Wrapped around the axle - iOS + GP + Client Certificate generated on the Palo

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Wrapped around the axle - iOS + GP + Client Certificate generated on the Palo

L0 Member

I’ve got an iPad that has the GlobalProtect client installed.  I’ve created self-signed certs using the PA 440 as the CA for the client auth, to enable MFA (user+pass & cert).  I get this error “A valid client certificate is required for authentication.  If the issue persists, contact your system administrator”. 

 

I’ve been troubleshooting this for a couple of days.  We kept running into pointers to JAMF or Apple Configurator, so I downloaded Apple Configurator and pushed the client certificate and the root CA trust chain, as well as the PA GP client instead of the manual method, *just to see* - and it acts the same way.  The iPad device just doesn’t seem to recognize the client certificate and MFA fails.  The EXACT same cert works on my MacBook Pro M3 without issue.

 

trust settings OKtrust settings OK

 

Valid and trusted client auth certs. OK

IMG_0620.png

IMG_0619.jpeg

 

Profiles in place. OK

IMG_0617.png

 

Still.. No GO!

IMG_0612.pngIMG_0622.jpegIMG_0621.jpeg

 

0 REPLIES 0
  • 25 Views
  • 0 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!