<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GlobalProtect Certificate to Encrypt and Decrypt Cookies in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-certificate-to-encrypt-and-decrypt-cookies/m-p/336624#M84812</link>
    <description>&lt;P&gt;Reading over this post, good stuff. Should the Certificate for decrypting and encrypting cookies be something other than the Sever Cert used to for the portal/gateway?&amp;nbsp; Is there any security benefit to using a cert from our Private PKI infrastructure similar to the Machine Cert for pre-logon?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 05 Jul 2020 15:38:38 GMT</pubDate>
    <dc:creator>Gregory_Korten</dc:creator>
    <dc:date>2020-07-05T15:38:38Z</dc:date>
    <item>
      <title>GlobalProtect Certificate to Encrypt and Decrypt Cookies</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-certificate-to-encrypt-and-decrypt-cookies/m-p/158112#M51773</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;I'd like to find out what type of certificate you need if you are configuring Authentication Override for GlobalProtect Portal and Gateway. That is, for the option to specify a certificate to Encrypt/Decrypt Cookie (screenshot below), does this need a Machine Certificate, Web certificate???&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Secondly, what is the behaviour if you don't specify a certificate? Will Authentication Override still work albeit without encrypting/decrypting?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Your feedback is appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="override.PNG" style="width: 773px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/9401i966113A4AD4FC150/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="override.PNG" alt="override.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 May 2017 17:07:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-certificate-to-encrypt-and-decrypt-cookies/m-p/158112#M51773</guid>
      <dc:creator>Bocsa</dc:creator>
      <dc:date>2017-05-24T17:07:25Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Certificate to Encrypt and Decrypt Cookies</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-certificate-to-encrypt-and-decrypt-cookies/m-p/158120#M51774</link>
      <description>&lt;P&gt;Any certificate is fine, as long as you have the private key for it. It doesn't matter if it's a CA, end-entity, key signing, etc. It doesn't have to be trusted or installed on the client either. It's just so the&amp;nbsp;portal can encrypt the cookie, and then the gateway can decrypt it. The only real requirement here is that you have to use the same cert on both portal and gateway for cookie encrypt/decrypt, otherwise it won't work.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you don't encrypt it, that's fine. If you don't specify one, it's just not an encrypted cookie. It'll still work just fine, but without the extra security of encryption for the auth cookie.&lt;/P&gt;</description>
      <pubDate>Wed, 24 May 2017 17:27:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-certificate-to-encrypt-and-decrypt-cookies/m-p/158120#M51774</guid>
      <dc:creator>gwesson</dc:creator>
      <dc:date>2017-05-24T17:27:50Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Certificate to Encrypt and Decrypt Cookies</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-certificate-to-encrypt-and-decrypt-cookies/m-p/336624#M84812</link>
      <description>&lt;P&gt;Reading over this post, good stuff. Should the Certificate for decrypting and encrypting cookies be something other than the Sever Cert used to for the portal/gateway?&amp;nbsp; Is there any security benefit to using a cert from our Private PKI infrastructure similar to the Machine Cert for pre-logon?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 05 Jul 2020 15:38:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-certificate-to-encrypt-and-decrypt-cookies/m-p/336624#M84812</guid>
      <dc:creator>Gregory_Korten</dc:creator>
      <dc:date>2020-07-05T15:38:38Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Certificate to Encrypt and Decrypt Cookies</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-certificate-to-encrypt-and-decrypt-cookies/m-p/336629#M84815</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/42546"&gt;@Gregory_Korten&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As mentioned by earlier post this cert can be any certificate.&lt;/P&gt;
&lt;P&gt;As per my knowledge there is no security benefit using the cert from PKI.&lt;/P&gt;</description>
      <pubDate>Sun, 05 Jul 2020 21:44:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-certificate-to-encrypt-and-decrypt-cookies/m-p/336629#M84815</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2020-07-05T21:44:33Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Certificate to Encrypt and Decrypt Cookies</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-certificate-to-encrypt-and-decrypt-cookies/m-p/461530#M102178</link>
      <description>&lt;P&gt;Do things break when the certificate expires or will it continue to encrypt/decrypt just fine?&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jan 2022 18:27:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-certificate-to-encrypt-and-decrypt-cookies/m-p/461530#M102178</guid>
      <dc:creator>MarkSanchezSSnC</dc:creator>
      <dc:date>2022-01-27T18:27:58Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Certificate to Encrypt and Decrypt Cookies</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-certificate-to-encrypt-and-decrypt-cookies/m-p/462941#M102312</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/157712"&gt;@MarkSanchezSSnC&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As per my understanding if certs are expired then it will cause the issue.&lt;/P&gt;
&lt;P&gt;Lets see if someone else has more info on this.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Thu, 03 Feb 2022 02:10:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-certificate-to-encrypt-and-decrypt-cookies/m-p/462941#M102312</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2022-02-03T02:10:22Z</dc:date>
    </item>
  </channel>
</rss>

