Hey Guys,
Currently we are trying to do Certificate authentication with global Protect. We have a mixed Catalina and Mojave environment with GP 5.1.1 and currently our portal and network is setup for user and machine auth. We are using OneLogin for 2FA and our machines our not bound to AD. We are getting an issue when our machines are logging in where it is asking our users for access to the keychain 3 times. I haven't seen a script out there that will allow for us to bypass this and Palo offers this manual workaround but I don't know how to script this out. The Palo portal is going to the Private Key in the Keychain and for some reason we cannot make the PanGPS stick and Always Allow doesn't show up like in the below URL. We have Gatekeeper and Personal Firewalls enabled.
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClkECAS
Can anyone possibly look at this and give me some advice on what to do?
