<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Choosing user certificate when you have multiple such as multiple company VPNs in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/choosing-user-certificate-when-you-have-multiple-such-as/m-p/367203#M88806</link>
    <description>&lt;P&gt;I might be getting the prompt on every connection as it does not have a valid gateway because i only need to test the cert against a portal.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i will add a gateway later today and see if it goes away.... &amp;nbsp; I only say this as picked this up from PAN docs..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;When only one client certificate meets the requirements above, the app automatically uses that client certificate for authentication. However, when multiple client certificates meet the these requirements, GlobalProtect prompts the user to select the client certificate from a list of valid client certificates on the endpoint. While GlobalProtect requires users to select the client certificate only when they first connect, users might not know which certificate to select. In this case, we recommend you to narrow the list of available client certificates by certificate purpose (as indicated by the OID) and certificate store.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 04 Dec 2020 03:37:06 GMT</pubDate>
    <dc:creator>Mick_Ball</dc:creator>
    <dc:date>2020-12-04T03:37:06Z</dc:date>
    <item>
      <title>Choosing user certificate when you have multiple such as multiple company VPNs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/choosing-user-certificate-when-you-have-multiple-such-as/m-p/366848#M88764</link>
      <description>&lt;P&gt;If a user has multiple user certificates, how can I ensure that the firewall chooses the correct one to use?&lt;/P&gt;&lt;P&gt;For example, a user might have a VPN to two different companies that both have PA firewalls.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'd strongly prefer not having to have a separate windows user account depending on which useraccount and portal I want to connect to.&amp;nbsp; Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 02 Dec 2020 20:20:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/choosing-user-certificate-when-you-have-multiple-such-as/m-p/366848#M88764</guid>
      <dc:creator>fhewiufhwefhwe</dc:creator>
      <dc:date>2020-12-02T20:20:15Z</dc:date>
    </item>
    <item>
      <title>Re: Choosing user certificate when you have multiple such as multiple company VPNs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/choosing-user-certificate-when-you-have-multiple-such-as/m-p/366879#M88766</link>
      <description>&lt;P&gt;When there's multiple user certificates, the user will get a pop-up requesting which one to use&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Dec 2020 21:40:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/choosing-user-certificate-when-you-have-multiple-such-as/m-p/366879#M88766</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2020-12-02T21:40:34Z</dc:date>
    </item>
    <item>
      <title>Re: Choosing user certificate when you have multiple such as multiple company VPNs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/choosing-user-certificate-when-you-have-multiple-such-as/m-p/366882#M88768</link>
      <description>&lt;P&gt;No such pop-up appearing requesting which one to use.&amp;nbsp; I've had to delete a user certificate due to the lack of pop-up.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Dec 2020 21:52:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/choosing-user-certificate-when-you-have-multiple-such-as/m-p/366882#M88768</guid>
      <dc:creator>fhewiufhwefhwe</dc:creator>
      <dc:date>2020-12-02T21:52:14Z</dc:date>
    </item>
    <item>
      <title>Re: Choosing user certificate when you have multiple such as multiple company VPNs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/choosing-user-certificate-when-you-have-multiple-such-as/m-p/366927#M88774</link>
      <description>&lt;P&gt;If the certificates are issued by different authorities, there *shouldn't* be a problem. Only the cert issued by the CA you define in the certificate profile should be used. The prompt should only happen if: there are multiple certs that are issued from the same authority, with client auth enabled and in the same cert store.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Dec 2020 00:00:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/choosing-user-certificate-when-you-have-multiple-such-as/m-p/366927#M88774</guid>
      <dc:creator>rmfalconer</dc:creator>
      <dc:date>2020-12-03T00:00:49Z</dc:date>
    </item>
    <item>
      <title>Re: Choosing user certificate when you have multiple such as multiple company VPNs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/choosing-user-certificate-when-you-have-multiple-such-as/m-p/367107#M88790</link>
      <description>&lt;P&gt;It's the same CA and the prompt is not occurring.&amp;nbsp; For instance, I am testing user certificate of a third party complaining of issues connecting to VPN.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Dec 2020 16:24:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/choosing-user-certificate-when-you-have-multiple-such-as/m-p/367107#M88790</guid>
      <dc:creator>fhewiufhwefhwe</dc:creator>
      <dc:date>2020-12-03T16:24:21Z</dc:date>
    </item>
    <item>
      <title>Re: Choosing user certificate when you have multiple such as multiple company VPNs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/choosing-user-certificate-when-you-have-multiple-such-as/m-p/367108#M88791</link>
      <description>&lt;P&gt;So it is _not_ the same CA? Which version of GP are you/they on? May need to upgrade, or reach out to aupport&lt;/P&gt;</description>
      <pubDate>Thu, 03 Dec 2020 16:36:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/choosing-user-certificate-when-you-have-multiple-such-as/m-p/367108#M88791</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2020-12-03T16:36:59Z</dc:date>
    </item>
    <item>
      <title>Re: Choosing user certificate when you have multiple such as multiple company VPNs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/choosing-user-certificate-when-you-have-multiple-such-as/m-p/367109#M88792</link>
      <description>&lt;P&gt;5.2.3 GP originally.&amp;nbsp; I upgraded to 5.2.4 GP and still have the same issue.&amp;nbsp; Their is no prompt to choose the user certificate / username with the GP client.&amp;nbsp; If I connect to the firewall web gui, I do get a prompt about which user certificate to use.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Dec 2020 17:03:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/choosing-user-certificate-when-you-have-multiple-such-as/m-p/367109#M88792</guid>
      <dc:creator>fhewiufhwefhwe</dc:creator>
      <dc:date>2020-12-03T17:03:32Z</dc:date>
    </item>
    <item>
      <title>Re: Choosing user certificate when you have multiple such as multiple company VPNs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/choosing-user-certificate-when-you-have-multiple-such-as/m-p/367146#M88797</link>
      <description>&lt;P&gt;I have 2 different certs from the same CA and i do get a prompt on v5.24&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="aaprompt.png" style="width: 652px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/28952i3C0BED3E2E10523B/image-size/large?v=v2&amp;amp;px=999" role="button" title="aaprompt.png" alt="aaprompt.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Dec 2020 18:13:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/choosing-user-certificate-when-you-have-multiple-such-as/m-p/367146#M88797</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2020-12-03T18:13:58Z</dc:date>
    </item>
    <item>
      <title>Re: Choosing user certificate when you have multiple such as multiple company VPNs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/choosing-user-certificate-when-you-have-multiple-such-as/m-p/367147#M88798</link>
      <description>&lt;P&gt;If I completely uninstall 5.2.4 then install 5.2.3, I get the prompt.&amp;nbsp; Does this only appear the first time you connect?&amp;nbsp; Is there some setting that controls whether you are prompted once or every time?&lt;/P&gt;</description>
      <pubDate>Thu, 03 Dec 2020 18:28:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/choosing-user-certificate-when-you-have-multiple-such-as/m-p/367147#M88798</guid>
      <dc:creator>fhewiufhwefhwe</dc:creator>
      <dc:date>2020-12-03T18:28:45Z</dc:date>
    </item>
    <item>
      <title>Re: Choosing user certificate when you have multiple such as multiple company VPNs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/choosing-user-certificate-when-you-have-multiple-such-as/m-p/367202#M88805</link>
      <description>&lt;P&gt;It does prompt me on every connection, however.... &amp;nbsp; i have a funny feeling that when i installed a second user cert from the same CA it just ignored it... as if it expected to use the one i had already been using prior to the second addition... and as far as i can remember i just connected to a different test portal for the first time to get the prompt. &amp;nbsp; I have never seen a setting to tweak this but GP client may be trying to do something clever in the background hence a re install resolution for yourself. I have seen a few odd things when chopping and changing user certs but normally rectified by pangps service restart.&lt;/P&gt;</description>
      <pubDate>Fri, 04 Dec 2020 03:17:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/choosing-user-certificate-when-you-have-multiple-such-as/m-p/367202#M88805</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2020-12-04T03:17:09Z</dc:date>
    </item>
    <item>
      <title>Re: Choosing user certificate when you have multiple such as multiple company VPNs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/choosing-user-certificate-when-you-have-multiple-such-as/m-p/367203#M88806</link>
      <description>&lt;P&gt;I might be getting the prompt on every connection as it does not have a valid gateway because i only need to test the cert against a portal.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i will add a gateway later today and see if it goes away.... &amp;nbsp; I only say this as picked this up from PAN docs..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;When only one client certificate meets the requirements above, the app automatically uses that client certificate for authentication. However, when multiple client certificates meet the these requirements, GlobalProtect prompts the user to select the client certificate from a list of valid client certificates on the endpoint. While GlobalProtect requires users to select the client certificate only when they first connect, users might not know which certificate to select. In this case, we recommend you to narrow the list of available client certificates by certificate purpose (as indicated by the OID) and certificate store.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Dec 2020 03:37:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/choosing-user-certificate-when-you-have-multiple-such-as/m-p/367203#M88806</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2020-12-04T03:37:06Z</dc:date>
    </item>
    <item>
      <title>Re: Choosing user certificate when you have multiple such as multiple company VPNs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/choosing-user-certificate-when-you-have-multiple-such-as/m-p/367567#M88847</link>
      <description>&lt;P&gt;Thanks.&amp;nbsp; My temporary workaround is the uninstall and reinstall of GlobalProtect VPN, or manually adding and deleting user certificates.&amp;nbsp; I tried simply changing the portal, but didn't get prompted to choose between the user certificates&lt;/P&gt;</description>
      <pubDate>Mon, 07 Dec 2020 00:53:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/choosing-user-certificate-when-you-have-multiple-such-as/m-p/367567#M88847</guid>
      <dc:creator>fhewiufhwefhwe</dc:creator>
      <dc:date>2020-12-07T00:53:03Z</dc:date>
    </item>
  </channel>
</rss>

