<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Replace TLS cert in OpenTelemetry/Skyline</title>
    <link>https://community.checkpoint.com/t5/OpenTelemetry-Skyline/Replace-TLS-cert/m-p/200860#M264</link>
    <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/11958"&gt;@Arik_Ovtracht&lt;/a&gt;&amp;nbsp;can you please advise?&lt;/P&gt;</description>
    <pubDate>Mon, 18 Dec 2023 09:23:48 GMT</pubDate>
    <dc:creator>_Val_</dc:creator>
    <dc:date>2023-12-18T09:23:48Z</dc:date>
    <item>
      <title>Replace TLS cert</title>
      <link>https://community.checkpoint.com/t5/OpenTelemetry-Skyline/Replace-TLS-cert/m-p/200514#M262</link>
      <description>&lt;P&gt;Hello all,&lt;BR /&gt;&lt;BR /&gt;did someone already replace the TLS cert in skyline configuration?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;The certificate was changed on our Prometheus server.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Is it possible to use the&amp;nbsp;Issuing CA, and not the cert of the&amp;nbsp;&amp;nbsp;Prometheus server, in ther configuration?&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;PRE&gt;"enabled": true,
            "server-auth": {
                "ca-public-key": {
                    "type": "PEM-X509",
                    "value": "&lt;SPAN&gt;&amp;lt;CERTIFICATE&amp;gt;&lt;/SPAN&gt;"&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;BR /&gt;Or what would be the best way, if the certificate of Prometheus will replace every 2,5 years?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;What are the steps, if we need to replace the cerificate for the Skyline TLS configuration?&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Dec 2023 15:37:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/OpenTelemetry-Skyline/Replace-TLS-cert/m-p/200514#M262</guid>
      <dc:creator>Kolafer</dc:creator>
      <dc:date>2023-12-13T15:37:20Z</dc:date>
    </item>
    <item>
      <title>Re: Replace TLS cert</title>
      <link>https://community.checkpoint.com/t5/OpenTelemetry-Skyline/Replace-TLS-cert/m-p/200860#M264</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/11958"&gt;@Arik_Ovtracht&lt;/a&gt;&amp;nbsp;can you please advise?&lt;/P&gt;</description>
      <pubDate>Mon, 18 Dec 2023 09:23:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/OpenTelemetry-Skyline/Replace-TLS-cert/m-p/200860#M264</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2023-12-18T09:23:48Z</dc:date>
    </item>
    <item>
      <title>Re: Replace TLS cert</title>
      <link>https://community.checkpoint.com/t5/OpenTelemetry-Skyline/Replace-TLS-cert/m-p/200932#M266</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/58158"&gt;@Kolafer&lt;/a&gt;&amp;nbsp;, As far as I know the issuer CA should work on the GW itself, so it should prevent you from the need to do redeployment ( Assuming the Prometheus CA is signed by it ).&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regarding automatic deployment of certificates, there are some available solutions outside of CheckPoint, that can be used, but as this is out of scope of the CheckPoint support, I can share them, However I can't recommend to go to one or to the other.&amp;nbsp;For example,&amp;nbsp;CertBot or&amp;nbsp;&lt;A href="https://www.nginx.com/blog/automating-certificate-management-in-a-kubernetes-environment/" target="_self"&gt;kubernetes&lt;/A&gt;&amp;nbsp;based solutions.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Dec 2023 16:38:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/OpenTelemetry-Skyline/Replace-TLS-cert/m-p/200932#M266</guid>
      <dc:creator>Elad_Chomsky</dc:creator>
      <dc:date>2023-12-18T16:38:08Z</dc:date>
    </item>
    <item>
      <title>Re: Replace TLS cert</title>
      <link>https://community.checkpoint.com/t5/OpenTelemetry-Skyline/Replace-TLS-cert/m-p/201244#M267</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/11958"&gt;@Arik_Ovtracht&lt;/a&gt;&amp;nbsp;,&lt;BR /&gt;&lt;BR /&gt;can you advise here please?&lt;BR /&gt;&lt;BR /&gt;I created a new payloadjson and add the &lt;SPAN&gt;issuer CA of the&amp;nbsp;Prometheus server, after rerun the configuration again. But still not working.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I can see the certificate was added to the&amp;nbsp;certs/ca-bundle.crt.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;br&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;What are the right steps to replace the certificate on the gateway?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Dec 2023 23:12:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/OpenTelemetry-Skyline/Replace-TLS-cert/m-p/201244#M267</guid>
      <dc:creator>Kolafer</dc:creator>
      <dc:date>2023-12-20T23:12:15Z</dc:date>
    </item>
    <item>
      <title>Re: Replace TLS cert</title>
      <link>https://community.checkpoint.com/t5/OpenTelemetry-Skyline/Replace-TLS-cert/m-p/201259#M268</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/58158"&gt;@Kolafer&lt;/a&gt;&amp;nbsp;, Please open a support ticket to CheckPoint, so we can try to assist you directly.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Dec 2023 09:03:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/OpenTelemetry-Skyline/Replace-TLS-cert/m-p/201259#M268</guid>
      <dc:creator>Elad_Chomsky</dc:creator>
      <dc:date>2023-12-21T09:03:16Z</dc:date>
    </item>
  </channel>
</rss>

