<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic GlobalProtect reports Machine Certificate (null) but it isn't... in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-reports-machine-certificate-null-but-it-isn-t/m-p/282324#M76081</link>
    <description>&lt;P&gt;Hey all,&lt;/P&gt;&lt;P&gt;Recently upgraded to PAN-OS v9.0.3 and GlobalProtect is no longer working for some.&amp;nbsp; Error messages in the system logs are showing GlobalProtect portal client configuration failed...&amp;nbsp; Machine Certificate CN: (null) for those that fail but also Machine Certificate CN: (just a blank here) for those that are successful.&amp;nbsp; This is intermittent and is affecting roughly 25% of our corporate users.&lt;/P&gt;&lt;P&gt;I'm guessing "Machine Certificate" is a general term PA uses since there is no mention in the system logs of a "Client or User Certificate".&amp;nbsp; We employ user certificates, not machine certificates.&amp;nbsp; We have our portal configured to use User Certificates.&amp;nbsp; We also have our Gateway and Portal configured to "Allow Authentication with user credentials OR Client Certificate".&amp;nbsp; This only works IF we delete the client certificate on the endpoint, then they are able to login using only credentials.&amp;nbsp; If we leave it in the OR position it seems to ignore the or and automatically fail with user credentials alone.&lt;/P&gt;&lt;P&gt;Our certificate profile is setup to use the Subject Alt. Name / Principal Name for the username, which matches what's contained within the certificate which matches LDAP / AD.&lt;/P&gt;&lt;P&gt;We do have a case open with Palo Alto.&amp;nbsp; 1st response was that the CN can no longer be null - our logs say different, and the 2nd response was to try an older GP Agent, which we're in the process of.&lt;/P&gt;&lt;P&gt;We've tried deleting the certificate on the failing client machines and re-issuing them - this doesn't work.&lt;/P&gt;&lt;P&gt;A couple of our clients that were originally experiencing issues magically started working.&lt;/P&gt;&lt;P&gt;Just wondering if anyone else has encountered something similar and / or has any suggestions.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;cfowler&lt;/P&gt;</description>
    <pubDate>Mon, 12 Aug 2019 20:27:16 GMT</pubDate>
    <dc:creator>cafowler</dc:creator>
    <dc:date>2019-08-12T20:27:16Z</dc:date>
    <item>
      <title>GlobalProtect reports Machine Certificate (null) but it isn't...</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-reports-machine-certificate-null-but-it-isn-t/m-p/282324#M76081</link>
      <description>&lt;P&gt;Hey all,&lt;/P&gt;&lt;P&gt;Recently upgraded to PAN-OS v9.0.3 and GlobalProtect is no longer working for some.&amp;nbsp; Error messages in the system logs are showing GlobalProtect portal client configuration failed...&amp;nbsp; Machine Certificate CN: (null) for those that fail but also Machine Certificate CN: (just a blank here) for those that are successful.&amp;nbsp; This is intermittent and is affecting roughly 25% of our corporate users.&lt;/P&gt;&lt;P&gt;I'm guessing "Machine Certificate" is a general term PA uses since there is no mention in the system logs of a "Client or User Certificate".&amp;nbsp; We employ user certificates, not machine certificates.&amp;nbsp; We have our portal configured to use User Certificates.&amp;nbsp; We also have our Gateway and Portal configured to "Allow Authentication with user credentials OR Client Certificate".&amp;nbsp; This only works IF we delete the client certificate on the endpoint, then they are able to login using only credentials.&amp;nbsp; If we leave it in the OR position it seems to ignore the or and automatically fail with user credentials alone.&lt;/P&gt;&lt;P&gt;Our certificate profile is setup to use the Subject Alt. Name / Principal Name for the username, which matches what's contained within the certificate which matches LDAP / AD.&lt;/P&gt;&lt;P&gt;We do have a case open with Palo Alto.&amp;nbsp; 1st response was that the CN can no longer be null - our logs say different, and the 2nd response was to try an older GP Agent, which we're in the process of.&lt;/P&gt;&lt;P&gt;We've tried deleting the certificate on the failing client machines and re-issuing them - this doesn't work.&lt;/P&gt;&lt;P&gt;A couple of our clients that were originally experiencing issues magically started working.&lt;/P&gt;&lt;P&gt;Just wondering if anyone else has encountered something similar and / or has any suggestions.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;cfowler&lt;/P&gt;</description>
      <pubDate>Mon, 12 Aug 2019 20:27:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-reports-machine-certificate-null-but-it-isn-t/m-p/282324#M76081</guid>
      <dc:creator>cafowler</dc:creator>
      <dc:date>2019-08-12T20:27:16Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect reports Machine Certificate (null) but it isn't...</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-reports-machine-certificate-null-but-it-isn-t/m-p/282451#M76091</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/4129"&gt;@cafowler&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;There are a number of known GP bugs in 9.0 code yet, so the fact that you are running into issues is not suprising. I would recommend logging a ticket with TAC so they can pull the logs and get it to the proper groups to get it fixed.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;FYI:&lt;/P&gt;&lt;P&gt;9.0 is not yet a recommended release, and short of needing a feature present within 9.0 I would not yet have installed this in a production environement.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Aug 2019 10:22:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-reports-machine-certificate-null-but-it-isn-t/m-p/282451#M76091</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-08-13T10:22:11Z</dc:date>
    </item>
  </channel>
</rss>

