<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GlobalProtect Portal - No certificate profile configured, but prompt for certificate in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-portal-no-certificate-profile-configured-but/m-p/267919#M74512</link>
    <description>&lt;P&gt;Well, as a 7 year instructor, the requirement (not recommendation) is that the portal NEEDS to have a certificate (preferably publically signed).&amp;nbsp;&lt;/P&gt;&lt;P&gt;The field below (in yellow) is a REQURED field.&amp;nbsp; Not sure how you are programing a portal without a certificate profile.&lt;/P&gt;&lt;P&gt;It should be the same SSL/TLS profile that is being used by the Gateway.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="portal.png" style="width: 508px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/20337i7B2913875D26B29E/image-dimensions/508x298/is-moderation-mode/true?v=v2" width="508" height="298" role="button" title="portal.png" alt="portal.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class="p"&gt;Before you can configure the GlobalProtect portal, you must complete the following tasks:&lt;/DIV&gt;&lt;UL&gt;&lt;LI&gt;&lt;DIV class="p"&gt;Create the interfaces (and zones) for the firewall interface where you plan to configure the portal. See &lt;A title="" href="https://docs.paloaltonetworks.com/content/techdocs/en_US/globalprotect/8-0/globalprotect-admin/get-started/create-interfaces-and-zones-for-globalprotect.html#id3c324ff2-c9e1-4480-a286-4718426353c7" target="_self"&gt;Create Interfaces and Zones for GlobalProtect&lt;/A&gt;.&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class="p"&gt;&lt;STRONG&gt;Set up the portal server certificate, &lt;/STRONG&gt;gateway server certificate, SSL/TLS service profiles, and, optionally, any client certificates to deploy to end users to enable SSL/TLS connections for the GlobalProtect™ services. See &lt;A title="" href="https://docs.paloaltonetworks.com/content/techdocs/en_US/globalprotect/8-0/globalprotect-admin/get-started/enable-ssl-between-globalprotect-components.html#idf9ae4a57-e8e0-492f-b49c-b78a8cde430c" target="_self"&gt;Enable SSL Between GlobalProtect Components&lt;/A&gt;.&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class="p"&gt;Define the optional authentication profiles and certificate profiles that the portal can use to authenticate GlobalProtect users. See &lt;A title="" href="https://docs.paloaltonetworks.com/content/techdocs/en_US/globalprotect/8-0/globalprotect-admin/authentication.html#id40041484-d1e0-465a-a970-a8af5dc53f79" target="_self"&gt;Authentication&lt;/A&gt;.&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class="p"&gt;&lt;A title="" href="https://docs.paloaltonetworks.com/content/techdocs/en_US/globalprotect/8-0/globalprotect-admin/globalprotect-gateways/configure-a-globalprotect-gateway.html#id0687b049-6664-4054-96dc-ba880f8c92c9" target="_self"&gt;Configure a GlobalProtect Gateway&lt;/A&gt; and understand &lt;A title="" href="https://docs.paloaltonetworks.com/content/techdocs/en_US/globalprotect/8-0/globalprotect-admin/globalprotect-gateways/globalprotect-gateway-concepts/gateway-priority-in-a-multiple-gateway-configuration.html#id6840a280-54cd-4ced-b9dd-0171092bcea2" target="_self"&gt;Gateway Priority in a Multiple Gateway Configuration&lt;/A&gt;.&lt;/DIV&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Please feel free to respond back to better clarify what you are trying to do.&lt;/P&gt;</description>
    <pubDate>Fri, 07 Jun 2019 14:22:46 GMT</pubDate>
    <dc:creator>S.Cantwell</dc:creator>
    <dc:date>2019-06-07T14:22:46Z</dc:date>
    <item>
      <title>GlobalProtect Portal - No certificate profile configured, but prompt for certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-portal-no-certificate-profile-configured-but/m-p/267743#M74492</link>
      <description>&lt;P&gt;Hi Community,&lt;/P&gt;&lt;P&gt;I got a strange problem and want to hear, if someone got the same.&lt;/P&gt;&lt;P&gt;We got a Panorama managed PA-3220 PAN-OS 8.1.7 with GlobalProtect portal, external gateway (which share the same IP) and an internal gateway.&lt;/P&gt;&lt;P&gt;The external gateway got a certificate profile defined, the portal not.&lt;/P&gt;&lt;P&gt;If I open the Webpage, the Portal prompts for a certificate - the same does the GP-client (4.1.12).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I cannot find any issues in the KB or release notes.&lt;BR /&gt;A colleague of mine experienced a similar issue and deleted the portal &amp;amp; gateways and configured that new - then it worked.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The configuration looks good (checked with AutoAssistant and XML-configs).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Looking forward to your feedback.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best Regards&lt;/P&gt;&lt;P&gt;Chacko&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jun 2019 08:13:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-portal-no-certificate-profile-configured-but/m-p/267743#M74492</guid>
      <dc:creator>Chacko42</dc:creator>
      <dc:date>2019-06-07T08:13:18Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Portal - No certificate profile configured, but prompt for certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-portal-no-certificate-profile-configured-but/m-p/267919#M74512</link>
      <description>&lt;P&gt;Well, as a 7 year instructor, the requirement (not recommendation) is that the portal NEEDS to have a certificate (preferably publically signed).&amp;nbsp;&lt;/P&gt;&lt;P&gt;The field below (in yellow) is a REQURED field.&amp;nbsp; Not sure how you are programing a portal without a certificate profile.&lt;/P&gt;&lt;P&gt;It should be the same SSL/TLS profile that is being used by the Gateway.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="portal.png" style="width: 508px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/20337i7B2913875D26B29E/image-dimensions/508x298/is-moderation-mode/true?v=v2" width="508" height="298" role="button" title="portal.png" alt="portal.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class="p"&gt;Before you can configure the GlobalProtect portal, you must complete the following tasks:&lt;/DIV&gt;&lt;UL&gt;&lt;LI&gt;&lt;DIV class="p"&gt;Create the interfaces (and zones) for the firewall interface where you plan to configure the portal. See &lt;A title="" href="https://docs.paloaltonetworks.com/content/techdocs/en_US/globalprotect/8-0/globalprotect-admin/get-started/create-interfaces-and-zones-for-globalprotect.html#id3c324ff2-c9e1-4480-a286-4718426353c7" target="_self"&gt;Create Interfaces and Zones for GlobalProtect&lt;/A&gt;.&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class="p"&gt;&lt;STRONG&gt;Set up the portal server certificate, &lt;/STRONG&gt;gateway server certificate, SSL/TLS service profiles, and, optionally, any client certificates to deploy to end users to enable SSL/TLS connections for the GlobalProtect™ services. See &lt;A title="" href="https://docs.paloaltonetworks.com/content/techdocs/en_US/globalprotect/8-0/globalprotect-admin/get-started/enable-ssl-between-globalprotect-components.html#idf9ae4a57-e8e0-492f-b49c-b78a8cde430c" target="_self"&gt;Enable SSL Between GlobalProtect Components&lt;/A&gt;.&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class="p"&gt;Define the optional authentication profiles and certificate profiles that the portal can use to authenticate GlobalProtect users. See &lt;A title="" href="https://docs.paloaltonetworks.com/content/techdocs/en_US/globalprotect/8-0/globalprotect-admin/authentication.html#id40041484-d1e0-465a-a970-a8af5dc53f79" target="_self"&gt;Authentication&lt;/A&gt;.&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class="p"&gt;&lt;A title="" href="https://docs.paloaltonetworks.com/content/techdocs/en_US/globalprotect/8-0/globalprotect-admin/globalprotect-gateways/configure-a-globalprotect-gateway.html#id0687b049-6664-4054-96dc-ba880f8c92c9" target="_self"&gt;Configure a GlobalProtect Gateway&lt;/A&gt; and understand &lt;A title="" href="https://docs.paloaltonetworks.com/content/techdocs/en_US/globalprotect/8-0/globalprotect-admin/globalprotect-gateways/globalprotect-gateway-concepts/gateway-priority-in-a-multiple-gateway-configuration.html#id6840a280-54cd-4ced-b9dd-0171092bcea2" target="_self"&gt;Gateway Priority in a Multiple Gateway Configuration&lt;/A&gt;.&lt;/DIV&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Please feel free to respond back to better clarify what you are trying to do.&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jun 2019 14:22:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-portal-no-certificate-profile-configured-but/m-p/267919#M74512</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2019-06-07T14:22:46Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Portal - No certificate profile configured, but prompt for certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-portal-no-certificate-profile-configured-but/m-p/267957#M74514</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/113304"&gt;@S.Cantwell&lt;/a&gt;: I agree, but I really mean the certificate profile, not the tls service profile.&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jun 2019 14:57:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-portal-no-certificate-profile-configured-but/m-p/267957#M74514</guid>
      <dc:creator>Chacko42</dc:creator>
      <dc:date>2019-06-07T14:57:53Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Portal - No certificate profile configured, but prompt for certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-portal-no-certificate-profile-configured-but/m-p/267993#M74516</link>
      <description>&lt;P&gt;Howdy again!&lt;/P&gt;&lt;P&gt;I think we (who are reading these messages) are getting just superficial info.&amp;nbsp; We need more details about your configuration setup.&amp;nbsp; I am an instructor who teaches and does PS for my company, so I am pretty familiar with the setup.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is this a new configuration, or something broke?&lt;/P&gt;&lt;P&gt;Are you doing client certificates for authentication?&amp;nbsp; This would be one reason why a request for a cert (probably machine cert would be requested.&amp;nbsp; Do you have "on-demand" or (always-on) in your configuration for your user.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jun 2019 16:20:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-portal-no-certificate-profile-configured-but/m-p/267993#M74516</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2019-06-07T16:20:24Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Portal - No certificate profile configured, but prompt for certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-portal-no-certificate-profile-configured-but/m-p/268002#M74519</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/113304"&gt;@S.Cantwell&lt;/a&gt;:&lt;/P&gt;&lt;P&gt;It's a new installation.&lt;BR /&gt;public portal requires an authentication sequence (primary kerberos, secondary ldap) and got two configs:&lt;BR /&gt;1st config is user logon (always on) for only a ldap group "vpn-users" and deploys the internal gateway for SSO and the external gateway. 2nd is user logon (always on) for everyone else, which deploys only the internal gateway for user id information.&lt;/P&gt;&lt;P&gt;The external gateway requires a user certificate and ldap for authentication.&lt;BR /&gt;The internal gateway got an auth sequence (primary kerberos, secondary ldap).&lt;/P&gt;&lt;P&gt;This setup is my default and works fine with several customers, so I'm confused, why the portal is prompting for a certificate, because no certificate profile is required for the portal.&lt;/P&gt;&lt;P&gt;I already opened up a case with TAC, but I'm interested in this now, and want to understand the issue and find a solution.&lt;/P&gt;&lt;P&gt;AutoAssitant does not see any issues regarding configuration.&lt;/P&gt;&lt;P&gt;Two strange bevahiors:&lt;BR /&gt;&amp;nbsp;1. clients get promptet for user cert when accessing portal (doesn't matter if web-portal or GP client).&lt;/P&gt;&lt;P&gt;&amp;nbsp;2. After connecting to portal, the FW logs a failed kerberos auth for user '' but, there is no Kerberos traffic sent from the client. The GP client logs match this and show a failed authentication for ___empty-user____&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Everything except for Kerberos SSO (the reason I raised the TAC case) with credential provider worked fine, the both issues occured first, after changing the Kerberos config.&lt;/P&gt;&lt;P&gt;I noticed, that we use two SPNs, but had only one Auth-Profile for Kerberos - I missed to export a second keytab with the 2nd SPN.&lt;/P&gt;&lt;P&gt;AD looks fine, both SPNs are matched to the Palo service user, and the keytabs are looking good and where imported succesfully to the config.&lt;BR /&gt;1st auth profile Kerb-Ext-GW shows SPN "vpn.company.com" in keytab while 2nd auth profile Kerb-Int-GW shows SPN "gpgw.internal.local" as SPN&lt;/P&gt;&lt;P&gt;Already rebooted the firewalls and reinstalled the GP clients, but the behavior is persistent&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jun 2019 16:34:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-portal-no-certificate-profile-configured-but/m-p/268002#M74519</guid>
      <dc:creator>Chacko42</dc:creator>
      <dc:date>2019-06-07T16:34:31Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Portal - No certificate profile configured, but prompt for certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-portal-no-certificate-profile-configured-but/m-p/434524#M95990</link>
      <description>&lt;P&gt;I am having the same problem but actually originated in different way.&lt;/P&gt;&lt;P&gt;I enabled and disabled the function (for testing purpouses) several times until, even if "&lt;SPAN&gt;Certificate Profile"&amp;nbsp;&lt;/SPAN&gt;is set no none, it still requires some undetermined sertificate from the VPN clients. I am forced now to leave it on to let people connect.&lt;/P&gt;&lt;P&gt;Luckily, it happened 3 days before the live of the feature.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In means though that I cannot disable the request for client certificates if I need to. I don't like it at all...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Sep 2021 15:00:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-portal-no-certificate-profile-configured-but/m-p/434524#M95990</guid>
      <dc:creator>soalridiudine</dc:creator>
      <dc:date>2021-09-16T15:00:03Z</dc:date>
    </item>
  </channel>
</rss>

