Create a certificate profile to define user and device authentication settings for
Authentication Portal, multi-factor authentication, GlobalProtect, and other
services.
Certificate profiles define user and device authentication for Authentication
Portal, multi-factor authentication (MFA), GlobalProtect, site-to-site IPSec VPN,
external dynamic list validation, dynamic DNS (DDNS), User-ID agent and TS agent
access, and web interface access to Palo Alto Networks firewalls or Panorama. The
profiles specify which certificates to use, how to verify certificate revocation
status, and how that status constrains access. Configure a certificate profile for
each application.
Enable Online Certificate Status Protocol
(OCSP) and certificate revocation list (CRL) status verification in certificate
profiles to verify that a certificate hasn’t been revoked. Enable both OCSP and CRL
so that if the OCSP server isn’t available, the firewall uses CRL. For details on
these methods, see
Certificate Revocation.