- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
08-01-2026 09:27 AM - edited 08-01-2026 09:32 AM
I’ve got an iPad that has the GlobalProtect client installed. I’ve created self-signed certs using the PA 440 as the CA for the client auth, to enable MFA (user+pass & cert). I get this error “A valid client certificate is required for authentication. If the issue persists, contact your system administrator”.
I’ve been troubleshooting this for a couple of days. We kept running into pointers to JAMF or Apple Configurator, so I downloaded Apple Configurator and pushed the client certificate and the root CA trust chain, as well as the PA GP client instead of the manual method, *just to see* - and it acts the same way. The iPad device just doesn’t seem to recognize the client certificate and MFA fails. The EXACT same cert works on my MacBook Pro M3 without issue.
trust settings OK
Valid and trusted client auth certs. OK
Profiles in place. OK
Still.. No GO!
08-04-2026 07:12 AM
In the error screen shot above, it doesn't show the error I'm getting. We checked the certificate trust settings on the iPad and it is set to trust the CA of the Palo that issued the client cert, which I've deployed manually (airdrop!) and using Apple Configurator to push the profile. Neither works, and I'm stuck here... Is this just an "Apple thing?" - I'm starting to see some results around the Apple Developers postings... Anyone getting IOS devices to work with GP and 2FA? Can't tell me to upgrade - I'm on 12.2.2 and the latest GP 6.3.3-1046. HELP
08-04-2026 07:38 AM
There are very strict certificate and MDM requirements and the certificates need to be presented as part of a VPN profile, not simply placed on the device. As you've described what you're doing, yes this is an iOS limitation and would be expected with how you appear to be trying to deploy this. It would also explain why you're seeing success with macOS.
08-05-2026 08:36 AM
Hello. I thought that, too, since I installed the cert manually the 1st time I tested. Then I learned how to push them using Apple Configurator 2.0 as part of a VPN profile. (see 2,3,4th screen shots in OP). I followed the instructions on the Apple site. I'm still not satisfied with the information that's out there, and I don't have a solution.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!

