<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Sectigo wildcard certificate problem for Globalprotect in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/sectigo-wildcard-certificate-problem-for-globalprotect/m-p/317869#M81680</link>
    <description>&lt;P&gt;Thanks, I've managed to puzzle it together. The final revelation was to use the fqdn name as the external gateway, not the ip.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Case can be closed as resolved &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Sat, 21 Mar 2020 22:04:03 GMT</pubDate>
    <dc:creator>KovBal</dc:creator>
    <dc:date>2020-03-21T22:04:03Z</dc:date>
    <item>
      <title>Sectigo wildcard certificate problem for Globalprotect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sectigo-wildcard-certificate-problem-for-globalprotect/m-p/317860#M81678</link>
      <description>&lt;P&gt;Dear Community,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've recently purchased a wildcard certificate, that I intend to use it on our firewall for globalprotect. It is a single device, and gateway is configured as external gateway (it provides only vpn access from the external world). I've installed the certificate, without any issue, but CA is not ticked on that. Therefore I cannot select this certificate at Portal/Agent/Trusted root ca, and I get error on the client side, with certificate error.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;If I create a self signed certificate to use it for the Gateway, and I use the wildcard for the Portal, client can connect, but then the browser is arguing about bad certificate.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I read something about Sectigo not listed in the default trusted certificate authorities, can that cause the problem? How can I resolve this issue, to keep the official certificate for the whole chain?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm using Pan OS 9.1&lt;/P&gt;</description>
      <pubDate>Sat, 21 Mar 2020 20:53:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sectigo-wildcard-certificate-problem-for-globalprotect/m-p/317860#M81678</guid>
      <dc:creator>KovBal</dc:creator>
      <dc:date>2020-03-21T20:53:57Z</dc:date>
    </item>
    <item>
      <title>Re: Sectigo wildcard certificate problem for Globalprotect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sectigo-wildcard-certificate-problem-for-globalprotect/m-p/317866#M81679</link>
      <description>&lt;P&gt;You don't need a CA for the portal, neither for the gateway. Using the wildcard certificate should work fine.&lt;/P&gt;&lt;P&gt;If you intend to use certificate based authentication (user and/or machine certificate), then you need a CA which signes the user/machine certificates. This CA needs to be listed as trusted CA in the portal (the portal will then only accept the certificate if it is signed by the "trusted CA" you have listed).&lt;/P&gt;</description>
      <pubDate>Sat, 21 Mar 2020 21:34:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sectigo-wildcard-certificate-problem-for-globalprotect/m-p/317866#M81679</guid>
      <dc:creator>JoergSchuetter</dc:creator>
      <dc:date>2020-03-21T21:34:59Z</dc:date>
    </item>
    <item>
      <title>Re: Sectigo wildcard certificate problem for Globalprotect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sectigo-wildcard-certificate-problem-for-globalprotect/m-p/317869#M81680</link>
      <description>&lt;P&gt;Thanks, I've managed to puzzle it together. The final revelation was to use the fqdn name as the external gateway, not the ip.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Case can be closed as resolved &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 21 Mar 2020 22:04:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sectigo-wildcard-certificate-problem-for-globalprotect/m-p/317869#M81680</guid>
      <dc:creator>KovBal</dc:creator>
      <dc:date>2020-03-21T22:04:03Z</dc:date>
    </item>
    <item>
      <title>Re: Sectigo wildcard certificate problem for Globalprotect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sectigo-wildcard-certificate-problem-for-globalprotect/m-p/330785#M83828</link>
      <description>&lt;P&gt;did you face any issue for global protect on 30 May 2020&amp;nbsp; due to sectigo cert ?&lt;/P&gt;</description>
      <pubDate>Mon, 01 Jun 2020 07:51:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sectigo-wildcard-certificate-problem-for-globalprotect/m-p/330785#M83828</guid>
      <dc:creator>Deepak_K</dc:creator>
      <dc:date>2020-06-01T07:51:21Z</dc:date>
    </item>
    <item>
      <title>Re: Sectigo wildcard certificate problem for Globalprotect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sectigo-wildcard-certificate-problem-for-globalprotect/m-p/330796#M83831</link>
      <description>&lt;P&gt;I have an issue with a sectigo secured site today that I would use relativly often without issue. PA says expired&amp;nbsp; certificate.&lt;/P&gt;</description>
      <pubDate>Mon, 01 Jun 2020 09:43:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sectigo-wildcard-certificate-problem-for-globalprotect/m-p/330796#M83831</guid>
      <dc:creator>RobinClayton</dc:creator>
      <dc:date>2020-06-01T09:43:05Z</dc:date>
    </item>
    <item>
      <title>Re: Sectigo wildcard certificate problem for Globalprotect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sectigo-wildcard-certificate-problem-for-globalprotect/m-p/330844#M83844</link>
      <description>&lt;P&gt;We're seeing the same on our end. Adding the root CA to device certs (with Trusted Root CA checked) hasn't resolved either.&lt;/P&gt;</description>
      <pubDate>Mon, 01 Jun 2020 16:51:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sectigo-wildcard-certificate-problem-for-globalprotect/m-p/330844#M83844</guid>
      <dc:creator>RyanHenckel</dc:creator>
      <dc:date>2020-06-01T16:51:40Z</dc:date>
    </item>
    <item>
      <title>Re: Sectigo wildcard certificate problem for Globalprotect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sectigo-wildcard-certificate-problem-for-globalprotect/m-p/331032#M83864</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/144027"&gt;@RyanHenckel&lt;/a&gt;&amp;nbsp; &amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/71756"&gt;@RobinClayton&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;please update if you got any solution. Currently for workaround we are using self-signed cert.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jun 2020 09:45:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sectigo-wildcard-certificate-problem-for-globalprotect/m-p/331032#M83864</guid>
      <dc:creator>Deepak_K</dc:creator>
      <dc:date>2020-06-02T09:45:16Z</dc:date>
    </item>
  </channel>
</rss>

