<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cannot install Machine Certificate for GP Pre-logon in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-install-machine-certificate-for-gp-pre-logon/m-p/391669#M90798</link>
    <description>&lt;P&gt;I cannot really tell without seeing your complete setup but it may be that as you included the certificate in the profile, GP was seeing pre-logon as a separate user rather than just a pre-logon user.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 17 Mar 2021 09:28:57 GMT</pubDate>
    <dc:creator>Mick_Ball</dc:creator>
    <dc:date>2021-03-17T09:28:57Z</dc:date>
    <item>
      <title>Cannot install Machine Certificate for GP Pre-logon</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-install-machine-certificate-for-gp-pre-logon/m-p/387683#M90407</link>
      <description>&lt;P&gt;&lt;SPAN&gt;I encountered a problem installing the machine certificate.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ERROR.png" style="width: 450px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/30057i6EDD1C61F52408C1/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="ERROR.png" alt="ERROR.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV&gt;I followed the article below:&lt;/DIV&gt;&lt;DIV&gt;&lt;A href="https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Flive.paloaltonetworks.com%2Ft5%2Fnews%2Fglobalprotect-pre-logon-authentication%2Fta-p%2F322237&amp;amp;data=04%7C01%7Csupport-anz%40arrow.com%7C94e133675a714c61b2b508d8d7a6777e%7C0beb0c359cbb4feb99e5589e415c7944%7C1%7C0%7C637496457276630672%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&amp;amp;sdata=m6V2MbCvJME6FZVWm%2BIS%2BP7eO%2B01KCNPWsQosaz98DI%3D&amp;amp;reserved=0" target="_blank" rel="noopener"&gt;https://live.paloaltonetworks.com/t5/news/globalprotect-pre-logon-authentication/ta-p/322237&lt;/A&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;We are using a self-signed&lt;SPAN&gt;&amp;nbsp;root ca that is in the cert profile for auth, then generated the server cert and machine cert and signed them with the same root. Then export as pks12.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;In the Certificate Profile, I&amp;nbsp;&lt;SPAN&gt;changed the Username Field type from 'None' to 'Subj'.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Made sure I selected the Computer account (default is user account) and cert is in folder "Personal" there.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="CERT.jpg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/30058i5378CCDBEF2CB649/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="CERT.jpg" alt="CERT.jpg" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Tried the MS fix but no luck.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&lt;A href="https://social.technet.microsoft.com/Forums/en-US/50bd9c7c-faaa-46e3-b9a4-a2bb885b180d/unable-to-import-certificate-p12-or-pfx-file?forum=winserver8gen" target="_blank" rel="noopener"&gt;https://social.technet.microsoft.com/Forums/en-US/50bd9c7c-faaa-46e3-b9a4-a2bb885b180d/unable-to-import-certificate-p12-or-pfx-file?forum=winserver8gen&lt;/A&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Please help!&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Thu, 25 Feb 2021 02:59:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cannot-install-machine-certificate-for-gp-pre-logon/m-p/387683#M90407</guid>
      <dc:creator>FarzanaMustafa</dc:creator>
      <dc:date>2021-02-25T02:59:01Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot install Machine Certificate for GP Pre-logon</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-install-machine-certificate-for-gp-pre-logon/m-p/387724#M90415</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/98673"&gt;@FarzanaMustafa&lt;/a&gt;&amp;nbsp;.&lt;/P&gt;&lt;P&gt;have you tried to install the same certificate into the user personal store of the same device or into another device that is not controlled by group policy etc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;this will not fix the issue but you need to first discover if this is a problem with the certificate or the installation process.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;has your root CA been used to generate other successful client auth certs?&lt;/P&gt;</description>
      <pubDate>Thu, 25 Feb 2021 06:18:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cannot-install-machine-certificate-for-gp-pre-logon/m-p/387724#M90415</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2021-02-25T06:18:24Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot install Machine Certificate for GP Pre-logon</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-install-machine-certificate-for-gp-pre-logon/m-p/388734#M90532</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&amp;nbsp;Thank you so much for your guidance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The Gateway is now working. Any idea how to check evidence of client cert checks being performed? ie.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;How can I validate if the user is authenticated with the pre-logon feature?&lt;/P&gt;</description>
      <pubDate>Wed, 03 Mar 2021 03:42:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cannot-install-machine-certificate-for-gp-pre-logon/m-p/388734#M90532</guid>
      <dc:creator>FarzanaMustafa</dc:creator>
      <dc:date>2021-03-03T03:42:22Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot install Machine Certificate for GP Pre-logon</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-install-machine-certificate-for-gp-pre-logon/m-p/388841#M90550</link>
      <description>&lt;P&gt;check the gateway current users. add "pre" to the search, this is what you will se before the user connects.&lt;/P&gt;&lt;P&gt;you can also check the previous user tab with pre.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MickBall_0-1614776470333.jpeg" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/30161i0AED6ED16ABB9CBA/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="MickBall_0-1614776470333.jpeg" alt="MickBall_0-1614776470333.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Mar 2021 13:01:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cannot-install-machine-certificate-for-gp-pre-logon/m-p/388841#M90550</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2021-03-03T13:01:22Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot install Machine Certificate for GP Pre-logon</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-install-machine-certificate-for-gp-pre-logon/m-p/390824#M90726</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sorry for the delayed response and thank you once again for your great inputs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;When I'm logged out from the workstation the pre-logon user is not showing in the gateway. I can see it in the Previous User tab.&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV&gt;However, on the KB article of PA it says:&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Pre-logon.jpg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/30303iBE25721937A94636/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Pre-logon.jpg" alt="Pre-logon.jpg" /&gt;&lt;/span&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;A href="https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail%3Fid%3DkA10g000000ClEYCA0&amp;amp;data=04%7C01%7Csupport-anz%40arrow.com%7Ca60d9eb1515b4cdce15808d8e516f465%7C0beb0c359cbb4feb99e5589e415c7944%7C1%7C0%7C637511234076731084%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&amp;amp;sdata=yHchboUuxwC27K6bFelyaSIEkUfNqMO9hkHZqVjHxzY%3D&amp;amp;reserved=0" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClEYCA0&lt;/A&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Could you please endorse my concern with the relevant PA Team?&lt;/SPAN&gt;&lt;/DIV&gt;</description>
      <pubDate>Fri, 12 Mar 2021 05:32:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cannot-install-machine-certificate-for-gp-pre-logon/m-p/390824#M90726</guid>
      <dc:creator>FarzanaMustafa</dc:creator>
      <dc:date>2021-03-12T05:32:58Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot install Machine Certificate for GP Pre-logon</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-install-machine-certificate-for-gp-pre-logon/m-p/390880#M90731</link>
      <description>&lt;P&gt;something seems to be wrong with your configuration as when I log off my workstation the existing (not previous) connection changes to pre-logon and reverts to my name when i log back in.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;can you post exactly what you have in the gateway config...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Mar 2021 10:49:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cannot-install-machine-certificate-for-gp-pre-logon/m-p/390880#M90731</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2021-03-12T10:49:00Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot install Machine Certificate for GP Pre-logon</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-install-machine-certificate-for-gp-pre-logon/m-p/390882#M90732</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MickBall_0-1615546942076.jpeg" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/30304i40D98CEAE241AF65/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="MickBall_0-1615546942076.jpeg" alt="MickBall_0-1615546942076.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Mar 2021 11:02:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cannot-install-machine-certificate-for-gp-pre-logon/m-p/390882#M90732</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2021-03-12T11:02:40Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot install Machine Certificate for GP Pre-logon</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-install-machine-certificate-for-gp-pre-logon/m-p/391645#M90795</link>
      <description>&lt;P&gt;Thank you so much for your guidance.&lt;/P&gt;&lt;P&gt;I checked the GP GW config and removed the cert from Certificate Profile. It worked!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;May I ask what was the problem?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Cert Profile.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/30386i76B1D2A2CE2F89CF/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Cert Profile.png" alt="Cert Profile.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Mar 2021 00:23:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cannot-install-machine-certificate-for-gp-pre-logon/m-p/391645#M90795</guid>
      <dc:creator>FarzanaMustafa</dc:creator>
      <dc:date>2021-03-17T00:23:55Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot install Machine Certificate for GP Pre-logon</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-install-machine-certificate-for-gp-pre-logon/m-p/391669#M90798</link>
      <description>&lt;P&gt;I cannot really tell without seeing your complete setup but it may be that as you included the certificate in the profile, GP was seeing pre-logon as a separate user rather than just a pre-logon user.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Mar 2021 09:28:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cannot-install-machine-certificate-for-gp-pre-logon/m-p/391669#M90798</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2021-03-17T09:28:57Z</dc:date>
    </item>
  </channel>
</rss>

