<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Globalprotect Smart Card configuration in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-smart-card-configuration/m-p/296176#M77952</link>
    <description>&lt;P&gt;So my company is working to setup a new PKI infrastructure with smart card logins for the users. I have looked at all the 2FA and associated articles about setting up the VPN but it leaves a lot to the imagination. I followed the steps creating the certificate profile and assigning it to the portal and gateway. But when i test it the issue i arrive at is the initial login to the vpn. If i were to sign into the workstation with my smart card and was already signed into the VPN it may or may not prompt for my pin. If i go into the menu and logout if the VPN it prompts for username and password.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;This could either be a failure on my configuration or a simple lack of understanding on my part. Is an initial login required and then never used again so long as you dont logout? Did i configure things incorrectly and it should login automatically? For reference we are attempting to swap from the existiny LDAP setup that uses the users login credentials to also login to the VPN. Any help would be greatly appreciated.&lt;/P&gt;</description>
    <pubDate>Mon, 04 Nov 2019 20:36:57 GMT</pubDate>
    <dc:creator>j.bartha</dc:creator>
    <dc:date>2019-11-04T20:36:57Z</dc:date>
    <item>
      <title>Globalprotect Smart Card configuration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-smart-card-configuration/m-p/296176#M77952</link>
      <description>&lt;P&gt;So my company is working to setup a new PKI infrastructure with smart card logins for the users. I have looked at all the 2FA and associated articles about setting up the VPN but it leaves a lot to the imagination. I followed the steps creating the certificate profile and assigning it to the portal and gateway. But when i test it the issue i arrive at is the initial login to the vpn. If i were to sign into the workstation with my smart card and was already signed into the VPN it may or may not prompt for my pin. If i go into the menu and logout if the VPN it prompts for username and password.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;This could either be a failure on my configuration or a simple lack of understanding on my part. Is an initial login required and then never used again so long as you dont logout? Did i configure things incorrectly and it should login automatically? For reference we are attempting to swap from the existiny LDAP setup that uses the users login credentials to also login to the VPN. Any help would be greatly appreciated.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Nov 2019 20:36:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-smart-card-configuration/m-p/296176#M77952</guid>
      <dc:creator>j.bartha</dc:creator>
      <dc:date>2019-11-04T20:36:57Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect Smart Card configuration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-smart-card-configuration/m-p/296183#M77953</link>
      <description>&lt;P&gt;These are the instructions I am referring to having followed.&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://docs.paloaltonetworks.com/globalprotect/8-1/globalprotect-admin/authentication/set-up-two-factor-authentication/enable-two-factor-authentication-using-smart-cards" target="_blank"&gt;https://docs.paloaltonetworks.com/globalprotect/8-1/globalprotect-admin/authentication/set-up-two-factor-authentication/enable-two-factor-authentication-using-smart-cards&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Nov 2019 20:41:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-smart-card-configuration/m-p/296183#M77953</guid>
      <dc:creator>j.bartha</dc:creator>
      <dc:date>2019-11-04T20:41:53Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect Smart Card configuration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-smart-card-configuration/m-p/297059#M78021</link>
      <description>&lt;P&gt;I am still looking for any help that anyone could provide. Documentation, personal experience, or just to tell me it is not possible to remedy.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Nov 2019 16:00:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-smart-card-configuration/m-p/297059#M78021</guid>
      <dc:creator>j.bartha</dc:creator>
      <dc:date>2019-11-07T16:00:43Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect Smart Card configuration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-smart-card-configuration/m-p/300826#M78578</link>
      <description>&lt;P&gt;I'm still looking for anyone with experience with this issue. Or anyone with any reference or instructions that can help me narrow down the issue. The current work around we are going to go with involves enforcing smart card login by group policy. This retains the users login info allowing them to stay connected to the vpn. But this isnt the way we would like to do it. It is just the available alternative. If anyone knows of a solution to my problem please take the time to help out. I feel like its a simple solution that im just not seeing.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Nov 2019 19:04:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-smart-card-configuration/m-p/300826#M78578</guid>
      <dc:creator>j.bartha</dc:creator>
      <dc:date>2019-11-26T19:04:06Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect Smart Card configuration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-smart-card-configuration/m-p/445194#M100441</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/125326"&gt;@j.bartha&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Did you finally found a solution?&lt;/P&gt;</description>
      <pubDate>Wed, 03 Nov 2021 11:04:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-smart-card-configuration/m-p/445194#M100441</guid>
      <dc:creator>MansuSupportAcc</dc:creator>
      <dc:date>2021-11-03T11:04:13Z</dc:date>
    </item>
  </channel>
</rss>

