Certificate Error in GP

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Certificate Error in GP

L4 Transporter

Hi Team,

 

I am getting below error while try to connect to GP. 

 

SubaMuthuram_0-1661322421146.png

 

When I am try to connect to the portal getting this error, any suggestions? before it was showing continue but not it is not showing. 

 

Usually it will give the option to proceed anyway but it is not giving that option. After Reinstallation it is giving that option. 

Snow
1 ACCEPTED SOLUTION

Accepted Solutions

Hey @SubaMuthuram ,

Yes, but you will need to re-install GP agent again. Because you are in the "catch 22" right now - in order for the GP agent to get the new setting it needs to connect to GP portal, but it cannot because it still has the old setting which will not allow it to proceed with invalid certificate.

 

- Set "allow users to continue..." to yes under GP portal settings

- Re-install the GP to get the default behaviour and allow you to continue with invalid cert

- Any subsequent connection should allow you to continue with invalid cert

 

Although the above will definately solve your problem, I must say the proper way would be to use valid certificate which GP agent trust and leave the setting with default value of no (to block users connecting to portal with invalid certifcate), to prevent any possible man-in-the-middle.

 

View solution in original post

8 REPLIES 8

Community Team Member

Hi @SubaMuthuram ,

 

Did I understand it correctly ? After reinstalling GP your problem was resolved ?

 

Best,

-Kiwi.

 
LIVEcommunity team member, CISSP
Cheers,
Kiwi
Don't forget to hit that Like button if a post is helpful to you!

Cyber Elite
Cyber Elite

Hi @SubaMuthuram ,

 

It sounds that like under the portal, agent config you are using either the default value (or specifically set it) for the option "Allow User to Continue with Invalid Portal Server certificate"

Astardzhiev_0-1661492907455.png

 

As you can imagine from the name it will not allow users to continue with connection if they don't trust the portal certificate.

Now there is a "Catch 22" - this is GP agent behaviour config which GP agent will receive from the portal on his fist connection.

 

When you manually re-install the GP agent application its default behaviour is restored, which will allow you to continue if you don't trust portal certificate. Once you connect and get the portal config from the firewall any subsequent connection will fail - because agent is now instructed to not continue if portal cert is invalid.

 

As described on the following link you could control this setting during installation - https://docs.paloaltonetworks.com/globalprotect/9-1/globalprotect-admin/globalprotect-apps/deploy-ap...

This way even the very first connection to portal will fail, because after installation agent default behaviour will be "don't proceed if cert is invalid"

 

 

Hi @Astardzhiev ,

 

Great thanks for the clear info. that clears the lot. 

Snow

Hi @kiwi ,

 

You you are correct, After reinstalling the client it is working fine. 

Snow
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!