Global Protect with self-signed certificate

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Global Protect with self-signed certificate

L4 Transporter

Hi, 

 

We have configured GlobalProtect with a self-sign certificate working properly, but when we try to connect through global protect we always receive this advise about "this certificate is not valid...." and we have to accept it to continue. This message is quite annoying.

Is there any way to use a self-signed certificate without seeing this message???

 

Regards,

JC

2 REPLIES 2

L4 Transporter

Hi JC,

 

To avoid the certificate error when using Self signed certificate, at least you need to make sure that the "signing certificate" ie the self signed CA used to sign the portal and gateway cert  is downloaded and added in the Trusted Root CA store of the end user machines.

 

Though there can be more complications regarding certificates (like one mentioned in the DOC below) depending on exact implementation of the GP setup. It is difficult to conclude the reason without knowing the exact setup/config.

 

https://live.paloaltonetworks.com/t5/Management-Articles/GlobalProtect-Gateway-Certificate-Error-Whe...

 

It would help if you could add the exact error message snapshot seen on the user machines and GP Agent and panOS version.

 

 

 

L5 Sessionator

Is the self singed certificate a CA cert or signed by a private CA?

  • 6274 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!