Zscaler ZTNA – Certificate Based Device Posture

Introduction

Zscaler Private Access (ZPA) can use device posture checks to verify that a device meets security requirements before granting access to protected applications. One supported posture criterion is a Client Certificate, which validates that the device presents a trusted client certificate during posture evaluation.

This integration uses a JoinNow-issued X.509 client certificate as the Client Certificate device posture check. JoinNow issues the certificate through Dynamic PKI, and Zscaler is configured to trust the issuing JoinNow Certificate Authority (CA). During posture evaluation, Zscaler Client Connector verifies that the device presents a valid certificate issued by the trusted CA. A ZPA access policy can then require this posture check to pass before access to protected applications is granted. 

This document describes how to configure a JoinNow-issued certificate as a Client Certificate device posture check in Zscaler Private Access.

Prerequisites

The following are required to configure this integration:

  1. An active subscription with the JoinNow Management Platform.
  2. An active Zscaler Private Access (ZPA) subscription with Device Posture Profiles enabled.

Integrating SecureW2 with Zscaler ZTNA

At a high level, there are two points of configuration:

  1. Configuring SecureW2 issues an X.509 client certificate to the device and makes the issuing CA available to upload into Zscaler.
  2. Configuring Zscaler trusts that CA, checks for the certificate as a device posture signal, and gates ZTNA access on that posture check.

Configuring SecureW2

This section covers creating the Intermediate CA and the certificate template used to issue the client certificate, delivering the certificate to the device, and exporting the CA so Zscaler can trust it.

Creating an Intermediate CA

SecureW2 recommends configuring a dedicated Intermediate CA for this integration, so it can be identified and managed separately from other Certificate Authorities (CAs).

To create a new Intermediate CA, perform the following steps:

  1. Log in to the JoinNow Management Portal.
  2. Navigate to Dynamic PKI > Certificate Authorities.
  3. Click Add Certificate Authority.
  4. In the Basic section, from the Generate CA For drop-down list, select the Device and User Authentication option to authenticate devices.
  5. From the Type drop-down list, select Intermediate CA. 
  6. From the Certificate Authority drop-down list, select the default Root CA provided by your organization.
  7. For the Common Name field, enter a name that identifies this CA. 
  8. From the Key Size drop-down list, select 2048 for the CA certificate key pair. 
  9. From the Signature Algorithm drop-down list, select the signature algorithm for the certificate signing request. The option available is SHA-256.
  10. In the Validity Period field, enter the validity period for the Intermediate CA in terms of the number of years.
  11. In the Notifications section:
    1. From the Expiry Notification Frequency (in days) drop-down list, select the frequency interval for which a certificate expiration notification should be sent to users.
    2. Select the Notify user on successful Enrollment checkbox to notify users after enrollment.
  12. In the Revocation section:
    1. In the Revoke Certificate if unused for field, select the number of days after which an unused certificate can be revoked.
      1. Since last usage – Select this checkbox to revoke the certificate after a specified number of days if it remains unused.
      2. Since certificate issuance – Select this checkbox to revoke the certificate after a specified number of days after it is issued.
    2. From the Reason Code drop-down list, select any one of the following reasons for which the certificate is revoked. 
      1. Certificate Hold
      2. AA Compromise
      3. Privilege Withdrawn
      4. Unspecified
  13. Click Save. This generates the new intermediate CA.

Creating a Certificate Template

A certificate template defines how information is encoded in a certificate issued by the Certificate Authority (CA).

To create a certificate template, perform the following steps:

  1. Navigate to Dynamic PKI > Certificate Authorities.
  2. Scroll to the Certificate Templates section and click Add Certificate Template.
  3. In the Basic section, enter the name of the certificate template in the Name field.
  4. In the Subject field, retain the default value CN=${/auth/displayName:/device/identity:/csr/subject/commonname}. 
  5. In the Display Description field, enter a suitable description for the certificate template.
  6. In the Validity Period field, type the validity period of the certificate (based on the requirement).
  7. To override the Validity Period attribute, select the Override Validity Period checkbox and choose an end date from the date picker to set a hard-coded expiry date for a certificate.
  8. From the Signature Algorithm drop-down list, select SHA-256 as the signature algorithm for the certificate signing request. 
  9. In the SAN section, retain the default values unless your organization requires a specific Subject Alternative Name format.
  10. In the Extended Key Usage section, from the Use Certificate For list, select Client Authentication. This is required for Zscaler to accept the certificate as a client certificate during posture evaluation.
  11. In the Notification section, select the Notify admin on certificate expiry checkbox to send certificate expiry email notifications to all Admins.
  12. Click Save.

Creating a Client Certificate

After creating the Intermediate CA and Certificate Template, create a client certificate. This certificate is installed on the endpoint and is used by Zscaler Client Connector during device posture evaluation.

To create a client certificate, perform the following steps:

  1. Navigate to Dynamic PKI > Create Certificate.
  2. In the Device Info section, select the device’s operating system from the Operating System drop-down list.
  3. In the Certificate Signing Request section: 
    1. Select Generate Keypair and CSR.
    2. In the Subject field, type the client certificate’s common name of the Client Certificate.
  4. In the Certificate Issuance Policy section:
    1. From the Certificate Authority drop-down list, select the Intermediate CA created in the Creating an Intermediate CA section.
    2. From the Use Certificate Template drop-down list, select the Client Template created in the Creating a Certificate Template section.
    3. Select the Include Entire Certificate Chain option.
  5. In the Distribution section:
    1. In the Format field, select PEM.
    2. In the Receive via field, select Download.
  6. Click Create.

After the client certificate is created, deploy it to the target endpoints. The client certificate must be installed in the device’s certificate store before Zscaler Client Connector can validate the device using the configured Client Certificate posture profile.

Exporting the CA Certificate

Zscaler needs a copy of the CA certificate to validate that a device’s client certificate chains up to a CA it trusts.

To export the CA certificate, perform the following steps:

  1. Navigate to Dynamic PKI > Certificate Authorities.
  2. Select the Intermediate CA created in the Creating an Intermediate CA section and download the CA certificate.

Configuring Zscaler

Creating a Device Posture Profile for the SecureW2 Certificate

A Device Posture Profile defines the criteria Zscaler Client Connector evaluates on a device. For the Client Certificate posture type, the CA certificate is uploaded directly as part of creating the profile. There is no separate certificate-upload step beforehand.

To create the Device Posture Profile, perform the following steps:

  1. From the Authentication Service landing page, click Zscaler Client Connector.
  2. In the left navigation, click Administration and select Device Posture.
  3. Click Add Device Posture.
  4. Configure the posture profile:
    1. In the Name field, enter a name for the posture profile.
    2. Under PLATFORM, enable the toggle for each platform this profile applies to.
    3. From the Posture Type drop-down list, select Client Certificate.
    4. From the Frequency (In Minutes) drop-down list, select how often the posture check is re-evaluated.
    5. Under Certificate, click Upload and select the SecureW2 CA certificate exported in the Exporting the CA Certificate section, so Zscaler knows which issuing CA to trust.
    6. Click Save.

Applying the Device Posture Profile to a ZPA Access Policy

With the posture profile created, apply it to a ZPA access policy so that ZTNA access to private applications is conditioned on the device presenting a valid SecureW2 certificate.

To apply the Device Posture Profile to an access policy, perform the following steps:

  1. Navigate to Policy > Access Policies.
  2. Select an existing access policy rule, or create a new one for the application(s) this posture check should protect.
  3. Under Conditions, add a Posture Profile condition set and select the profile created in the Creating a Device Posture Profile for the SecureW2 Certificate section.
  4. Set the profile’s expected result to VERIFIED (the device must pass the check) — or VERIFICATION FAILED, if building a rule that explicitly blocks devices that fail it.
  5. Set the rule Action to Allow for devices that satisfy the condition (and, if desired, add a separate rule to explicitly deny devices that do not).
  6. Save and activate the policy.

Verifying the ZTNA Certificate Posture Integration

To validate the integration, perform the following steps:

  1. On a test device without the SecureW2-issued certificate installed, attempt to access a protected application through Zscaler Client Connector and confirm that access is denied or that the device shows as failing the posture check.
  2. Deliver the SecureW2-issued certificate to the same device.
  3. Wait for Zscaler Client Connector to re-evaluate device posture (up to approximately 15 minutes), or trigger a manual re-check if supported.
  4. Confirm the device now shows as passing the SecureW2 ZTNA Certificate Posture check and is granted access to the protected application.