<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Globalprotect users cert renewal process? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-users-cert-renewal-process/m-p/387487#M90382</link>
    <description>&lt;P&gt;Sounds like a plan. Good idea... &amp;nbsp; i dont think you will have many major issues here...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Good Luck.....&lt;/P&gt;</description>
    <pubDate>Tue, 23 Feb 2021 21:25:11 GMT</pubDate>
    <dc:creator>Mick_Ball</dc:creator>
    <dc:date>2021-02-23T21:25:11Z</dc:date>
    <item>
      <title>Globalprotect users cert renewal process?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-users-cert-renewal-process/m-p/387415#M90369</link>
      <description>&lt;P&gt;I have 20 GP users that has certificate check as first factor of authentication. The certs are set to expire in a month. If I renew the cert and export it to them on a USB stikc, will that break the connection until the certs are installed? What is the best way to refresh the certs on user machines?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Feb 2021 16:23:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-users-cert-renewal-process/m-p/387415#M90369</guid>
      <dc:creator>SThatipelly</dc:creator>
      <dc:date>2021-02-23T16:23:39Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect users cert renewal process?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-users-cert-renewal-process/m-p/387453#M90370</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/70284"&gt;@SThatipelly&lt;/a&gt;&amp;nbsp;.&lt;/P&gt;&lt;P&gt;a couple of questions...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;are these individual users certs or 1 generic cert that covers all users.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;is the root CA about to expire or just the user certs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;in general... &amp;nbsp; I would only use some form of PKI to distribute certificates but you may not have that option. &amp;nbsp; You can send new certs to users and tell them to install when they get a cert error or you can get them to install now but they will be asked to choose which one to use prior to expiry.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Feb 2021 19:43:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-users-cert-renewal-process/m-p/387453#M90370</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2021-02-23T19:43:15Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect users cert renewal process?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-users-cert-renewal-process/m-p/387458#M90371</link>
      <description>&lt;P&gt;&lt;EM&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&amp;nbsp; &lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;are these individual users certs or 1 generic cert that covers all users.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Individual users&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;is the root CA about to expire or just the user certs.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Just the end user certs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Our plan is to renew certificates on firewall, copy them to USB stick and ship it to end users. So, we anticipate at least a week from the time the cert is renewed on firewall to installation on end user device.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My question is : will Globalprotect gateway/portal accept the connection from user (with old cert) when a new certificate exists on firewall(renewed cert is not yet installed on user machine)?&lt;/P&gt;</description>
      <pubDate>Tue, 23 Feb 2021 19:47:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-users-cert-renewal-process/m-p/387458#M90371</guid>
      <dc:creator>SThatipelly</dc:creator>
      <dc:date>2021-02-23T19:47:10Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect users cert renewal process?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-users-cert-renewal-process/m-p/387471#M90372</link>
      <description>&lt;P&gt;I would say yes, as the auth process would not care about user certs sitting on the firewall as long as the ones on the device &amp;nbsp;matched the root cert used to generate them.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;you will still of course be asked which certificate to use if you have 2 installed from the same root CA.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;why not generate a new self signed CA and use this to generate user certs, export certs to users and get them to import. &amp;nbsp; This will not cause the user to choose certs on GP connection as only one is valid to the original root cert in the profile. &amp;nbsp;then just before expiry, edit the certificate profile and remove original cert and add new. This will then force GP to auto select the new cert as it will be the only one that is valid at that time.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Feb 2021 20:45:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-users-cert-renewal-process/m-p/387471#M90372</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2021-02-23T20:45:23Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect users cert renewal process?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-users-cert-renewal-process/m-p/387472#M90373</link>
      <description>&lt;P&gt;Hmmmm... that may sound a bit confusing.....&lt;/P&gt;</description>
      <pubDate>Tue, 23 Feb 2021 20:48:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-users-cert-renewal-process/m-p/387472#M90373</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2021-02-23T20:48:30Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect users cert renewal process?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-users-cert-renewal-process/m-p/387475#M90376</link>
      <description>&lt;P&gt;Hmmmmm2. For 20 users, why not remote when user connected, remove old , add new, Bingo....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;this will also rule out the possibility of the user installing the cert elsewhere....&lt;/P&gt;</description>
      <pubDate>Tue, 23 Feb 2021 21:02:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-users-cert-renewal-process/m-p/387475#M90376</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2021-02-23T21:02:51Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect users cert renewal process?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-users-cert-renewal-process/m-p/387485#M90380</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&amp;nbsp;those users are isolated from business and I have no access into their machines. I think I will renew one user cert first, see how GP would behave and go about other users.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Feb 2021 21:16:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-users-cert-renewal-process/m-p/387485#M90380</guid>
      <dc:creator>SThatipelly</dc:creator>
      <dc:date>2021-02-23T21:16:05Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect users cert renewal process?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-users-cert-renewal-process/m-p/387487#M90382</link>
      <description>&lt;P&gt;Sounds like a plan. Good idea... &amp;nbsp; i dont think you will have many major issues here...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Good Luck.....&lt;/P&gt;</description>
      <pubDate>Tue, 23 Feb 2021 21:25:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-users-cert-renewal-process/m-p/387487#M90382</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2021-02-23T21:25:11Z</dc:date>
    </item>
  </channel>
</rss>

