Login problem - old user, new laptop and a confused administrator

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Login problem - old user, new laptop and a confused administrator

L3 Networker

PAN-200

Version: 6.0.1

GP Agent: 2.0.4

Having a problem with a laptop (Windows 8.1)  and authenticated using certificates and active directory.  Palo Alto and network newbie.  New to Windows .. I've been a linux admin for so very long. Help ...

So .. we doubled the size of our IT department with a new hire, Ben.  Ben used a loaner laptop for a week, until 'his' arrived.

(Active Directory Domain Controller resides at another site.  We connect to them at boot time using GPAgent, with the PAN-200 acting as a CA for the machine certs.  It's worked well for my laptop (OS X), a test laptop (Win 8), and New Guy's loaner laptop (Win 8).  The windows machines present the domain login at boot and all appears to be well.)

The process we have to setup machines is roughly ..

Admin generates new certificate, signed by CA.  Export as PKCS12, email to user.  Verbally provide the passphrase.  They import, placing it in the personal cert folder.

Ben's new laptop arrived. 

Generated a new certificate per above.  Installed it on new laptop per published instructions.  Login to https:\\PAN-IP and it tells him ... 'bad certificate'.

Downloaded the .msi and forwarded to him via email .. he installed.  Same problem with GP Agent: 'bad certificate'.

Removed the certs using the windows cert manage, reinstalled with a NEW certificate.  Same problem.  Removed the certs from IE and reinstalled the NEW certificate .. same problem.

Revoked the cert from the OLD laptop and reinstalled a new certificate .. and it works.

It does the same thing when I login with 'my' AD credentials.  So I think I've fault isolated the problem to 'the new laptop'.

Logs \ System tells me 'GlobalProtect portal user authentication failed.   Login from: xxx.xxx.xxx.xxx, User name: , Reason: client cert invalid.

I'll accept the cert is invalid, I just don't see how.

Where in the Wide World of Sports does one start to troubleshoot this stuff with Win 8.1?

2 REPLIES 2

L5 Sessionator

Hi Bdunbar,

Might be a overkill but can you install both root cert (without passphrase) and client cert (with pass phrase) on both Computer Account and My User Account (under mmc) and try logging in one more time. Thank you.

Update. The problem was Internet Explorer.  Ben installed Chrome and LO it worked without issue.

I'd not noticed because the first thing I do on a new host is install Chrome or Firefox.

  • 2336 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!