HIPs check for Client Side Certificate

Reply
L1 Bithead

HIPs check for Client Side Certificate

Is it possible to use HIPs to verify the presence of a Client Side Certificate such as GlobalProtect cert for a computer and also check for cert on a mobile device? If the device has the cert then we would allow it through a firewall policy.

L7 Applicator

Re: HIPs check for Client Side Certificate

Hello,

Would this device you are attempting to check behind the firewall or connecting via a client VPN connection?

 

Regards,

L1 Bithead

Re: HIPs check for Client Side Certificate

Thanks for replying and it would be connecting via a GlobalProtect VPN client.

L7 Applicator

Re: HIPs check for Client Side Certificate

L1 Bithead

Re: HIPs check for Client Side Certificate

Thanks for that info. The issue is that we would need to check for a specfic certificate: the machine certificate and I cannot seem to find a registry entry that allows me to do that. I believe I need to open a case with Palo Alto Support and I will report back with results if possible. Thank You

L1 Bithead

Re: HIPs check for Client Side Certificate

Well in the end we did not find a way to use HIPs custom checks in order to verify a machine certificate. The issue being that the certificate stuff is stored in the registry in blob format which doesnt allow parsing for specifics.

 

I have convinced the team to move forward by using GlobalProtect Certificate check against our PKI

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!