<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GlobalProtect with machine cert in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-with-machine-cert/m-p/322297#M82449</link>
    <description>&lt;P&gt;Yes I only suggest putting the user cert into the computer store to just make sure all of your GP stuff is set and working correctly.&lt;/P&gt;&lt;P&gt;if this proves successful then start looking at the difference between user and computer certs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm sure that&amp;nbsp;the default AD template for machine certs do not&amp;nbsp;populate the subject field and although&amp;nbsp;you can set your Palo certificate profile "Username" field to "None" I don't think GP will validate a certificate without the subject field populated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sat, 11 Apr 2020 07:28:24 GMT</pubDate>
    <dc:creator>Mick_Ball</dc:creator>
    <dc:date>2020-04-11T07:28:24Z</dc:date>
    <item>
      <title>GlobalProtect with machine cert</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-with-machine-cert/m-p/322150#M82426</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I'm having a challenge with GlobalProtect when trying to do ldap authentication with a machine cert (from internal MS pki).&amp;nbsp; I've tried both the computer and workstation authentication template, but neither worked.&amp;nbsp; GlobalProtect states certificate is missing.&amp;nbsp; I'm not doing pre-logon,&amp;nbsp; I have GP set to always on.&amp;nbsp; &amp;nbsp;In GP portal app setting, I have the client certificate store check set to machine. Is this not supported or am I missing something else?&amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As a test, i deployed a user certificate from the same MS pki,&amp;nbsp; set GP client store to be user and that works as expected&lt;/P&gt;</description>
      <pubDate>Fri, 10 Apr 2020 16:07:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-with-machine-cert/m-p/322150#M82426</guid>
      <dc:creator>ce1028</dc:creator>
      <dc:date>2020-04-10T16:07:45Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect with machine cert</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-with-machine-cert/m-p/322163#M82428</link>
      <description>&lt;P&gt;Certificates in the machine store does work, perhaps its the type of certificate you are using,. You say you have a user cert that works in the user store, try importing this to the machine personal store and see what happens.&lt;/P&gt;&lt;P&gt;also... &amp;nbsp; import the machine cert to the user store to see if it accepted. If not then probably wrong type of cert.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Apr 2020 16:45:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-with-machine-cert/m-p/322163#M82428</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2020-04-10T16:45:22Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect with machine cert</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-with-machine-cert/m-p/322186#M82435</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the reply.&amp;nbsp; I'm not sure its the type of cert that I'm using, as both templates that I have tried are computer certs.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can try moving the user cert to computer store, but not really going to help me determine what the problem is&lt;/P&gt;</description>
      <pubDate>Fri, 10 Apr 2020 17:50:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-with-machine-cert/m-p/322186#M82435</guid>
      <dc:creator>ce1028</dc:creator>
      <dc:date>2020-04-10T17:50:00Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect with machine cert</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-with-machine-cert/m-p/322196#M82437</link>
      <description>&lt;P&gt;There is a difference in windows world between machine certs and user certs.&lt;/P&gt;&lt;P&gt;We use user certs for GP and computer certs for network access control on our lan switches.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the computer cert cannot be used for GP auth.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;so if you move the user cert into the computer store this will prove my limited theory.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i think the app setting means look in both places rather than user or machine actual cert.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Apr 2020 18:10:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-with-machine-cert/m-p/322196#M82437</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2020-04-10T18:10:19Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect with machine cert</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-with-machine-cert/m-p/322253#M82441</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&amp;nbsp;ah thanks.&amp;nbsp; That would explain it, but also would be useless for me.&amp;nbsp; I'm trying to use computer certs that way regardless of user, the machine would have a cert.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Windows won't put a user cert in the computer store on its own, but I will definitely try your suggestion to see.&amp;nbsp; Thanks!&lt;/P&gt;</description>
      <pubDate>Fri, 10 Apr 2020 20:07:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-with-machine-cert/m-p/322253#M82441</guid>
      <dc:creator>ce1028</dc:creator>
      <dc:date>2020-04-10T20:07:40Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect with machine cert</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-with-machine-cert/m-p/322297#M82449</link>
      <description>&lt;P&gt;Yes I only suggest putting the user cert into the computer store to just make sure all of your GP stuff is set and working correctly.&lt;/P&gt;&lt;P&gt;if this proves successful then start looking at the difference between user and computer certs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm sure that&amp;nbsp;the default AD template for machine certs do not&amp;nbsp;populate the subject field and although&amp;nbsp;you can set your Palo certificate profile "Username" field to "None" I don't think GP will validate a certificate without the subject field populated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 11 Apr 2020 07:28:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-with-machine-cert/m-p/322297#M82449</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2020-04-11T07:28:24Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect with machine cert</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-with-machine-cert/m-p/322341#M82464</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Edited my post.&amp;nbsp; I was able to get it to work.&amp;nbsp; It was a configuration issue in my lab.&amp;nbsp; I set the computer template to include a subject and worked like a charm.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 12 Apr 2020 01:38:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-with-machine-cert/m-p/322341#M82464</guid>
      <dc:creator>ce1028</dc:creator>
      <dc:date>2020-04-12T01:38:25Z</dc:date>
    </item>
  </channel>
</rss>

