Pre-Logon Behavior with SAML Login

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Pre-Logon Behavior with SAML Login

L1 Bithead

I recently found interesting behavior in GlobalProtect with pre-logon when using SAML. I started off by following these instructions:  Remote Access VPN with Pre-Logon

 

The customer I was working with had certificates in the user-store they did not want to access during pre-logon or user login. We specified "Machine" in the "Client Certificate Store Lookup" App setting for both the pre-logon and user login app configs.

 

Despite setting this, the GlobalProtect gateway connection still attempted to access the user-store. I was able to test this by importing the user certificate with Windows strong private key protection enabled, causing Windows to require interactive user approval whenever an application attempted to use the certificate’s private key.

 

In my setup, I had only one gateway for both the pre-logon and user login. The authentication method was Microsoft Entra as a SAML Identity Provider. The Client Authentication setting "Allow Authentication with User Credentials OR Client Certificate" was set to "Yes." Therefore, the login phase itself does not need access to a certificate.

 

To solve this, I separated out the gateways into two. The pre-logon gateway had no Client Authentication set. The Certificate Profile set in the Global Protect Gateway's Authentication tab was the profile with the Certificate Authority that signed the machine certificates in the machine store. The user login gateway had Client Authentication with the SAML Identity Provider Authentication Profile and "none" set for the Certificate Profile.

 

This means, when the login flow accessed the gateway during user login, it would search the user-store despite having "Machine" set in "Client Certificate Store Lookup" for both Portal Agent App configurations. I began to suspect this was due to the Embedded Browser (Microsoft WebView2). To explore this I changed the Client Authentication method in both the Portal and Gateway to a Local Database Authentication Profile. This change, indeed, stopped the flow from looking in the user-store.

 

Based on my investigation, the Embedded Browser will look into the user-store of a Windows machine during user logon if a Certificate Profile is set in the Gateway's Authentication tab. This will happen even if Machine is set in the "Client Certificate Store Lookup" of the corresponding Agent App configuration. The only way to resolve this is to separate the pre-logon gateway from the user login gateway when setting up GlobalProtect with Pre-Logon.

 

I completed this entire setup and show the pop-up indicating searches through the user-store here: https://youtu.be/6KHkkMr0SCI

Securing stuff
0 REPLIES 0
  • 43 Views
  • 0 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!