Palo Alto Global Protect embedded browser + Shibboleth

IAM David Bantz dabantz at alaska.edu
Thu May 26 18:34:50 UTC 2022


We’re using Palo Alto's Global Protect VPN with the client’s default
browser rather than PA’s embedded browser (just now confirmed with them
that there is a configuration setting on the GPN side enabling that
switch). The primary motivator for them was to be able to use hardware
tokens for MFA, but it has the advantages of avoiding the issue being
discussed here with the embedded browser, plus of course, establishing a
useful SSO session in the default browser, potentially avoiding additional
prompt for credentials. Isn’t that a win-win-win - or am I missing
something?

David St Pierre Bantz
U Alaska IAM
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20220526/adcd5c8c/attachment.htm>


More information about the users mailing list