cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Who Me Too'd this topic

GlobalProtect Web Portal - Domain Validation Code (DVC) - /.well-known/pki-validation

L4 Transporter

Does anyone know how to go about performing domain validation for an IP address for the GlobalProtect Portal?

 

This is a standard supported by most Certificate providers but I can't find anything about it when searching Palo Alto's site.  With this tunnelcrack vulnerability and the need to use an IP address in the SAN of a publicly signed cert, I need to validate ownership of the IP and this appears to be the only method with DNS being out of the equation.

 

As an example this is digicert's method of validation: https://docs.digicert.com/en/certcentral/manage-certificates/dv-certificate-enrollment/domain-contro...

 

It essentially involves dropping a file in this standard directory path: [yourdomain.com]/.well-known/pki-validation/

 

Searching the KB's and Support I can't find a reference to this on Palo's site.

Who Me Too'd this topic