<div dir="ltr">Hi Steve -<div><br></div><div>Were you able to import the IDP's metadata into the PA console? Our user had issues doing that (it complained it couldn't find an IDPSSODDescriptor element), so we resorted to trying to configure the IDP manually.</div><div><br></div><div>Liam</div></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Tue, Feb 18, 2020 at 7:08 AM Mak, Steve <<a href="mailto:makst@upenn.edu">makst@upenn.edu</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">
<div lang="EN-US">
<div class="gmail-m_8403401492685643936WordSection1">
<p class="MsoNormal"><span style="font-family:Helvetica">Liam,<u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-family:Helvetica"><u></u> <u></u></span></p>
<p class="MsoNormal"><span style="font-family:Helvetica">We've successfully integrated a Palo Alto VPN with our Shibboleth IdP using SAML.<u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-family:Helvetica"><u></u> <u></u></span></p>
<p class="MsoNormal"><span style="font-family:Helvetica">We also ran into that error in the PA admin console.<u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-family:Helvetica"><u></u> <u></u></span></p>
<p class="MsoNormal"><span style="font-family:Helvetica">We determined that the PA admin console needed better documentation, but the end result was that the admin had to generate a new cert for authn REQUESTS.<u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-family:Helvetica"><u></u> <u></u></span></p>
<p class="MsoNormal"><span style="font-family:Helvetica">It was not expecting the IdP cert in that step. The PA console makes it seem like you need to give it the IdP's cert at that step, but it was asking for the cert it will use to sign the requests. We
found PA documentation that showed us how to generate a new cert in the admin console to use.<u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-family:Helvetica"><u></u> <u></u></span></p>
<p class="MsoNormal"><span style="font-family:Helvetica"><u></u> <u></u></span></p>
<p class="MsoNormal"><span style="font-family:Helvetica">We originally thought that we needed to reissue our IdP cert which would have been a nightmare. Before we decided to bite that bullet, we re-read the documentation because that seemed like a drastic
thing to do.<u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-family:Helvetica"><u></u> <u></u></span></p>
<p class="MsoNormal"><span style="font-family:Helvetica">Hope you find what you're looking for.<u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-family:Helvetica"><u></u> <u></u></span></p>
<p class="MsoNormal"><span style="font-family:Helvetica">- Steve<u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-family:Helvetica"><u></u> <u></u></span></p>
<div style="border-right:none;border-bottom:none;border-left:none;border-top:1pt solid rgb(181,196,223);padding:3pt 0in 0in">
<p class="MsoNormal"><b><span style="font-size:12pt;color:black">From: </span></b><span style="font-size:12pt;color:black">users <<a href="mailto:users-bounces@shibboleth.net" target="_blank">users-bounces@shibboleth.net</a>> on behalf of Liam Hoekenga <<a href="mailto:liamr@umich.edu" target="_blank">liamr@umich.edu</a>><br>
<b>Reply-To: </b>Shib Users <<a href="mailto:users@shibboleth.net" target="_blank">users@shibboleth.net</a>><br>
<b>Date: </b>Monday, February 17, 2020 at 16:14<br>
<b>To: </b>Shib Users <<a href="mailto:users@shibboleth.net" target="_blank">users@shibboleth.net</a>><br>
<b>Subject: </b>PaloAlto PAN-OS firewall<u></u><u></u></span></p>
</div>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
<div>
<p class="MsoNormal">I'm working with a department on our campus that is trying to bring up Palo Alto Security appliances (PA-3020 and PA-7080).<u></u><u></u></p>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
<div>
<p class="MsoNormal">The GUI cannot import the Shibboleth IDP metadata (for whatever reason), so we're trying the manual configuration route. The latest error comes when they try to import the IDP's signing certificate:<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
<div>
<p class="MsoNormal">"Only self-signed CA certificates can have identical subject and issue fields".<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
<div>
<p class="MsoNormal">Has anyone here integrated with PAN-OS?<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
<div>
<p class="MsoNormal">Liam<u></u><u></u></p>
</div>
</div>
</div>
</div>
-- <br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a></blockquote></div>