<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Adding multiple client certificate in Linux GP agent in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/adding-multiple-client-certificate-in-linux-gp-agent/m-p/336833#M84894</link>
    <description>&lt;P&gt;Hi Community,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a requirement to add multiple client certificate into Linux GP config. Usually, whe we put 'globalprotect import-certificate --location &amp;lt;cert_location&amp;gt;', the existing client cert will be overridden with the new one and it will be imported as &lt;SPAN&gt;pan_client_cert.pfx under&amp;nbsp;&lt;/SPAN&gt;/opt/paloaltonetworks/globalprotect .. Is there a way to keep both instead of override, so that i can use different client certificates while connecting to different portals. In windows, as it is taking from windows personal store, it will be discrete and we wont face this issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anybody have any idea to achieve this ?.. or can we combine different .p12 files to single .pfx ?,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am looking for some options other than adding both CAs in certificate profile&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 07 Jul 2020 10:54:09 GMT</pubDate>
    <dc:creator>Abdul_Razaq</dc:creator>
    <dc:date>2020-07-07T10:54:09Z</dc:date>
    <item>
      <title>Adding multiple client certificate in Linux GP agent</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/adding-multiple-client-certificate-in-linux-gp-agent/m-p/336833#M84894</link>
      <description>&lt;P&gt;Hi Community,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a requirement to add multiple client certificate into Linux GP config. Usually, whe we put 'globalprotect import-certificate --location &amp;lt;cert_location&amp;gt;', the existing client cert will be overridden with the new one and it will be imported as &lt;SPAN&gt;pan_client_cert.pfx under&amp;nbsp;&lt;/SPAN&gt;/opt/paloaltonetworks/globalprotect .. Is there a way to keep both instead of override, so that i can use different client certificates while connecting to different portals. In windows, as it is taking from windows personal store, it will be discrete and we wont face this issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anybody have any idea to achieve this ?.. or can we combine different .p12 files to single .pfx ?,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am looking for some options other than adding both CAs in certificate profile&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jul 2020 10:54:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/adding-multiple-client-certificate-in-linux-gp-agent/m-p/336833#M84894</guid>
      <dc:creator>Abdul_Razaq</dc:creator>
      <dc:date>2020-07-07T10:54:09Z</dc:date>
    </item>
    <item>
      <title>Re: Adding multiple client certificate in Linux GP agent</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/adding-multiple-client-certificate-in-linux-gp-agent/m-p/336852#M84898</link>
      <description>&lt;P&gt;Hello &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/101029"&gt;@Abdul_Razaq&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As far as I know there is a technical possibility to include multiple certificate chains and private keys in a PKCS #12 archive however it is not something widely implemented.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I see GlobalProtect App for Linux as an open-beta and assume what you require is beyond its abilities. Even basic verification of imported certificate is not performed:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;$ globalprotect import-certificate --location /dev/zero
Please input passcode:
Import certificate is successful.&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would explore alternative VPN Client - OpenConnect. It claims compatibility with GlobalProtect: &lt;A href="https://www.infradead.org/openconnect/globalprotect.html" target="_blank"&gt;https://www.infradead.org/openconnect/globalprotect.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Certificate for authentication is provided as command-line argument (&lt;A href="https://www.infradead.org/openconnect/manual.html" target="_blank"&gt;https://www.infradead.org/openconnect/manual.html&lt;/A&gt;&amp;nbsp;- -c,--certificate=CERT) so it can be easily selected per Portal/Gateway.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Not sure it will satisfy your other requirements, and it is a 3-rd party application introduction into environment, but might work.&lt;/P&gt;&lt;P&gt;Getting in touch with your SE to rise a Feature Request and wait like Sleeping Beauty for it to be kissed by a PM-Prince is also an option &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jul 2020 14:52:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/adding-multiple-client-certificate-in-linux-gp-agent/m-p/336852#M84898</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2020-07-07T14:52:29Z</dc:date>
    </item>
  </channel>
</rss>

