Configure Certificate Selection in Prisma Agent (Strata Cloud Manager)
Focus
Focus
Prisma Agent

Configure Certificate Selection in Prisma Agent (Strata Cloud Manager)

Table of Contents


Configure Certificate Selection in Prisma Agent (Strata Cloud Manager)

Configure certificate selection criteria for Prisma Agent authentication in Strata Cloud Manager Managed Prisma Access.
To configure certificate selection criteria for Prisma Agent authentication in Strata Cloud Manager Managed Prisma Access.
  1. Select ConfigurationNGFW and Prisma AccessConfiguration ScopeAccess AgentSetupPrisma Access Agent.
  2. Add Agent Settings, or edit an existing agent settings profile.
  3. Expand Show Advanced Options and then expand Authentication.
  4. For Client Certificate Lookup Store, choose the certificate store the agent searches when selecting certificates for authentication:
    • User Store—Searches only the certificate store of the currently logged-in user.
    • Machine Store—Searches only the local machine's certificate store.
    • User, then Machine Store—Searches the user store first; if no matching certificate is found, searches the machine store. (Default)
    During a pre-logon tunnel, the agent always uses the machine store regardless of this setting.
  5. (Optional) In Extended Key Usage OID for Client Certificate, enter the OID values you want the agent to use to filter which certificates are valid for authentication. Enter OIDs as comma-separated values. If you leave this field blank, the agent doesn't perform EKU-based filtering.
    • The agent selects certificates that match any one of the specified OIDs.
    • You can enter up to 20 OIDs. Hover your cursor over the tool tip to show the common OIDS.
    • Common OIDs:
      • Client Authentication (1.3.6.1.5.5.7.3.2) (Default if not specified)
      • Smart Card Logon (1.3.6.1.4.1.311.20.2.2)
      • Any Extended Key Usage (2.5.29.37.0)
      • IPSec End System (1.3.6.1.5.5.7.3.5)
      • IPSec Tunnel (1.3.6.1.5.5.7.3.6)
      • IPSec User (1.3.6.1.5.5.7.3.7)
      • OCSP Signing (1.3.6.1.5.5.7.3.9)
  6. Save your agent settings.
  7. Push the Prisma Agent configuration to apply the changes to endpoints.