Adding multiple client certificate in Linux GP agent

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Adding multiple client certificate in Linux GP agent

L4 Transporter

Hi Community,

 

I have a requirement to add multiple client certificate into Linux GP config. Usually, whe we put 'globalprotect import-certificate --location <cert_location>', the existing client cert will be overridden with the new one and it will be imported as pan_client_cert.pfx under /opt/paloaltonetworks/globalprotect .. Is there a way to keep both instead of override, so that i can use different client certificates while connecting to different portals. In windows, as it is taking from windows personal store, it will be discrete and we wont face this issue.

 

Anybody have any idea to achieve this ?.. or can we combine different .p12 files to single .pfx ?, 

I am looking for some options other than adding both CAs in certificate profile

 

Thanks in advance!

 

1 REPLY 1

L3 Networker

Hello @Abdul_Razaq,

 

As far as I know there is a technical possibility to include multiple certificate chains and private keys in a PKCS #12 archive however it is not something widely implemented.

 

I see GlobalProtect App for Linux as an open-beta and assume what you require is beyond its abilities. Even basic verification of imported certificate is not performed:

$ globalprotect import-certificate --location /dev/zero
Please input passcode:
Import certificate is successful.

 

I would explore alternative VPN Client - OpenConnect. It claims compatibility with GlobalProtect: https://www.infradead.org/openconnect/globalprotect.html

Certificate for authentication is provided as command-line argument (https://www.infradead.org/openconnect/manual.html - -c,--certificate=CERT) so it can be easily selected per Portal/Gateway.

 

Not sure it will satisfy your other requirements, and it is a 3-rd party application introduction into environment, but might work.

Getting in touch with your SE to rise a Feature Request and wait like Sleeping Beauty for it to be kissed by a PM-Prince is also an option 😉

  • 2590 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!