<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Logon Method for mixed users using certificates in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/logon-method-for-mixed-users-using-certificates/m-p/352356#M87173</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp; thanks for your reply.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The goal is to use both AD creds plus certificate check&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Corp users have machine certificate&lt;/P&gt;&lt;P&gt;Non corp users have user certificate&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1) if I use user logon&amp;nbsp; for a machine certificate ,how the gp willl check the certificate?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I understand that prelogon is preferred way .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I use prelogon then I need three rules in total on agent configuration:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1) prelogon to be selected under user/ user group&lt;/P&gt;&lt;P&gt;Logon method prelogon and certificate store look machine only&lt;/P&gt;&lt;P&gt;2) specific users under user/ user group .&lt;/P&gt;&lt;P&gt;Logon method prelogon and certificate store look machine only&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;3) specific users under user/ user group and logon methods user logon and certificate store look user only.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Gatway and portal use same interface .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sat, 26 Sep 2020 06:06:51 GMT</pubDate>
    <dc:creator>FWPalolearner</dc:creator>
    <dc:date>2020-09-26T06:06:51Z</dc:date>
    <item>
      <title>Logon Method for mixed users using certificates</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/logon-method-for-mixed-users-using-certificates/m-p/352057#M87131</link>
      <description>&lt;P&gt;Hello ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a requirement ,&amp;nbsp; Currently both Internal and external users ( both are AD users) connect to GP via their AD user name and Password&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Requirement is enroll Machine certificate to Internal Users and a Common Certificate issued by Palo Alto Generate Root CA to all External users&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Internal Users are having Machine Certificate issued by PKI on their Windows 10&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;External Users have a Common User certificate in their User certificate store. Certificate Profile is OK and has Root CA certificate from PKI and PA Root CA&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So my queries are :&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1) Can I still use Logon Method as User Logon ( Always on )&amp;nbsp; as a common method for both types of users ? the requirement is that the certificate check should not kick in until user logs in ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2)&amp;nbsp; Client Certificate Store Look up is User and Machine :: So that it checks for both Spaces and find a certificate in one of the store&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is this OK ?&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the config selection criteria ,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have selected the User Groups ( mix of both internal and external) . Do i need to change it Pre-logon ?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Sep 2020 07:49:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/logon-method-for-mixed-users-using-certificates/m-p/352057#M87131</guid>
      <dc:creator>FWPalolearner</dc:creator>
      <dc:date>2020-09-25T07:49:30Z</dc:date>
    </item>
    <item>
      <title>Re: Logon Method for mixed users using certificates</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/logon-method-for-mixed-users-using-certificates/m-p/352341#M87171</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/133520"&gt;@FWPalolearner&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;1) Can I still use Logon Method as User Logon ( Always on )&amp;nbsp; as a common method for both types of users ? the requirement is that the certificate check should not kick in until user logs in ?&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF0000"&gt;Yes, but if you are going through and deploying machine certificates to machines it makes more sense in the majority of situations to go with pre-logon. Obviously if that doesn't meet your requirements you can stick with User Logon but I really recommend looking into pre-logon since you've already done all of the work for these internal clients.&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2)&amp;nbsp; Client Certificate Store Look up is User and Machine :: So that it checks for both Spaces and find a certificate in one of the store&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF0000"&gt;Correct. The thing to keep in mind here though is that anything in the user certificate store that actually matches your certificate profile is going to take priority over the machine certificate. &lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;SPAN&gt;I have selected the User Groups ( mix of both internal and external) . Do i need to change it Pre-logon ?&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF0000"&gt;&lt;SPAN&gt;Only if you are actually going to deploy pre-logon mode. The thing to make sure here in testing prior to actual deployment is that the user is going to be identified from the certificate as you actually expect it to be for the users. It's not abundantly clear if you're talking about just doing certificate authentication for the internal users or if you plan on doing a certificate AND credential deployment instead.&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;FONT color="#000000"&gt;Talking about internal and external just has me curious on what you actually mean by this. Generally you would want to see an internal&amp;nbsp;&lt;STRONG&gt;and&amp;nbsp;&lt;/STRONG&gt;an external gateway configured if you are actually utilizing GlobalProtect for internal hosts. So you might only have one portal address, but you would have two separate&amp;nbsp;gateway configurations. It kind of sounds like you are lumping your internal and external GlobalProtect clients on one gateway, which would be somewhat odd from a deployment. Is that just odd word choice, or what was the reason behind the sole gateway deployment?&amp;nbsp;&lt;/FONT&gt;&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 26 Sep 2020 05:21:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/logon-method-for-mixed-users-using-certificates/m-p/352341#M87171</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-09-26T05:21:42Z</dc:date>
    </item>
    <item>
      <title>Re: Logon Method for mixed users using certificates</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/logon-method-for-mixed-users-using-certificates/m-p/352356#M87173</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp; thanks for your reply.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The goal is to use both AD creds plus certificate check&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Corp users have machine certificate&lt;/P&gt;&lt;P&gt;Non corp users have user certificate&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1) if I use user logon&amp;nbsp; for a machine certificate ,how the gp willl check the certificate?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I understand that prelogon is preferred way .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I use prelogon then I need three rules in total on agent configuration:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1) prelogon to be selected under user/ user group&lt;/P&gt;&lt;P&gt;Logon method prelogon and certificate store look machine only&lt;/P&gt;&lt;P&gt;2) specific users under user/ user group .&lt;/P&gt;&lt;P&gt;Logon method prelogon and certificate store look machine only&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;3) specific users under user/ user group and logon methods user logon and certificate store look user only.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Gatway and portal use same interface .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 26 Sep 2020 06:06:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/logon-method-for-mixed-users-using-certificates/m-p/352356#M87173</guid>
      <dc:creator>FWPalolearner</dc:creator>
      <dc:date>2020-09-26T06:06:51Z</dc:date>
    </item>
  </channel>
</rss>

