- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
08-01-2026 09:27 AM - edited 08-01-2026 09:32 AM
I’ve got an iPad that has the GlobalProtect client installed. I’ve created self-signed certs using the PA 440 as the CA for the client auth, to enable MFA (user+pass & cert). I get this error “A valid client certificate is required for authentication. If the issue persists, contact your system administrator”.
I’ve been troubleshooting this for a couple of days. We kept running into pointers to JAMF or Apple Configurator, so I downloaded Apple Configurator and pushed the client certificate and the root CA trust chain, as well as the PA GP client instead of the manual method, *just to see* - and it acts the same way. The iPad device just doesn’t seem to recognize the client certificate and MFA fails. The EXACT same cert works on my MacBook Pro M3 without issue.
trust settings OK
Valid and trusted client auth certs. OK
Profiles in place. OK
Still.. No GO!
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!

