Configure Certificate Selection in Prisma Agent (Panorama)
Focus
Focus
Prisma Agent

Configure Certificate Selection in Prisma Agent (Panorama)

Table of Contents


Configure Certificate Selection in Prisma Agent (Panorama)

Configure certificate selection criteria for Prisma Agent authentication in Panorama Managed Prisma Access.
To configure certificate selection criteria for Prisma Agent authentication in Panorama Managed Prisma Access:
  1. From the Cloud Services plugin in Panorama, select PanoramaCloud ServicesPrisma Access AgentLaunch Prisma Access Agent.
  2. Select ConfigurationPrisma Access AgentSettings.
  3. Select the Prisma Access Agent tab.
  4. Add Agent Settings, or edit an existing agent settings profile.
  5. Under the Authentication section, for Client Certificate Lookup Store, choose the certificate store the agent searches when selecting certificates for authentication:
    • User Store—Searches only the certificate store of the currently logged-in user.
    • Machine Store—Searches only the local machine's certificate store.
    • User, then Machine Store—Searches the user store first; if no matching certificate is found, searches the machine store. (Default)
    During a pre-logon tunnel, the agent always uses the machine store regardless of this setting.
  6. (Optional) In Extended Key Usage OID for Client Certificate, enter the OID values you want the agent to use to filter which certificates are valid for authentication. Enter OIDs as comma-separated values. If you leave this field blank, the agent doesn't perform EKU-based filtering.
    • The agent selects certificates that match any one of the specified OIDs.
    • You can enter up to 20 OIDs. Hover your cursor over the tooltip to show the common OIDS.
    • Common OIDs:
      • Client Authentication (1.3.6.1.5.5.7.3.2) (Default if not specified)
      • Smart Card Logon (1.3.6.1.4.1.311.20.2.2)
      • Any Extended Key Usage (2.5.29.37.0)
      • IPSec End System (1.3.6.1.5.5.7.3.5)
      • IPSec Tunnel (1.3.6.1.5.5.7.3.6)
      • IPSec User (1.3.6.1.5.5.7.3.7)
      • OCSP Signing (1.3.6.1.5.5.7.3.9)
  7. Save your agent settings.
  8. Push the Prisma Agent configuration to apply the changes to endpoints.