<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Event Forwarding Manager Cloud in Portal</title>
    <link>https://community.checkpoint.com/t5/Portal/Event-Forwarding-Manager-Cloud/m-p/158236#M109</link>
    <description>&lt;P&gt;We're talking about the CA key, right?&lt;BR /&gt;That comes from whoever the Certificate Authority is, which should&amp;nbsp;be able to provide you the public key along with all the intermediate public certificates you need.&lt;/P&gt;</description>
    <pubDate>Tue, 27 Sep 2022 21:16:40 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2022-09-27T21:16:40Z</dc:date>
    <item>
      <title>Event Forwarding Manager Cloud</title>
      <link>https://community.checkpoint.com/t5/Portal/Event-Forwarding-Manager-Cloud/m-p/158068#M102</link>
      <description>&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Hello,&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;I'm trying to use the "EventForwarding" configuration to send the logs to my siem, but I'm having problems with the certificate.&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;I entered my company's .crt and .pem certificates, but last step it always complains that the CA is invalid.&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;What could I be doing wrong or what's missing?&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Thanks!&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Sep 2022 18:13:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Portal/Event-Forwarding-Manager-Cloud/m-p/158068#M102</guid>
      <dc:creator>itguerreiro</dc:creator>
      <dc:date>2022-09-26T18:13:10Z</dc:date>
    </item>
    <item>
      <title>Re: Event Forwarding Manager Cloud</title>
      <link>https://community.checkpoint.com/t5/Portal/Event-Forwarding-Manager-Cloud/m-p/158114#M103</link>
      <description>&lt;P&gt;Could you please share the actual error and more details about the SIEM in use?&lt;/P&gt;</description>
      <pubDate>Tue, 27 Sep 2022 07:17:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Portal/Event-Forwarding-Manager-Cloud/m-p/158114#M103</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-09-27T07:17:15Z</dc:date>
    </item>
    <item>
      <title>Re: Event Forwarding Manager Cloud</title>
      <link>https://community.checkpoint.com/t5/Portal/Event-Forwarding-Manager-Cloud/m-p/158156#M104</link>
      <description>&lt;P&gt;Hi ,&amp;nbsp;Thanks for your interaction.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Actually I'm trying to send the logs to my current syslog server, it's not a siem.&amp;nbsp;I tried to follow the step by step of the link&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/Infinity-Portal-Admin-Guide/Content/Topics-Infinity-Portal/Event-Forwarding.htm?tocpath=Global%20Settings%7CEvent%20Forwarding%7C_____0#Event_Forwarding" target="_blank" rel="noopener"&gt;https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/Infinity-Portal-Admin-Guide/Content/Topics-Infinity-Portal/Event-Forwarding.htm?tocpath=Global%20Settings%7CEvent%20Forwarding%7C_____0#Event_Forwarding&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;But I'm having difficulties in step 3, I tried to insert my company's certificate, but when it goes to CA validate it says it's not valid.&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;It is not very clear in this link the step by step.&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Could you help me in a more didactic way?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks!!!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Sep 2022 12:17:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Portal/Event-Forwarding-Manager-Cloud/m-p/158156#M104</guid>
      <dc:creator>itguerreiro</dc:creator>
      <dc:date>2022-09-27T12:17:40Z</dc:date>
    </item>
    <item>
      <title>Re: Event Forwarding Manager Cloud</title>
      <link>https://community.checkpoint.com/t5/Portal/Event-Forwarding-Manager-Cloud/m-p/158216#M105</link>
      <description>&lt;P&gt;Is your CA key a root or is it a sub-CA signed by a different CA?&lt;BR /&gt;In that case, I suspect you will need to include all the intermediate certificates to ensure we can validate the entire trust chain.&lt;/P&gt;</description>
      <pubDate>Tue, 27 Sep 2022 17:48:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Portal/Event-Forwarding-Manager-Cloud/m-p/158216#M105</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-09-27T17:48:00Z</dc:date>
    </item>
    <item>
      <title>Re: Event Forwarding Manager Cloud</title>
      <link>https://community.checkpoint.com/t5/Portal/Event-Forwarding-Manager-Cloud/m-p/158219#M106</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;thanks!!&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Where do I process the request to download client certificate?&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;I have to sue on my third party.&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;like for example godday, thawte?&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Or should I do it on my local machine?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Sep 2022 17:55:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Portal/Event-Forwarding-Manager-Cloud/m-p/158219#M106</guid>
      <dc:creator>itguerreiro</dc:creator>
      <dc:date>2022-09-27T17:55:40Z</dc:date>
    </item>
    <item>
      <title>Re: Event Forwarding Manager Cloud</title>
      <link>https://community.checkpoint.com/t5/Portal/Event-Forwarding-Manager-Cloud/m-p/158221#M107</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Here's the image of the error I'm having.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Sep 2022 18:01:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Portal/Event-Forwarding-Manager-Cloud/m-p/158221#M107</guid>
      <dc:creator>itguerreiro</dc:creator>
      <dc:date>2022-09-27T18:01:23Z</dc:date>
    </item>
    <item>
      <title>Re: Event Forwarding Manager Cloud</title>
      <link>https://community.checkpoint.com/t5/Portal/Event-Forwarding-Manager-Cloud/m-p/158230#M108</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Please send me the details of you Infinity account to &lt;A href="mailto:liorm@checkpoint.com," target="_blank"&gt;liorm@checkpoint.com, &lt;/A&gt;and I will have someone take a look and get back to you.&lt;/P&gt;
&lt;P&gt;Lior&lt;/P&gt;</description>
      <pubDate>Tue, 27 Sep 2022 19:09:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Portal/Event-Forwarding-Manager-Cloud/m-p/158230#M108</guid>
      <dc:creator>Lior_Manor</dc:creator>
      <dc:date>2022-09-27T19:09:08Z</dc:date>
    </item>
    <item>
      <title>Re: Event Forwarding Manager Cloud</title>
      <link>https://community.checkpoint.com/t5/Portal/Event-Forwarding-Manager-Cloud/m-p/158236#M109</link>
      <description>&lt;P&gt;We're talking about the CA key, right?&lt;BR /&gt;That comes from whoever the Certificate Authority is, which should&amp;nbsp;be able to provide you the public key along with all the intermediate public certificates you need.&lt;/P&gt;</description>
      <pubDate>Tue, 27 Sep 2022 21:16:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Portal/Event-Forwarding-Manager-Cloud/m-p/158236#M109</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-09-27T21:16:40Z</dc:date>
    </item>
    <item>
      <title>Re: Event Forwarding Manager Cloud</title>
      <link>https://community.checkpoint.com/t5/Portal/Event-Forwarding-Manager-Cloud/m-p/158349#M110</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From what we understand with the command below, the "Private Key" of the CA is needed and we don't have it.&lt;/P&gt;&lt;P&gt;We do have the Public Key as you said, but we haven't identified how to get a Private Key from a CA.&lt;/P&gt;&lt;P&gt;Can we run the command in another way?&lt;/P&gt;&lt;P&gt;openssl x509 -req -in PORTAL.CSR -CA CA.PEM -CAkey CAPRIVATEKEY.key -CAcreateserial -out CERTOUT.CRT -days 825 -sha256&lt;/P&gt;</description>
      <pubDate>Wed, 28 Sep 2022 15:36:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Portal/Event-Forwarding-Manager-Cloud/m-p/158349#M110</guid>
      <dc:creator>itguerreiro</dc:creator>
      <dc:date>2022-09-28T15:36:13Z</dc:date>
    </item>
    <item>
      <title>Re: Event Forwarding Manager Cloud</title>
      <link>https://community.checkpoint.com/t5/Portal/Event-Forwarding-Manager-Cloud/m-p/158456#M111</link>
      <description>&lt;P&gt;Validation of a Certificate Authority does not require private keys.&lt;BR /&gt;However, it does require the public keys of any other CA that has signed your CA certificate.&lt;BR /&gt;Refer to the following example from this very website you're interacting with me on &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/17971i411841EB1466D0D2/image-size/medium?v=v2&amp;amp;px=400" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;To validate any certificate signed by DigiCert TLS RSA SHA256 2020 CA1, you also need the public key of DigiCert Global Root CA.&lt;BR /&gt;Unless your CA is a root, then we need all the public CAs in the certificate chain.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Sep 2022 14:35:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Portal/Event-Forwarding-Manager-Cloud/m-p/158456#M111</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-09-29T14:35:43Z</dc:date>
    </item>
  </channel>
</rss>

