Hello team, To identify my users, I have used Captive Portal with ldap authentication profile. Then I removed the ldap from the captive protal config and added a "Certificate profile", and it works well as well. However, when I assign both an ldap profile AND a certificate profile to my captive portal configuration (Device> User Identification> Captive Portal settings), the paloalto first ask me to provide a client certificat then it allways prompt me for username/ password .... which is not something I want. My question is the following, is there a way to configure to paloalto so that if the client certificate authentication succeed then it doesn't prompt us for username/password. And if the client certificat authentication fails then it does prompt us for username password. I'm in lab environment and I can show my config, Many thanks for your help karim benyelloul
... View more