Wrapped around the axle - iOS + GP + Client Certificate generated on the Palo

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Wrapped around the axle - iOS + GP + Client Certificate generated on the Palo

L1 Bithead

I’ve got an iPad that has the GlobalProtect client installed.  I’ve created self-signed certs using the PA 440 as the CA for the client auth, to enable MFA (user+pass & cert).  I get this error “A valid client certificate is required for authentication.  If the issue persists, contact your system administrator”. 

 

I’ve been troubleshooting this for a couple of days.  We kept running into pointers to JAMF or Apple Configurator, so I downloaded Apple Configurator and pushed the client certificate and the root CA trust chain, as well as the PA GP client instead of the manual method, *just to see* - and it acts the same way.  The iPad device just doesn’t seem to recognize the client certificate and MFA fails.  The EXACT same cert works on my MacBook Pro M3 without issue.

 

trust settings OKtrust settings OK

 

Valid and trusted client auth certs. OK

IMG_0620.png

IMG_0619.jpeg

 

Profiles in place. OK

IMG_0617.png

 

Still.. No GO!

IMG_0612.pngIMG_0622.jpegIMG_0621.jpeg

 

"May your error messages be ever changing" - The Troubleshooter's Blessing
3 REPLIES 3

L1 Bithead

In the error screen shot above, it doesn't show the error I'm getting. We checked the certificate trust settings on the iPad and it is set to trust the CA of the Palo that issued the client cert, which I've deployed manually (airdrop!) and using Apple Configurator to push the profile.  Neither works, and I'm stuck here... Is this just an "Apple thing?" - I'm starting to see some results around the Apple Developers postings...  Anyone getting IOS devices to work with GP and 2FA?  Can't tell me to upgrade - I'm on 12.2.2 and the latest GP 6.3.3-1046.  HELP

Screenshot 2026-08-04 at 10.03.17 AM.png

 

"May your error messages be ever changing" - The Troubleshooter's Blessing

Cyber Elite

@wesprather,

There are very strict certificate and MDM requirements and the certificates need to be presented as part of a VPN profile, not simply placed on the device. As you've described what you're doing, yes this is an iOS limitation and would be expected with how you appear to be trying to deploy this. It would also explain why you're seeing success with macOS.  

Hello.  I thought that, too, since I installed the cert manually the 1st time I tested.  Then I learned how to push them using Apple Configurator 2.0 as part of a VPN profile.  (see 2,3,4th screen shots in OP).  I followed the instructions on the Apple site.  I'm still not satisfied with the information that's out there, and I don't have a solution.

"May your error messages be ever changing" - The Troubleshooter's Blessing
  • 188 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!