GlobalProtect Certificate Prompt

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

GlobalProtect Certificate Prompt

L3 Networker

My users using GlobalProtect on Windows are experiencing a very strange problem when they connect with GlobalProtect.   I am stuck on this one, any tips, pointers, or possible solutions are much appreciated.  

 

Usage:

  • Our GlobalProtect clients connect using pre-logon with certificates.  We are not using SSO.    

Problem:

  • Every once and a while, GlobalPrtect will throw a "certificate error" (see attached image of the error).  

Notes:

  • When I check the Microsoft Certificate store, the certificate is installed correctly. 
  • A reboot of the user's computer fixes the issue (certificate prompt does not come back)
  • Error happens among all the clients, completely at random (typically when they start-up their computer).

 

PAN-OS 7.0.3

GlobalProtect 2.2.1

 

certerror.png

 

 

1 accepted solution

Accepted Solutions

L3 Networker

I thought I would circle back and answer this:

 

In Windows, if you are using self-signed certificates, I found that both the CA and machine/client certificate must be put in both the Computer and User certificate stores.  I am not sure if this works for all variations of Windows, but it works in Win7, 8, and 10 from my testing.

 

  1. On Windows machine, open MMC console.
  2. File->Add/Remove Snap-ins...
  3. Click "Certificates" and add the Computer Account certificate store.
  4. Close out of Add/Remove Snap-ins... 
  5. Expand Computer Account store in MMC window.
    1. Right click Personal->Import 
      1. Import both the CA and the machine/client certificate individually.
    2. Right click Trusted Root Certificates->Import
      1. Import both the CA and the machine/client certificate individually.
  6. Do steps 1-5 again, except select "My User Account" certificate store in Step 3.  

View solution in original post

1 REPLY 1

L3 Networker

I thought I would circle back and answer this:

 

In Windows, if you are using self-signed certificates, I found that both the CA and machine/client certificate must be put in both the Computer and User certificate stores.  I am not sure if this works for all variations of Windows, but it works in Win7, 8, and 10 from my testing.

 

  1. On Windows machine, open MMC console.
  2. File->Add/Remove Snap-ins...
  3. Click "Certificates" and add the Computer Account certificate store.
  4. Close out of Add/Remove Snap-ins... 
  5. Expand Computer Account store in MMC window.
    1. Right click Personal->Import 
      1. Import both the CA and the machine/client certificate individually.
    2. Right click Trusted Root Certificates->Import
      1. Import both the CA and the machine/client certificate individually.
  6. Do steps 1-5 again, except select "My User Account" certificate store in Step 3.  
  • 1 accepted solution
  • 3372 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!