<div dir="ltr">Thank you for that response and for including the options. We also thought of options 1 and 2 and knew it would be painful. We also use openssl a lot. We actually built our own CA for campus usage with openssl and pushed out the root certificate with GPO so clients machines trust the certificate. This is only used for internal use.  I did not know about option 3. That will be something I will be looking into. I had heard about the Global Protect client issue with 5.2.8 on this forum. So I will definitely have to let our service desk know. Hopefully PA gets it figured out soon.<div><br></div><div>Thank you <br clear="all"><div><div dir="ltr" class="gmail_signature" data-smartmail="gmail_signature"><div dir="ltr"><div><p><span style="font-family:Arial,sans-serif;color:rgb(31,73,125)"><font size="1">Steve Herrera</font></span><span style="font-family:Arial,sans-serif;color:rgb(31,73,125)"><font size="1"><br>Information Security<br></font></span><span style="color:rgb(31,73,125);font-family:Arial,sans-serif;font-size:7.5pt">Bradley University<br></span><span style="color:rgb(31,73,125);font-family:Arial,sans-serif;font-size:7.5pt">Phone: 309 / 677-2336<br></span><span style="color:rgb(31,73,125);font-family:Arial,sans-serif;font-size:7.5pt">FAX: 309 / 677-3460<br></span><span style="font-size:7.5pt;font-family:Arial,sans-serif;color:rgb(31,73,125)">Email:  </span><u><span style="font-size:7.5pt;font-family:"Arial","sans-serif";color:blue"><a href="mailto:sherrera@fsmail.bradley.edu" target="_blank">sherrera@fsmail.bradley.edu</a></span></u></p></div></div></div></div><br></div></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Thu, Jun 9, 2022 at 11:05 AM Steven Teixeira <<a href="mailto:steixeira@csustan.edu">steixeira@csustan.edu</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">





<div lang="EN-US" style="overflow-wrap: break-word;">
<div class="gmail-m_8459468688643072350WordSection1">
<p class="MsoNormal">So first off, get ready for some pain and suffering when it comes to PAN.  I don’t intend to scare you, and it’s totally something that can be implemented, but PAN makes things pretty difficult.<u></u><u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal">You’re getting that error because PAN requires that the “Subject Type=CA” basic restraint be included in the self-signed certificate.  Shibboleth doesn’t generate a self-signed certificate at install time with this constraint.  So you have
 to generate a certificate yourself with this constraint.  So you have a few options:<u></u><u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<ol style="margin-top:0in" start="1" type="1">
<li class="gmail-m_8459468688643072350MsoListParagraph" style="margin-left:0in">Generate a new self-signed certificate with that constraint outside of Shibboleth(like with openssl), and replace your existing certificate.  This is obviously very, very painful as
 you’ll have to deal with key rotations and notifying a lot of parties.  I don’t recommend this, but it’s an option.<u></u><u></u></li><li class="gmail-m_8459468688643072350MsoListParagraph" style="margin-left:0in">Generate a new self-signed certificate with that constraint outside of Shibboleth(like with openssl), using that same key so at least your key is the same.  However, some SPs don’t
 do what they should and incorrectly look at the certificate instead of the just key it contains, so they’ll not like that you changed the certificate, even though it’s the same key.  So you’ll still have to notify and brace yourself for some fallout.<u></u><u></u></li><li class="gmail-m_8459468688643072350MsoListParagraph" style="margin-left:0in">Generate a new self-signed certificate with that constraint outside of Shibboleth(like with openssl), and wire up your IdP to only use that certificate for PAN and no one else(or potentially
 for others than have this silly requirement, but I haven’t seen another yet).  How to do this should be documented somewhere, and I fortunately didn’t have to do this myself, so I’m not of much help there.  This option is more work for you, but is probably
 your best option since you don’t really have to worry about problems with existing SPs.<u></u><u></u></li></ol>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal">Sorry to be the bearer of bad news.  Also, you should be aware if you haven’t read it on this list already that currently, any Global Protect client above 5.2.8 has a bug if you’re choosing to use the provided/embedded browser where hitting
 the Enter key after providing credentials on your IdP’s login page will result in an error.  Clicking the “submit” button instead of using the Enter key is a (dumb) workaround.  I haven’t been following the issue closely, but I hear that PAN hasn’t been responsive
 to that issue either and they’re the ones who broke it in the first place.<u></u><u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<div>
<p class="MsoNormal">Steven Teixeira<u></u><u></u></p>
</div>
<p class="MsoNormal"><u></u> <u></u></p>
<div>
<div style="border-right:none;border-bottom:none;border-left:none;border-top:1pt solid rgb(225,225,225);padding:3pt 0in 0in">
<p class="MsoNormal"><b>From:</b> users <<a href="mailto:users-bounces@shibboleth.net" target="_blank">users-bounces@shibboleth.net</a>> <b>On Behalf Of
</b>Steve Herrera via users<br>
<b>Sent:</b> Thursday, June 9, 2022 8:07 AM<br>
<b>To:</b> Shib Users <<a href="mailto:users@shibboleth.net" target="_blank">users@shibboleth.net</a>><br>
<b>Cc:</b> Steve Herrera <<a href="mailto:sherrera@fsmail.bradley.edu" target="_blank">sherrera@fsmail.bradley.edu</a>><br>
<b>Subject:</b> Globalprotect and Shibboleth<u></u><u></u></p>
</div>
</div>
<p class="MsoNormal"><u></u> <u></u></p>
<div style="border:4.5pt solid rgb(156,101,0);padding:2pt">
<p class="MsoNormal" style="line-height:16pt;background:rgb(255,235,156)"><u><span style="font-size:14pt;font-family:’Calibri’,serif;color:rgb(144,5,40)">CAUTION:
</span></u><span style="font-size:14pt;font-family:’Calibri’,serif;color:black">This message originated from outside of Stanislaus State. Do not click on links or open attachments unless you recognize the sender and are expecting the message.<u></u><u></u></span></p>
</div>
<p class="MsoNormal"><u></u> <u></u></p>
<div>
<div>
<p class="MsoNormal">We use Palo Alto firewalls here and the Globalprotect client as the method for our users to VPN into campus. We are trying to get Globalprotect to use SAML. The first hurdle we are running into is uploading the Shibboleth self-signed certificate
 into the Palo Alto certificate profile. The error we get is: <u></u><u></u></p>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
<div>
<p class="MsoNormal">Import failed. Only self signed CA certificates can have identical subject and issuer fields.<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
<div>
<p class="MsoNormal">I have seen others posting about using Globalprotect and shibboleth on here. My question is, are you using the shibboleth self-signed certificate and were you able to import that into the Palo Alto? Or are you using a different certificate? 
 I have a ticket open with Palo but they have not been responsive. <u></u><u></u></p>
</div>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
<div>
<p class="MsoNormal">Thanks<br clear="all">
<u></u><u></u></p>
<div>
<div>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>

-- <br>
For Consortium Member technical support, see <a href="https://shibboleth.atlassian.net/wiki/x/ZYEpPw" rel="noreferrer" target="_blank">https://shibboleth.atlassian.net/wiki/x/ZYEpPw</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div>