<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AppSec, certificate issues. in WAF</title>
    <link>https://community.checkpoint.com/t5/WAF/AppSec-certificate-issues/m-p/165168#M105</link>
    <description>&lt;P&gt;Hey,&lt;/P&gt;
&lt;P&gt;The wildcard is supported, so I don't think this can mess things up.&lt;BR /&gt;It is weird, but, my rule is: if it works, don't touch&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":zipper_mouth_face:"&gt;🤐&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Did you double check that the correct tag is attached with the correct ARN?&lt;/P&gt;</description>
    <pubDate>Wed, 14 Dec 2022 13:01:41 GMT</pubDate>
    <dc:creator>yuvalmamka</dc:creator>
    <dc:date>2022-12-14T13:01:41Z</dc:date>
    <item>
      <title>AppSec, certificate issues.</title>
      <link>https://community.checkpoint.com/t5/WAF/AppSec-certificate-issues/m-p/165139#M96</link>
      <description>&lt;P&gt;We have set up the AppSec solution, running on a couple of machines in AWS. (we used the cloud formation template). We got it up an running fine, and went trough the setup of getting certificates from the AWS cert store.&lt;/P&gt;
&lt;P&gt;We set up our first website, and everything was working, I see the logs verify that we get the certificate from the AWS store.. everything i all ok ! It was a pretty straight forward setup and workes fine for that one site..&lt;/P&gt;
&lt;P&gt;Then, after some time we where adding in a few more sites with different certificates. We did exactly the same.. no changes in IAM roles.. Same as before. (we did it several times, since we thought we did something wrong)&lt;/P&gt;
&lt;P&gt;But we keep getting errors:&lt;/P&gt;
&lt;P&gt;{"eventTime": "2022-12-09T08:04:31.677","eventName": "The AppSec Gateway's certificate for URL '&amp;lt;&lt;A href="https://xxx.xxxx.xxx.xxx.xxxx" target="_blank"&gt;https://xxx.xxxx.xxx.xxx.xxxx&lt;/A&gt;&amp;gt;' could not be found in cloud certificate store","eventSeverity": "Critical",&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;{"logIndex": 8,"eventRemediation": "Verify the relevant certificate exists in the appropriate location. error: &amp;lt;Host xx.xxxx.com could not be matched to any of the certificates&amp;gt;","eventObject": &lt;BR /&gt;{"notificationConsumerData": {"certificationStatusNotificationConsumers": {"assetId": "xxxxxa-c145-xx8c-53d6-xxxxxxx2c","profileId": "42xxxx3-2362-5xxx-498b-1xxxxxce","certType": "Aws","url": &lt;BR /&gt;"&lt;A href="https://xxx.xxx.xxx.xxx" target="_blank"&gt;https://xxx.xxx.xxx.xxx&lt;/A&gt;","message": "The AppSec Gateway's certificate for URL '&amp;lt;&lt;A href="https://xx.x.x.xx.xxx.xx" target="_blank"&gt;https://xx.x.x.xx.xxx.xx&lt;/A&gt;&amp;gt;' &lt;BR /&gt;could not be found in cloud certificate store"}}},"notificationId": "41xxxb1-e9bc-4xxx3-8xxb-xxxxxxxxb"}}&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The event viewer in the Infinity portal also tells me to check the IAM roles.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The thing is, that we have gone trough this several times. And we have also brought in consultants on certificates and IAM in AWS. We are totaly unable to find anything wrong. (in addition we have restarted services, rebootet the servers...)&lt;/P&gt;
&lt;P&gt;Refering to the APP Sec documentation, we do get a few commands relating to cpnano - but can anyone tell me if there is some place that describes a bit more advanced tshoot method ? Or - even better, has anyone had same issue ?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To note.. the original site we got working - is still working. We have also reached out to Check Point and is waiting for a remote session.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Dec 2022 10:39:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/WAF/AppSec-certificate-issues/m-p/165139#M96</guid>
      <dc:creator>vinceneil666</dc:creator>
      <dc:date>2022-12-14T10:39:59Z</dc:date>
    </item>
    <item>
      <title>Re: AppSec, certificate issues.</title>
      <link>https://community.checkpoint.com/t5/WAF/AppSec-certificate-issues/m-p/165145#M97</link>
      <description>&lt;P&gt;I read your post carefully and here is my logic on this. Im not by any means AWS cloud expert at all, but based on error you indicated&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;"The AppSec Gateway's certificate for URL '&amp;lt;&lt;/SPAN&gt;&lt;A href="https://xxx.xxxx.xxx.xxx.xxxx/" target="_blank" rel="nofollow noopener noreferrer"&gt;https://xxx.xxxx.xxx.xxx.xxxx&lt;/A&gt;&lt;SPAN&gt;&amp;gt;' could not be found in cloud certificate store","eventSeverity": "Critical",&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;to me, that clearly complains that it cannot locate the proper cert anywhere. Now, I know you said you guys broght in consultant to check on this, but can you maybe verify where the cert is located for the initial site that does work?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Dec 2022 11:23:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/WAF/AppSec-certificate-issues/m-p/165145#M97</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-12-14T11:23:21Z</dc:date>
    </item>
    <item>
      <title>Re: AppSec, certificate issues.</title>
      <link>https://community.checkpoint.com/t5/WAF/AppSec-certificate-issues/m-p/165146#M98</link>
      <description>&lt;P&gt;Hey,&lt;/P&gt;
&lt;P&gt;Do the other certificates contain SAN (Subject Alternative Name)?&lt;BR /&gt;AppSec is using SAN to fetch the relevant certificate to the correct asset.&lt;/P&gt;
&lt;P&gt;You can also try to run &lt;A href="https://appsec-doc.inext.checkpoint.com/getting-started/deploy-enforcement-point/gateway-virtual-machine/aws/store-certificates-on-the-appsec-gateway" target="_self"&gt;CertVerify&lt;/A&gt; on the certificate and understand from the outcome if there is an issue with the certificate itself.&lt;/P&gt;
&lt;P&gt;I would also check that the correct tag is in place with the correct ARN.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Dec 2022 11:27:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/WAF/AppSec-certificate-issues/m-p/165146#M98</guid>
      <dc:creator>yuvalmamka</dc:creator>
      <dc:date>2022-12-14T11:27:45Z</dc:date>
    </item>
    <item>
      <title>Re: AppSec, certificate issues.</title>
      <link>https://community.checkpoint.com/t5/WAF/AppSec-certificate-issues/m-p/165147#M99</link>
      <description>&lt;P&gt;yes, we have done this. And its where its supposed to be, and where the new ones are. Also we keep refering to:&lt;BR /&gt;&lt;A href="https://appsec-doc.inext.checkpoint.com/getting-started/deploy-enforcement-point/gateway-virtual-machine/aws/store-certificates-in-aws" target="_blank"&gt;https://appsec-doc.inext.checkpoint.com/getting-started/deploy-enforcement-point/gateway-virtual-machine/aws/store-certificates-in-aws&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;The error message is pretty clear, so I do agree - might be a typo somewhere or something. But we have been trough it 4 times now..&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Dec 2022 11:27:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/WAF/AppSec-certificate-issues/m-p/165147#M99</guid>
      <dc:creator>vinceneil666</dc:creator>
      <dc:date>2022-12-14T11:27:10Z</dc:date>
    </item>
    <item>
      <title>Re: AppSec, certificate issues.</title>
      <link>https://community.checkpoint.com/t5/WAF/AppSec-certificate-issues/m-p/165148#M100</link>
      <description>&lt;P&gt;Thank you for the tip - I will get that checked asap !&lt;/P&gt;</description>
      <pubDate>Wed, 14 Dec 2022 11:29:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/WAF/AppSec-certificate-issues/m-p/165148#M100</guid>
      <dc:creator>vinceneil666</dc:creator>
      <dc:date>2022-12-14T11:29:39Z</dc:date>
    </item>
    <item>
      <title>Re: AppSec, certificate issues.</title>
      <link>https://community.checkpoint.com/t5/WAF/AppSec-certificate-issues/m-p/165149#M101</link>
      <description>&lt;P&gt;Ok, fair enough! Maybe follow what&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/80409"&gt;@yuvalmamka&lt;/a&gt;&amp;nbsp;sent, that looks promising.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 14 Dec 2022 11:30:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/WAF/AppSec-certificate-issues/m-p/165149#M101</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-12-14T11:30:02Z</dc:date>
    </item>
    <item>
      <title>Re: AppSec, certificate issues.</title>
      <link>https://community.checkpoint.com/t5/WAF/AppSec-certificate-issues/m-p/165150#M102</link>
      <description>&lt;P&gt;hi,&lt;/P&gt;
&lt;P&gt;So the site that is working has a wildcard cert - so that one does not have a SAN.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The site that is not working, do have a SAN.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Dec 2022 11:38:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/WAF/AppSec-certificate-issues/m-p/165150#M102</guid>
      <dc:creator>vinceneil666</dc:creator>
      <dc:date>2022-12-14T11:38:54Z</dc:date>
    </item>
    <item>
      <title>Re: AppSec, certificate issues.</title>
      <link>https://community.checkpoint.com/t5/WAF/AppSec-certificate-issues/m-p/165155#M103</link>
      <description>&lt;P&gt;Well, thats interesting that wildcard cert would work...how many hostnames are protected by the cert for the site thats failing?&lt;/P&gt;</description>
      <pubDate>Wed, 14 Dec 2022 11:59:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/WAF/AppSec-certificate-issues/m-p/165155#M103</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-12-14T11:59:50Z</dc:date>
    </item>
    <item>
      <title>Re: AppSec, certificate issues.</title>
      <link>https://community.checkpoint.com/t5/WAF/AppSec-certificate-issues/m-p/165156#M104</link>
      <description>&lt;P&gt;The wildcard is, as of now, protecting two sites.&lt;BR /&gt;Then I have two sites, with two different certs, that are both failing.&lt;/P&gt;
&lt;P&gt;Could it be the use of the wildcard that messes things up ? I have considered removing it... (we are not in production yet for these sites.)&lt;/P&gt;</description>
      <pubDate>Wed, 14 Dec 2022 12:05:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/WAF/AppSec-certificate-issues/m-p/165156#M104</guid>
      <dc:creator>vinceneil666</dc:creator>
      <dc:date>2022-12-14T12:05:34Z</dc:date>
    </item>
    <item>
      <title>Re: AppSec, certificate issues.</title>
      <link>https://community.checkpoint.com/t5/WAF/AppSec-certificate-issues/m-p/165168#M105</link>
      <description>&lt;P&gt;Hey,&lt;/P&gt;
&lt;P&gt;The wildcard is supported, so I don't think this can mess things up.&lt;BR /&gt;It is weird, but, my rule is: if it works, don't touch&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":zipper_mouth_face:"&gt;🤐&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Did you double check that the correct tag is attached with the correct ARN?&lt;/P&gt;</description>
      <pubDate>Wed, 14 Dec 2022 13:01:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/WAF/AppSec-certificate-issues/m-p/165168#M105</guid>
      <dc:creator>yuvalmamka</dc:creator>
      <dc:date>2022-12-14T13:01:41Z</dc:date>
    </item>
    <item>
      <title>Re: AppSec, certificate issues.</title>
      <link>https://community.checkpoint.com/t5/WAF/AppSec-certificate-issues/m-p/165182#M106</link>
      <description>&lt;P&gt;I assumed that this was the tags in the Secrets Manager in AWS ? - if so, yes, those are verified.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Dec 2022 14:16:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/WAF/AppSec-certificate-issues/m-p/165182#M106</guid>
      <dc:creator>vinceneil666</dc:creator>
      <dc:date>2022-12-14T14:16:28Z</dc:date>
    </item>
    <item>
      <title>Re: AppSec, certificate issues.</title>
      <link>https://community.checkpoint.com/t5/WAF/AppSec-certificate-issues/m-p/165184#M107</link>
      <description>&lt;P&gt;Ok, so apart from SAN and one being wildcard cert, you guys dont see any other differences?&lt;/P&gt;</description>
      <pubDate>Wed, 14 Dec 2022 14:56:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/WAF/AppSec-certificate-issues/m-p/165184#M107</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-12-14T14:56:54Z</dc:date>
    </item>
    <item>
      <title>Re: AppSec, certificate issues.</title>
      <link>https://community.checkpoint.com/t5/WAF/AppSec-certificate-issues/m-p/165185#M108</link>
      <description>&lt;P&gt;Yes. Ok, so it looks weird according to what you described.&lt;/P&gt;
&lt;P&gt;Let's look further into it tomorrow on the remote session that you scheduled.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Dec 2022 14:43:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/WAF/AppSec-certificate-issues/m-p/165185#M108</guid>
      <dc:creator>yuvalmamka</dc:creator>
      <dc:date>2022-12-14T14:43:02Z</dc:date>
    </item>
    <item>
      <title>Re: AppSec, certificate issues.</title>
      <link>https://community.checkpoint.com/t5/WAF/AppSec-certificate-issues/m-p/165793#M112</link>
      <description>&lt;P&gt;So TAC got this resolved, and it came down to the tag in AWS secrets manager was written as "Private Key", not as "private key" - this actually created a world of problems, crashing the reverse proxy running on the app sec. Tnx to TAC for the major digging that was needed to figure that out.. and a fix that's probably on the way very soon ! &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Dec 2022 14:05:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/WAF/AppSec-certificate-issues/m-p/165793#M112</guid>
      <dc:creator>vinceneil666</dc:creator>
      <dc:date>2022-12-21T14:05:28Z</dc:date>
    </item>
    <item>
      <title>Re: AppSec, certificate issues.</title>
      <link>https://community.checkpoint.com/t5/WAF/AppSec-certificate-issues/m-p/165831#M113</link>
      <description>&lt;P&gt;Hmm&amp;nbsp; - Nice learning for us as well. I set all appsec on my customized nginx reverse proxy and using nginx nano agent hence managing the certs on my Rev Proxy box.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Dec 2022 03:24:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/WAF/AppSec-certificate-issues/m-p/165831#M113</guid>
      <dc:creator>Blason_R</dc:creator>
      <dc:date>2022-12-22T03:24:02Z</dc:date>
    </item>
  </channel>
</rss>

