Does Pre-logon for Global Protect use the Computer certificate as a client certificate?

Reply
L2 Linker

Does Pre-logon for Global Protect use the Computer certificate as a client certificate?

Hi;

 

Prelogon Global Protect connection, does it use the Computer certificate as opposed to the user certificate to establish the tunnel? It seems that the only way to do it.

 

Kindly

Wasfi

L6 Presenter

Re: Does Pre-logon for Global Protect use the Computer certificate as a client certificate?

Yes it will use the certificate in the computers store, it cannot use the user cert until user logs in as GP will not have access to the user profile and how will GP know which user will be logging in.

 

is there another reason why you need user details on pre logon?

L2 Linker

Re: Does Pre-logon for Global Protect use the Computer certificate as a client certificate?

Thank you Mick. 

 

There is no reason but I just wanted to understand the mechanism as one of the clients asked me about it.

 

 

 

Kindly

Wasfi

L6 Presenter

Re: Does Pre-logon for Global Protect use the Computer certificate as a client certificate?

sure, no problem but please note that its not a case of using a machine certificate, more using a certificate in the machine store.

 

you could import a cert for fred smiff into the machine store and it will happily use that if it matches the root cert on the palo config.

 

L2 Linker

Re: Does Pre-logon for Global Protect use the Computer certificate as a client certificate?

However GP Pre-logon from 9.0 and 9.0.1 is broken and is currently with TAC for investigation. 

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!