- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
09-19-2023 06:43 AM
Does anyone know how to go about performing domain validation for an IP address for the GlobalProtect Portal?
This is a standard supported by most Certificate providers but I can't find anything about it when searching Palo Alto's site. With this tunnelcrack vulnerability and the need to use an IP address in the SAN of a publicly signed cert, I need to validate ownership of the IP and this appears to be the only method with DNS being out of the equation.
As an example this is digicert's method of validation: https://docs.digicert.com/en/certcentral/manage-certificates/dv-certificate-enrollment/domain-contro...
It essentially involves dropping a file in this standard directory path: [yourdomain.com]/.well-known/pki-validation/
Searching the KB's and Support I can't find a reference to this on Palo's site.