如何在 Linux 机器上安装全球保护客户证书(乌本图)

如何在 Linux 机器上安装全球保护客户证书(乌本图)

53561
Created On 04/02/19 04:11 AM - Last Modified 09/04/23 17:54 PM


Objective


客户端尝试在Linux机上安装客户端证书。

Environment


  • PAN-OS 7.1及以上
  • 帕洛阿尔托 Firewall .
  • 任何支持Linux客户端运行全球保护4.1.x或5.0.x。


Procedure


  1. 在 Linux 机器上安装全球保护代理请参阅此链接
  2. 使用 Ftp 或 Scp 将证书下载或复制到 Linux 机器。
  3. 运行以下命令以安装证书。
SA@ubuntu:$ globalprotect import-certificate --location /home/skhan/Desktop/cert_Win7-SOS.p12 
Please input passcode:
Import certificate is successful. 
注意:在上面的命令/家庭/skhan/桌面是通往证书的路径。 修改它以适应您的环境。
  1. 一旦证书被导入,验证证书安装在 globalprotect 目录/选择/帕洛尔顿工厂 globalprotect /。在下面的示例中,安装了pan_client_cert_passcode.dat  pan_client_cert.pfx 的证书。
skhan@ubuntu:/opt/paloaltonetworks/globalprotect$ ls -lah 
total 12M
drwxr-xr-x 3 root              root  4.0K Apr  1 17:13 .
drwxr-xr-x 3 root              root  4.0K Sep 21  2018 ..
-rwxr-xr-x 1 speech-dispatcher uuidd 3.2M Mar 26 15:43 globalprotect
-rw-r--r-- 1 speech-dispatcher uuidd 1.1K Mar 26 15:43 gpd
-rw-r--r-- 1 speech-dispatcher uuidd  386 Mar 26 15:43 gpd.service
-rwxr-xr-x 1 speech-dispatcher uuidd  415 Mar 26 15:43 gpshow.sh
-rwxr-xr-x 1 speech-dispatcher uuidd 1.6K Mar 26 15:43 gp_support.sh
-rw-r--r-- 1 root              root   864 Apr  1 17:13 HipPolicy.dat
-rw-r--r-- 1 root              root   471 Apr  1 17:09 install.log
drwxr-xr-x 3 root              root  4.0K Apr  1 17:13 network
-rw-r--r-- 1 root              root    16 Apr  1 17:12 pan_client_cert_passcode.dat
-rw-r--r-- 1 root              root  2.4K Apr  1 17:12 pan_client_cert.pfx
-rwxr-xr-x 1 speech-dispatcher uuidd 3.3M Mar 26 15:43 PanGPA
-rwxr-xr-x 1 speech-dispatcher uuidd 3.9M Mar 26 15:43 PanGPS
-rw-r--r-- 1 root              root  924K Apr  1 21:03 PanGPS.log
-rw-r--r-- 1 speech-dispatcher uuidd 2.7K Apr  1 17:19 pangps.xml
-rwxr-xr-x 1 speech-dispatcher uuidd  181 Mar 26 15:43 PanMSInit.sh
-rwxr-xr-x 1 speech-dispatcher uuidd  118 Mar 26 15:43 pre_exec_gps.sh
-rw-r--r-- 1 root              root  2.3K Apr  1 17:13 tca.cer
skhan@ubuntu:/opt/paloaltonetworks/globalprotect$
  1. 使用预登录或用户徽标与客户端证书连接,以下日志将在 PanGPS .log中看到。 这确认已安装的证书工作正常。
P4022-T1047267072 Apr 01 21:08:48:990799 Debug( 160): Linux::GetHttpResponse serverIp=10.46.162.193
P4022-T1047267072 Apr 01 21:08:48:990907 Debug( 599): File /opt/paloaltonetworks/globalprotect/cc.pfx does not exist.
P4022-T1047267072 Apr 01 21:08:48:990913 Debug( 595): File /opt/paloaltonetworks/globalprotect/pan_client_cert.pfx exists.
P4022-T1047267072 Apr 01 21:08:48:990917 Debug( 595): File /opt/paloaltonetworks/globalprotect/pan_client_cert_passcode.dat exists.
P4022-T1047267072 Apr 01 21:08:48:994539 Debug(1174): not before=190326234539Z, not after=200325234539Z
P4022-T1047267072 Apr 01 21:08:48:994558 Debug(1181): cTime=190402040848
P4022-T1047267072 Apr 01 21:08:48:994561 Debug(1187): pkcs12 cert expired = 0
P4022-T1047267072 Apr 01 21:08:48:997781 Debug( 259): certIssuer=/CN=SOS-CA
P4022-T1047267072 Apr 01 21:08:48:997789 Debug( 769): SSL connecting to 10.46.162.193

 


Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PLMaCAO&lang=zh_CN&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language