<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic check_point.gaia config ssl tls not available in Ansible</title>
    <link>https://community.checkpoint.com/t5/Ansible/check-point-gaia-config-ssl-tls-not-available/m-p/245563#M840</link>
    <description>&lt;P&gt;In clish we can set tlsv1.3 with&lt;/P&gt;
&lt;LI-CODE lang="javascript"&gt;set ssl tls TLSv1.3 on&lt;/LI-CODE&gt;
&lt;P&gt;With ansible or nativ API this is not possible.&lt;/P&gt;
&lt;P&gt;Have I overlooked this in the documentation or is there no API-first strategy in Check Point?&lt;BR /&gt;And&amp;nbsp;check_point.gaia.cp_gaia_run_script is not API-first....&lt;/P&gt;</description>
    <pubDate>Thu, 03 Apr 2025 11:55:15 GMT</pubDate>
    <dc:creator>Daniel_</dc:creator>
    <dc:date>2025-04-03T11:55:15Z</dc:date>
    <item>
      <title>check_point.gaia config ssl tls not available</title>
      <link>https://community.checkpoint.com/t5/Ansible/check-point-gaia-config-ssl-tls-not-available/m-p/245563#M840</link>
      <description>&lt;P&gt;In clish we can set tlsv1.3 with&lt;/P&gt;
&lt;LI-CODE lang="javascript"&gt;set ssl tls TLSv1.3 on&lt;/LI-CODE&gt;
&lt;P&gt;With ansible or nativ API this is not possible.&lt;/P&gt;
&lt;P&gt;Have I overlooked this in the documentation or is there no API-first strategy in Check Point?&lt;BR /&gt;And&amp;nbsp;check_point.gaia.cp_gaia_run_script is not API-first....&lt;/P&gt;</description>
      <pubDate>Thu, 03 Apr 2025 11:55:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Ansible/check-point-gaia-config-ssl-tls-not-available/m-p/245563#M840</guid>
      <dc:creator>Daniel_</dc:creator>
      <dc:date>2025-04-03T11:55:15Z</dc:date>
    </item>
    <item>
      <title>Re: check_point.gaia config ssl tls not available</title>
      <link>https://community.checkpoint.com/t5/Ansible/check-point-gaia-config-ssl-tls-not-available/m-p/245627#M841</link>
      <description>&lt;P&gt;You are correct that the only way to do this currently is via run-script.&lt;BR /&gt;Hopefully this is something we will address in a future release.&lt;/P&gt;
&lt;P&gt;API-first implies that the product was designed &lt;EM&gt;&lt;STRONG&gt;from the ground up&lt;/STRONG&gt;&lt;/EM&gt; with the relevant APIs.&lt;BR /&gt;The Check Point security gateway product (called FireWall-1 in 1993) predates REST APIs themselves (which were &lt;A href="https://readme.com/resources/the-history-of-rest-apis" target="_blank"&gt;only a concept back in 2000&lt;/A&gt;).&lt;BR /&gt;We have our own APIs (&lt;A href="https://support.checkpoint.com/results/sk/sk63026" target="_self"&gt;OPSEC&lt;/A&gt;) that date back to the mid-1990, some of which are still in use today.&lt;/P&gt;
&lt;P&gt;For new features, we definitely try to be API-first, of course (using REST).&lt;BR /&gt;Existing features either have to have REST APIs implemented for them (which we are continuing to do in every release) and/or be re-implemented in a REST API friendly way.&lt;BR /&gt;This was at least part of the motivation for VSnext (replacement for VSX) and ElasticXL (replacement for ClusterXL) in the R82 release.&lt;BR /&gt;It's also why &lt;A href="https://support.checkpoint.com/results/sk/sk170314" target="_self"&gt;Web SmartConsole&lt;/A&gt; still has some limitations compared to the Windows SmartConsole client, though there is currently a major effort underway to close the gaps between the two.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Apr 2025 16:21:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Ansible/check-point-gaia-config-ssl-tls-not-available/m-p/245627#M841</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-04-03T16:21:00Z</dc:date>
    </item>
  </channel>
</rss>

