/m-p/253742#M72045</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-03-14T16:40:32Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Client Certificate not Found</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-certificate-not-found/m-p/254040#M72129</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/52796"&gt;@LukeBullimore&lt;/a&gt;&amp;nbsp;, did you manage to sort this out...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the reason i ask is that i too am having issues with cert auth on V8 whereas i had no issues on V7.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i cannot get basic cert auth working, never mind the pre-logon stuff...&lt;/P&gt;</description>
      <pubDate>Mon, 18 Mar 2019 11:15:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-certificate-not-found/m-p/254040#M72129</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-03-18T11:15:16Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Client Certificate not Found</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-certificate-not-found/m-p/254042#M72130</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I cannot get this to work either, basic cert auth.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I even had a scenario with a proper PKI setup and even then it wasn't working. There must be something I'm missing here!&lt;/P&gt;</description>
      <pubDate>Mon, 18 Mar 2019 11:25:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-certificate-not-found/m-p/254042#M72130</guid>
      <dc:creator>LukeBullimore</dc:creator>
      <dc:date>2019-03-18T11:25:43Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Client Certificate not Found</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-certificate-not-found/m-p/254048#M72132</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/52796"&gt;@LukeBullimore&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Been away for abit..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have set up a working solution in 8.0 and 8.1 with only certificates. Also used certificates from an internal PKI, but that should not matter if you have exported the certificates to your client in the correct way.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How is your certificate-profile setup?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is the UserName-filed set to subject-alt and Principal Name?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You could try to set it up with simple logon with local-accounts to starts with. When you have verified that you can connect to both Portal and Gateway you can go ahead and change the authentication on the Portal to only the certificate-profile. When that is in place you can also verify that pre-logon is working.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;/xen-pv&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Mar 2019 12:14:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-certificate-not-found/m-p/254048#M72132</guid>
      <dc:creator>xen-pv</dc:creator>
      <dc:date>2019-03-18T12:14:57Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Client Certificate not Found</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-certificate-not-found/m-p/254062#M72134</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/77751"&gt;@xen-pv&lt;/a&gt;&amp;nbsp;, Hi.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am also having the same issue, i just need cert auth for portal only.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have it configured on 7.1.15&amp;nbsp; for GlobalProtect using both PKI for windows users and Self Signed for IPad users.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am doing exactly the same process on 8.0.10 but cert auth is failing, &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/52796"&gt;@LukeBullimore&lt;/a&gt;&amp;nbsp;seems to be having a similar issue so I'm also sure i've missed something simple....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have generated a self cert, as a CA.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have then generated a user cert signed by the above and entered a CN.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i have exported/imported as PKCS12 onto my laptop user store.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a cert profile set to subject common-name and added this profile to my portal auth page...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;this is a replication of what I have done on 7.1x so completely stumped.....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks in advance&lt;/P&gt;</description>
      <pubDate>Mon, 18 Mar 2019 13:37:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-certificate-not-found/m-p/254062#M72134</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-03-18T13:37:30Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Client Certificate not Found</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-certificate-not-found/m-p/254066#M72135</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&amp;nbsp;If you are only using the certificate-profile on the portal - set Username-field to "None" and only add the root-certificate to the profile.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;UserName-field is only needed if you are authenticating to the gateway with a certificate as well. Subject us pulled from the certificate and is used as the "Username".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am normally setting it up with certificate-profile on the Portal and LDAP with SSO on the gateway witch do not require that any information is pulled from the certificate.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As ive set up the certificates:&lt;/P&gt;&lt;P&gt;1. Imported Root CA and marked it as "Trusted"'&lt;/P&gt;&lt;P&gt;2. Imported Intermediate CA that is signed by the Root CA&lt;/P&gt;&lt;P&gt;3. Made sure client has a machinecertificate (In Personal Computer store) that is signed by the Intermediate CA&lt;/P&gt;&lt;P&gt;4. Made sure the client has the Root CA &amp;amp; Intermediate in the local certificatestore&lt;/P&gt;&lt;P&gt;5. Create Certificate Profile, set the Username-Field to None, add the Root CA&lt;/P&gt;&lt;P&gt;6. Add the Certificate Profile to the Portal and commit&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have not set it up on 7.1 before, so not sure what the difference could be.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Mar 2019 14:08:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-certificate-not-found/m-p/254066#M72135</guid>
      <dc:creator>xen-pv</dc:creator>
      <dc:date>2019-03-18T14:08:33Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Client Certificate not Found</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-certificate-not-found/m-p/254164#M72151</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/77751"&gt;@xen-pv&lt;/a&gt;&amp;nbsp;, Hi, thanks for the info..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i think we need to go back a step here as I seem to have jumped into &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/52796"&gt;@LukeBullimore&lt;/a&gt;'s call.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;he logged a call regarding pre-logon, i suggested he just tried to get basic auth working first with certificates and he was unable to do this, i also tried to do this from scratch to explain exactly how I did it but it also failed for me yet I have been using it for many years on Windows (cert only) and IPad (cert and ldap).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;so, i am not using it for pre-logon and i do need the subject set in the cert profile as this CN determines which portal app config they get..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;so to test, as i always have done is to just browse to the portal.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;on my V7.x all is OK but on my 8.0 and above it fails so I am deffo missing something obvious.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks again for your time and sorry for the confusion...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Mar 2019 09:12:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-certificate-not-found/m-p/254164#M72151</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-03-19T09:12:32Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Client Certificate not Found</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-certificate-not-found/m-p/254178#M72154</link>
      <description>&lt;P&gt;OK it seems that I had the same CN in my forward trust as i had in my trusted root CA for client certs, not sure why this would cause an auth fail as i clearly stated the trusted root CA in my cert profile.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I created a new root CA with a different CN ( a secondary ip interface) and all certs work for both portals and gateways.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/52796"&gt;@LukeBullimore&lt;/a&gt;&amp;nbsp;, not sure how your getting on but will be happy to post step by step config for cert auth if required, cant help with pre-logon as don't use it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Laters...&lt;/P&gt;</description>
      <pubDate>Tue, 19 Mar 2019 11:24:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-certificate-not-found/m-p/254178#M72154</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-03-19T11:24:28Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Client Certificate not Found</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-certificate-not-found/m-p/254190#M72159</link>
      <description>&lt;P&gt;Hey Mick,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I actually was doing the same thing with ForwardTrust and that mine would be fixed as with yours but unfortunately not.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Self signed Root and Intermediate Certificate on FW which are added to cert profile&lt;/P&gt;&lt;P&gt;Certificate signed by intermediate imported onto client machine in Personal and Trusted Root stores&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Still get the client certificate not found, what am I doing wrong!!&lt;/P&gt;</description>
      <pubDate>Tue, 19 Mar 2019 13:58:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-certificate-not-found/m-p/254190#M72159</guid>
      <dc:creator>LukeBullimore</dc:creator>
      <dc:date>2019-03-19T13:58:23Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Client Certificate not Found</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-certificate-not-found/m-p/254191#M72160</link>
      <description>&lt;P&gt;Luke, Hi.&lt;/P&gt;&lt;P&gt;firstly mine is signed by the root, i dont have an intermediate, never needed it...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;secondly.. are you exporting client cert with PKCS12 format&lt;/P&gt;</description>
      <pubDate>Tue, 19 Mar 2019 14:02:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-certificate-not-found/m-p/254191#M72160</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-03-19T14:02:39Z</dc:date>
    </item>
  </channel>
</rss>

