Global Protect Certificate Authentication

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Global Protect Certificate Authentication

L1 Bithead

Hi Team,

 

We are using self signed certificate for user authentication signed by self-signed CA cert on Palo Alto for our global protect.

 

does my understanding below is correct regarding certificate expiration/renewal.

 

1. if CA cert expired while user cert still valid, user does not need to install renewed CA cert.

we can renew the CA cert on palo alto and user will be able to connect to global protect again.

 

2. If we renew user certificate (i.e user cert is still valid and we renew for 1 year), user will need to install new renewed certificate.

 

 

Thanks

2 accepted solutions

Accepted Solutions

L2 Linker

Hey @L1_ENG  I hope all is well!

 

1. If the CA certificate used to sign any intermediate or leaf certificate expires, then each subordinate child ticket will be invalidated also. This is true regardless of the certificate being self-signed form the firewall itself or imported from an internal PKI.

 

2. If the CA certificate is generated on the firewall, and is renewed on the firewall prior to expiring, then it doesn't require being redeployed to the endpoints, as it will automatically be updated.

 

I hope this helps with your questions! 

 

 

-Stay safe and have a great day!

-Cheers

View solution in original post

Hi @trivers01!

 

Thank you for your response,

 

View solution in original post

2 REPLIES 2

L2 Linker

Hey @L1_ENG  I hope all is well!

 

1. If the CA certificate used to sign any intermediate or leaf certificate expires, then each subordinate child ticket will be invalidated also. This is true regardless of the certificate being self-signed form the firewall itself or imported from an internal PKI.

 

2. If the CA certificate is generated on the firewall, and is renewed on the firewall prior to expiring, then it doesn't require being redeployed to the endpoints, as it will automatically be updated.

 

I hope this helps with your questions! 

 

 

-Stay safe and have a great day!

-Cheers

Hi @trivers01!

 

Thank you for your response,

 

  • 2 accepted solutions
  • 3486 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!