<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Mac computer GlobalProtect with Computer Cert How To in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/mac-computer-globalprotect-with-computer-cert-how-to/m-p/325601#M83033</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/86276"&gt;@ebrookman&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;Thanks for the instructions, I followed the instructions as below but GP client MAC complains "client certificate not found"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;Certificate auth works fine on a windows machine and certificate lookup is set to 'machine store" in GP portal. Any ideas for troubleshooting?&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 30 Apr 2020 23:50:24 GMT</pubDate>
    <dc:creator>Namalw</dc:creator>
    <dc:date>2020-04-30T23:50:24Z</dc:date>
    <item>
      <title>Mac computer GlobalProtect with Computer Cert How To</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/mac-computer-globalprotect-with-computer-cert-how-to/m-p/259446#M73572</link>
      <description>&lt;P&gt;Below are the instructions that I have cobbled together to install GlobalProtect on a Mac and not have the system ask for authentication of an administrator at each connection.&amp;nbsp; Full document with pictures is available on my GitHub.&lt;/P&gt;&lt;P&gt;&lt;A href="https://github.com/scriptingcaveman/PaloAlto-Documents" target="_blank"&gt;https://github.com/scriptingcaveman/PaloAlto-Documents&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The use case that led me to these directions is a non-administrator user on a Mac with Always on VPN with computer certificate.&amp;nbsp; The user will not have access to the administrator password for the authentication prompt.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Installation and Configuration of Global Protect on Mac OSx&lt;BR /&gt;Installation of GlobalProtect Client for Mac:&lt;BR /&gt;1. Log into the GlobalProtect Portal, download and run the installer for Mac OSx.&lt;BR /&gt;2. On the Introduction Screen, press “Continue”.&lt;BR /&gt;3. On the Destination Select screen choose the default by pressing “Continue”&lt;BR /&gt;4. On the Installation Type screen, ensure GlobalProtect Package Name is selected with&lt;BR /&gt;the checkbox. Press “Continue”.&lt;BR /&gt;5. Confirm the Installation by pressing “Install”.&lt;BR /&gt;6. Enter the computer Administrator’s name and password to begin installation and press&lt;BR /&gt;“Install Software”.&lt;BR /&gt;7. System Extension Blocked: Click on “Open Security Preferences” to allow the&lt;BR /&gt;GlobalProtect installation to proceed.&lt;BR /&gt;8. On the Security &amp;amp; Privacy screen, Press “Allow” to continue the installation.&lt;BR /&gt;9. Once the installation is complete, click “Close” on the Summary screen.&lt;BR /&gt;Certificate Configuration for GlobalProtect&lt;BR /&gt;1. Configure the Certificate Template&lt;BR /&gt;a. From the CA console, right-click Certificate Templates and select “Manage”&lt;BR /&gt;b. Right-click the “Workstation Authentication” template, then select “Duplicate&lt;BR /&gt;Template”.&lt;BR /&gt;c. On the “General” Tab, enter a template name that is recognizable.&lt;BR /&gt;d. On the “Request Handling” tab, make sure the “Allow private key to be&lt;BR /&gt;exported” is selected.&lt;BR /&gt;e. Click the “Subject Name” tab and select “Supply in the request”. Press “OK” in&lt;BR /&gt;the warning dialog to acknowledge the security risk.&lt;BR /&gt;f. Click the “Security” tab and remove the “Enroll” permission from the security&lt;BR /&gt;groups Domain Admins and Enterprise Admins.&lt;BR /&gt;g. Click “Add”. In the “Select Users, Computers, Service Accounts, or Groups”&lt;BR /&gt;dialog box, click “Object Types”, then “Computers”, then click “OK”. Specify the&lt;BR /&gt;name of a Windows computer that will request the certificate on behalf of the&lt;BR /&gt;Mac Computers (it can be the CA itself), click “Check Name” to verify, finally&lt;BR /&gt;click “OK”.&lt;BR /&gt;h. Select Enroll permission for this computer. **DO NOT CLEAR READ&lt;BR /&gt;PERMISSIONS**&lt;BR /&gt;i. Click “OK” and close the Certificate Templates Console.&lt;BR /&gt;2. Issue Certificate to Mac Workstation&lt;BR /&gt;a. From the computer that was configured in step 1 above, click “Start”, click&lt;BR /&gt;“Run”, type mmc.exe.&lt;BR /&gt;b. Click “File”, then “Add/Remove Snap-In”&lt;BR /&gt;c. In the dialog box that appears, select Certificates, and press “Add”&lt;BR /&gt;d. In the “Certificate Snap-In” dialog box, select Computer Account and press&lt;BR /&gt;“Next”&lt;BR /&gt;e. In the “Select Computer” dialog box, ensure Local Computer is selected and&lt;BR /&gt;press “Finish”.&lt;BR /&gt;f. Click “OK”&lt;BR /&gt;g. Expand “Certificates (Local Computer)”, then click “Personal”.&lt;BR /&gt;h. Right-click Certificates; click All Tasks; and click Request New Certificate.&lt;BR /&gt;i. On the Before You Begin screen, press “Next”&lt;BR /&gt;j. Press “Next” on the Certificate Enrollment Screen&lt;BR /&gt;k. Select the Certificate template created in the previous steps.&lt;BR /&gt;i. Click the hyperlink under the Certificate&lt;BR /&gt;l. On the Certificate Properties dialog box, enter the value in the Subject name&lt;BR /&gt;box. Use the FQDN (hostname.domain.com).&lt;BR /&gt;m. Press the “Add” button and press “OK”.&lt;BR /&gt;n. Press the “Enroll” button.&lt;BR /&gt;3. Export the needed certificates&lt;BR /&gt;a. Both the newly added certificate and root certificates need to be exported.&lt;BR /&gt;b. Right-click on the certificate, select “All Tasks”, then click “Export”.&lt;BR /&gt;c. On the Export Certificate Wizard Welcome page, press “Next”&lt;BR /&gt;d. Select “Yes, export the private key” and press “Next”.&lt;BR /&gt;e. On the Export File Format screen, make sure the file format is “PKCS #12 (.PFX)”&lt;BR /&gt;and press “Next”.&lt;BR /&gt;f. On the Security screen, give the file a secure password. This will be used when&lt;BR /&gt;importing the certificate into the Mac.&lt;BR /&gt;g. On the File to Export page, give the certificate a file name and press “Next”.&lt;BR /&gt;h. Finally, click “Finish” to close the wizard, and “OK” in any dialog boxes that&lt;BR /&gt;appear.&lt;BR /&gt;i. Copy the certificate(s) to the Mac.&lt;BR /&gt;4. Import the certificates into the System Keychain&lt;BR /&gt;a. As an administrator, open the KeyChain application on the Mac.&lt;BR /&gt;i. Press Command + Space bar and type Keychain&lt;BR /&gt;b. Browse to the System keychain.&lt;BR /&gt;c. Go to File -&amp;gt; Import Items&lt;BR /&gt;d. Select the .pfx file from the previous step and press “Open”&lt;BR /&gt;e. On the Keychain Access popup, allow access to modify the System keychain by&lt;BR /&gt;entering the administrator’s password.&lt;BR /&gt;f. The next pop up window will be the password for the certificate. Enter the&lt;BR /&gt;password used in the previous step here.&lt;BR /&gt;g. Once the certificate(s) are loaded ensure they are trusted by all users and&lt;BR /&gt;processes. Right-click on the certificate and select “Get Info”.&lt;BR /&gt;h. Expand “Trust” and change “When using this certificate:” to “Always Trust”.&lt;BR /&gt;5. Ensure GlobalProtect has access&lt;BR /&gt;a. Expand the computer certificate and right-click on the private key.&lt;BR /&gt;b. Click “Get Info”&lt;BR /&gt;c. Go to the “Access Control” tab.&lt;BR /&gt;d. Press the “+” key.&lt;BR /&gt;e. On the Pop up, press “Command + Shift + G” to enter the path directly.&lt;BR /&gt;f. Enter the path of /Applications/GlobalProtect.app/Contents/Resources and&lt;BR /&gt;press “Go”.&lt;BR /&gt;g. In the right pane, scroll to the end and find PanGPS in the list of resources.&lt;BR /&gt;h. Click “Save Changes” and enter the Administrator’s password in the popup.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 01 May 2019 19:48:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/mac-computer-globalprotect-with-computer-cert-how-to/m-p/259446#M73572</guid>
      <dc:creator>ebrookman</dc:creator>
      <dc:date>2019-05-01T19:48:31Z</dc:date>
    </item>
    <item>
      <title>Re: Mac computer GlobalProtect with Computer Cert How To</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/mac-computer-globalprotect-with-computer-cert-how-to/m-p/325601#M83033</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/86276"&gt;@ebrookman&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;Thanks for the instructions, I followed the instructions as below but GP client MAC complains "client certificate not found"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;Certificate auth works fine on a windows machine and certificate lookup is set to 'machine store" in GP portal. Any ideas for troubleshooting?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Apr 2020 23:50:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/mac-computer-globalprotect-with-computer-cert-how-to/m-p/325601#M83033</guid>
      <dc:creator>Namalw</dc:creator>
      <dc:date>2020-04-30T23:50:24Z</dc:date>
    </item>
  </channel>
</rss>

