<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Unable to Authenticate to GP using SMAL in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-authenticate-to-gp-using-smal/m-p/339535#M85256</link>
    <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/136293"&gt;@RamiAkermi&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have our GP where Portal and Gateway are configured for SAML authentication.&lt;/P&gt;
&lt;P&gt;Make sure authentication profile is same for both portal and GW.&lt;/P&gt;
&lt;P&gt;Did you check logs on the Duo side?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 20 Jul 2020 03:19:06 GMT</pubDate>
    <dc:creator>MP18</dc:creator>
    <dc:date>2020-07-20T03:19:06Z</dc:date>
    <item>
      <title>Unable to Authenticate to GP using SMAL</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-authenticate-to-gp-using-smal/m-p/301332#M78661</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On PA 8.1.19 we have configured GP portal and Gateway for SAML authentic in Azure.&lt;/P&gt;&lt;P&gt;We have imported the SAML Metadata XML into SAML identity provider in PA.&lt;/P&gt;&lt;P&gt;&lt;FONT color="red"&gt;&lt;STRONG&gt;Authentication Failed&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;DIV class="dError1"&gt;Please contact the administrator for further assistance&lt;/DIV&gt;&lt;P&gt;&lt;SPAN&gt;Error code: &lt;/SPAN&gt;-1&lt;/P&gt;&lt;P&gt;When I go to GP. url. I get authentic on my phone and I approve it then I get this error on browser.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PA. system log shows sam authentic error.&lt;/P&gt;&lt;P&gt;Server team says that SAML is working fine as it authenticates the user.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas how can we proceed on this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 29 Nov 2019 06:31:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-authenticate-to-gp-using-smal/m-p/301332#M78661</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-11-29T06:31:29Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to Authenticate to GP using SMAL</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-authenticate-to-gp-using-smal/m-p/301384#M78664</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There are various browser plugins (for the PC based browsers, most probably not for the smartphone, so you need to test this from a PC). This plugin helped me a lot while trouble shooting some SAML related authentication topics.&lt;/P&gt;</description>
      <pubDate>Fri, 29 Nov 2019 12:24:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-authenticate-to-gp-using-smal/m-p/301384#M78664</guid>
      <dc:creator>JoergSchuetter</dc:creator>
      <dc:date>2019-11-29T12:24:01Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to Authenticate to GP using SMAL</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-authenticate-to-gp-using-smal/m-p/301404#M78666</link>
      <description>&lt;P&gt;I am testing from the PC only.&lt;/P&gt;&lt;P&gt;Will use SAML ext for chrome now&lt;/P&gt;</description>
      <pubDate>Fri, 29 Nov 2019 15:38:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-authenticate-to-gp-using-smal/m-p/301404#M78666</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-11-29T15:38:02Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to Authenticate to GP using SMAL</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-authenticate-to-gp-using-smal/m-p/301408#M78668</link>
      <description>&lt;P&gt;PA system log shows this error&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and ( description contains 'Failure while validating the signature of SAML message received from the IdP "&lt;A href="https://sts.windows.net/7262967a-05fa-4d59-8afd-25b734eaf196/" target="_blank"&gt;https://sts.windows.net/7262967a-05fa-4d59-8afd-25b734eaf196/&lt;/A&gt;", because the certificate in the SAML Message doesn\'t match the IDP certificate configured on the IdP Server Profile "Azure_GP". (SP: "Global Protect"), (Client IP: 207.228.78.105), (vsys: vsys1), (authd id: 6723816240130860777), (user: xsy@com)' )&lt;/P&gt;</description>
      <pubDate>Fri, 29 Nov 2019 15:43:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-authenticate-to-gp-using-smal/m-p/301408#M78668</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-11-29T15:43:21Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to Authenticate to GP using SMAL</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-authenticate-to-gp-using-smal/m-p/302492#M78824</link>
      <description>&lt;P&gt;Issue was fixed by exporting the right cert from Azure.&lt;/P&gt;&lt;P&gt;XML metadata file is azure was using inactive cert.&lt;/P&gt;</description>
      <pubDate>Sat, 07 Dec 2019 17:20:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-authenticate-to-gp-using-smal/m-p/302492#M78824</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-12-07T17:20:52Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to Authenticate to GP using SMAL</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-authenticate-to-gp-using-smal/m-p/308885#M80104</link>
      <description>&lt;P&gt;I am having a similar issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;global protect with azure SAML&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;authentication works fine with the GP Portal, but when connecting to the GP gateway, authentication fails with the same error you received. The Cert from Azure is an active and valid cert.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My portal and gateway have separate hostnames/IPs&lt;/P&gt;</description>
      <pubDate>Fri, 31 Jan 2020 13:57:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-authenticate-to-gp-using-smal/m-p/308885#M80104</guid>
      <dc:creator>kevin.thomas</dc:creator>
      <dc:date>2020-01-31T13:57:29Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to Authenticate to GP using SMAL</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-authenticate-to-gp-using-smal/m-p/309598#M80220</link>
      <description>&lt;P&gt;check the authd logs in the PA.&lt;/P&gt;&lt;P&gt;Also check the logs in Azure.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Authd logs in PA helps to find the cause of the error message.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Feb 2020 16:38:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-authenticate-to-gp-using-smal/m-p/309598#M80220</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2020-02-05T16:38:48Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to Authenticate to GP using SMAL</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-authenticate-to-gp-using-smal/m-p/338607#M85123</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/75039"&gt;@MP18&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;I was able to make palo alto admin UI authentication work with SAML.&lt;BR /&gt;Now, I want to do the same with GlobalProtect.&lt;BR /&gt;A brief history:&lt;BR /&gt;I configured a SAML authentication profile for globalprotect and it's working just fine with our globalprotect VPN portal (we use Auth0 as an IDP with Duo MFA).&lt;BR /&gt;When trying to do the same with the globalprotect gateway (I'm 100% sure that the authentication profile and the auth0 client settings are correct), I keep getting this error "unknown private header auth-failed-invalid-user-input" and the globalprotect client is showing that it's not able to contact the gateway.&lt;BR /&gt;A workaround was using SAML authentication with vpn portal and certificate profile with the gateway.&lt;BR /&gt;Now, The problem is that I'm unable to identify VPN source users on Palo alto since I'm using the Common Name of a client SSL cert to identify users and not LDAP or adfs ...&lt;BR /&gt;Can someone help me make the saml authentication work with GP VPN gateway?&lt;BR /&gt;Thanks.&lt;BR /&gt;Rami&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jul 2020 16:22:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-authenticate-to-gp-using-smal/m-p/338607#M85123</guid>
      <dc:creator>RamiAkermi</dc:creator>
      <dc:date>2020-07-15T16:22:52Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to Authenticate to GP using SMAL</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-authenticate-to-gp-using-smal/m-p/339535#M85256</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/136293"&gt;@RamiAkermi&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have our GP where Portal and Gateway are configured for SAML authentication.&lt;/P&gt;
&lt;P&gt;Make sure authentication profile is same for both portal and GW.&lt;/P&gt;
&lt;P&gt;Did you check logs on the Duo side?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jul 2020 03:19:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-authenticate-to-gp-using-smal/m-p/339535#M85256</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2020-07-20T03:19:06Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to Authenticate to GP using SMAL</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-authenticate-to-gp-using-smal/m-p/339555#M85266</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/75039"&gt;@MP18&lt;/a&gt;&amp;nbsp;,&lt;BR /&gt;&lt;BR /&gt;I'm using the same SAML auth profile for both portal and gateway.&lt;BR /&gt;I'm suspecting that the callback url for the gateway is wrong.&lt;BR /&gt;Since the portal and the gateway are in the same domain, I'm using wildcard FQDN (https://*.X.X.X.X&lt;A href="https://ztportal.net.vpsvc.com/SAML20/SP/ACS" target="_blank"&gt;/SAML20/SP/ACS&lt;/A&gt;&amp;nbsp; ).&lt;BR /&gt;Could it be that the gateway uses a different callback url ?&lt;BR /&gt;P.S: they are both using port 443.&lt;BR /&gt;&lt;BR /&gt;Thanks.&lt;BR /&gt;Rami&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jul 2020 08:49:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-authenticate-to-gp-using-smal/m-p/339555#M85266</guid>
      <dc:creator>RamiAkermi</dc:creator>
      <dc:date>2020-07-20T08:49:58Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to Authenticate to GP using SMAL</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-authenticate-to-gp-using-smal/m-p/339644#M85282</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/136293"&gt;@RamiAkermi&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;They both use same redirect url.&lt;/P&gt;
&lt;P&gt;Other thing you can try is to reimport the Certificate again.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jul 2020 16:45:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-authenticate-to-gp-using-smal/m-p/339644#M85282</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2020-07-20T16:45:15Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to Authenticate to GP using SMAL</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-authenticate-to-gp-using-smal/m-p/340077#M85372</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/96909"&gt;@kevin.thomas&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Did you get this to work?&lt;BR /&gt;I'm having the same issue.&lt;BR /&gt;I'm able to connect to the GP portal but not to GP VPN gateway.&lt;BR /&gt;Something else, what's the callback url (ACS url ) that you are using for your vpn gateway?&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jul 2020 16:19:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-authenticate-to-gp-using-smal/m-p/340077#M85372</guid>
      <dc:creator>RamiAkermi</dc:creator>
      <dc:date>2020-07-22T16:19:35Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to Authenticate to GP using SAML</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-authenticate-to-gp-using-smal/m-p/390896#M90737</link>
      <description>&lt;P&gt;I am having the same issue. We want to upgrade version 9.1.8 and have a working saml implementation for Globalprotect under 9.0.x . Since now signing and validate "identity provider certificate" is required, signing messages seem obligatory. When I enable the profile with ipc enabled in gateway it works. When I enable it in portal, it doesnt work under version 9.0.x. When I only sign after upgrade under panos 9.1.8, I notice that the translation from UPN (user principal name / emailadresses) to Ad user doesnt work anymore, causing all traffic blocked. I suppose it has something to do with the new saml implementation starting panos 9.1.3 . Did something change on UPN translation on panos 9.1.X ?&lt;/P&gt;&lt;P&gt;The error i get when trying to enable identity provider certificate is :&lt;/P&gt;&lt;P&gt;Failed to validate the signature in IdP certificate "crt.AzureaD-SAML.shared" of entity Id "&lt;A href="https://sts.windows.net/xxx" target="_blank"&gt;https://sts.windows.net/xxx&lt;/A&gt;"&lt;/P&gt;</description>
      <pubDate>Fri, 12 Mar 2021 15:13:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-authenticate-to-gp-using-smal/m-p/390896#M90737</guid>
      <dc:creator>johan.boeckx</dc:creator>
      <dc:date>2021-03-12T15:13:37Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to Authenticate to GP using SMAL</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-authenticate-to-gp-using-smal/m-p/408152#M92310</link>
      <description>&lt;P&gt;had same issue on my firewall. resolved after re configuring ntp (time settings ). this was because of time difference between SAML authentication URLs and your firewall. default maximum deference is 60s&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 May 2021 16:18:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-authenticate-to-gp-using-smal/m-p/408152#M92310</guid>
      <dc:creator>sandeepchs</dc:creator>
      <dc:date>2021-05-20T16:18:02Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to Authenticate to GP using SMAL</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-authenticate-to-gp-using-smal/m-p/589349#M117460</link>
      <description>&lt;P&gt;I saw this alert on our corporate firewall ; 'Failed to convert SAML message payload into xml tree', as a high level,&lt;/P&gt;
&lt;P&gt;Is there anyone to explain what this means and what this situation effects to our SAML vpn configurations?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please inform to me,&lt;/P&gt;
&lt;P&gt;Have a good day.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jun 2024 05:24:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-authenticate-to-gp-using-smal/m-p/589349#M117460</guid>
      <dc:creator>OykuMiser</dc:creator>
      <dc:date>2024-06-12T05:24:09Z</dc:date>
    </item>
  </channel>
</rss>

