<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: R80.10 GAiA Portal - Problems Importing already issued WILDCARD 2048 Certificate in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-10-GAiA-Portal-Problems-Importing-already-issued-WILDCARD/m-p/5291#M129</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;same thing, first it makes tcp/4444 then back to tcp/4434 and same error in chrome:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #646464; background-color: #f7f7f7;"&gt;NET::ERR_CERT_AUTHORITY_INVALID&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #646464; background-color: #f7f7f7;"&gt;I don't think this is the issue with cert but CA root cert on the box ... there is somewhere a conflict between the imported PEM's and p12 one by the GUI Platform Portal record editing SG and CA root somewhere ...&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #646464; background-color: #f7f7f7;"&gt;I did made the opsec root ca with Comodo CA - should I remove it or something ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #646464; background-color: #f7f7f7;"&gt;starting to get really persistent in order to solve that openssl crappy case ...&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 11 Aug 2017 21:24:21 GMT</pubDate>
    <dc:creator>Jerry</dc:creator>
    <dc:date>2017-08-11T21:24:21Z</dc:date>
    <item>
      <title>R80.10 GAiA Portal - Problems Importing already issued WILDCARD 2048 Certificate</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-10-GAiA-Portal-Problems-Importing-already-issued-WILDCARD/m-p/5277#M115</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #fafafa; font-size: 13px;"&gt;Hi folks&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #fafafa; font-size: 13px;"&gt;just a quick one but to some extent complicated thing: Little background though.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #fafafa; font-size: 13px;"&gt;1. R80.10 Standalone Appliance (all-in-one) as usual&lt;/SPAN&gt;&lt;BR style="color: #333333; background-color: #fafafa; font-size: 13px;" /&gt;&lt;SPAN style="color: #333333; background-color: #fafafa; font-size: 13px;"&gt;2. no PKI done for either VPN or MAB (MAB is not in use)&lt;/SPAN&gt;&lt;BR style="color: #333333; background-color: #fafafa; font-size: 13px;" /&gt;&lt;SPAN style="color: #333333; background-color: #fafafa; font-size: 13px;"&gt;3. Gaia Portal has typical per-ip Cert error when you try to log in - that's normal&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #fafafa; font-size: 13px;"&gt;Research:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #fafafa; font-size: 13px;"&gt;1. replace files at&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #fafafa; font-size: 13px;"&gt;/web/conf/server.crt&lt;/SPAN&gt;&lt;BR style="color: #333333; background-color: #fafafa; font-size: 13px;" /&gt;&lt;SPAN style="color: #333333; background-color: #fafafa; font-size: 13px;"&gt;/web/conf/server.key&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #fafafa; font-size: 13px;"&gt;with your own one from your *.domain.com set (received as issued with Public CA)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #fafafa; font-size: 13px;"&gt;based on sk109593&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #fafafa; font-size: 13px;"&gt;- result: Tomcat does not wake up at all making your GAIA portal unusable&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #fafafa; font-size: 13px;"&gt;2. replacing above files is not enough as long as your $CPDIR/conf/openssl.cnf has no CSR issued within the shell (of course not as the CSR was done separately on different device in order to make wildcard cert!)&lt;/SPAN&gt;&lt;BR style="color: #333333; background-color: #fafafa; font-size: 13px;" /&gt;&lt;SPAN style="color: #333333; background-color: #fafafa; font-size: 13px;"&gt;3. I see no path for importing wildcard cert without generating csr on particular appliance - do you?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #fafafa; font-size: 13px;"&gt;GOAL:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #fafafa; font-size: 13px;"&gt;1. have all GAIA portal(s) from each appliance within the network using same wildcard cert already in hand from Comodo.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #fafafa; font-size: 13px;"&gt;---&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #fafafa; font-size: 13px;"&gt;any ideas/tips/hints chaps?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #fafafa; font-size: 13px;"&gt;much appreciate your assistance as always (PhoneBoy especially) &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #fafafa; font-size: 13px;"&gt;Cheers&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #fafafa; font-size: 13px;"&gt;Jerry&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Aug 2017 17:23:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-10-GAiA-Portal-Problems-Importing-already-issued-WILDCARD/m-p/5277#M115</guid>
      <dc:creator>Jerry</dc:creator>
      <dc:date>2017-08-11T17:23:33Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 GAiA Portal - Problems Importing already issued WILDCARD 2048 Certificate</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-10-GAiA-Portal-Problems-Importing-already-issued-WILDCARD/m-p/5278#M116</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;$CPDIR/conf/openssl.cnf is not the correct file to edit here.&lt;/P&gt;&lt;P&gt;The actual config file read by the Gaia Web Portal is /web/conf/httpd2.conf&lt;/P&gt;&lt;P&gt;This file, however, is generated based off the files in /web/templates.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You might look in /var/log/httpd2_error_log to see what&amp;nbsp;the actual errors are.&lt;/P&gt;&lt;P&gt;That may help you change the config in /web/templates.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When you do that, you will need to restart the httpd process to have the necessary configuration files regenerated:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier, monospace;"&gt;[Expert@HostName]# &lt;STRONG&gt;tellpm process:httpd2&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier, monospace;"&gt;[Expert@HostName]# &lt;STRONG&gt;tellpm process:httpd2 t&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier, monospace;"&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Aug 2017 18:07:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-10-GAiA-Portal-Problems-Importing-already-issued-WILDCARD/m-p/5278#M116</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2017-08-11T18:07:46Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 GAiA Portal - Problems Importing already issued WILDCARD 2048 Certificate</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-10-GAiA-Portal-Problems-Importing-already-issued-WILDCARD/m-p/5279#M117</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks !&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'll try this and update you (all) due course&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jerry&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Aug 2017 18:10:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-10-GAiA-Portal-Problems-Importing-already-issued-WILDCARD/m-p/5279#M117</guid>
      <dc:creator>Jerry</dc:creator>
      <dc:date>2017-08-11T18:10:41Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 GAiA Portal - Problems Importing already issued WILDCARD 2048 Certificate</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-10-GAiA-Portal-Problems-Importing-already-issued-WILDCARD/m-p/5280#M118</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;funny enough is that I found following entry in template for httpd2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;UseCanonicalName Off&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;shouldn't that be On by any chance?&lt;/P&gt;&lt;P&gt;I'd love to import wildcard crt and key file with no CSR onto the /web/conf folder&lt;/P&gt;&lt;P&gt;If I do so httpd2 won't start or starts anyway but gives me no access go gaia claiming that the source of my cert is still 192.168.1.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;in a log there are all errors but nothing really saying anything in particular about the cert issues&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;any clues ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Aug 2017 18:19:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-10-GAiA-Portal-Problems-Importing-already-issued-WILDCARD/m-p/5280#M118</guid>
      <dc:creator>Jerry</dc:creator>
      <dc:date>2017-08-11T18:19:20Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 GAiA Portal - Problems Importing already issued WILDCARD 2048 Certificate</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-10-GAiA-Portal-Problems-Importing-already-issued-WILDCARD/m-p/5281#M119</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think I found the path's into the&amp;nbsp;httpd-ssl.conf.templ&lt;/P&gt;&lt;P&gt;if I modify this with my files from the /web/conf&lt;/P&gt;&lt;P&gt;would that work?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'll try all the options Dameon ...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;please let me know what you think digging it a little if you can...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Aug 2017 18:37:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-10-GAiA-Portal-Problems-Importing-already-issued-WILDCARD/m-p/5281#M119</guid>
      <dc:creator>Jerry</dc:creator>
      <dc:date>2017-08-11T18:37:06Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 GAiA Portal - Problems Importing already issued WILDCARD 2048 Certificate</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-10-GAiA-Portal-Problems-Importing-already-issued-WILDCARD/m-p/5282#M120</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In theory it should work.&lt;/P&gt;&lt;P&gt;You need to restart httpd2 as I mentioned above for the changes to take effect.&lt;/P&gt;&lt;P&gt;It should regenerate the files in /web/conf (easy to confirm).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Aug 2017 18:39:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-10-GAiA-Portal-Problems-Importing-already-issued-WILDCARD/m-p/5282#M120</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2017-08-11T18:39:00Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 GAiA Portal - Problems Importing already issued WILDCARD 2048 Certificate</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-10-GAiA-Portal-Problems-Importing-already-issued-WILDCARD/m-p/5283#M121</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ok so let's summarize what files need to be replaced in /web/conf folder&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;/web/conf/server.crt&lt;BR /&gt;/web/conf/server.key&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've got them replaced, also replaced one another:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SSLCertificateFile /usr/local/apache2/conf/server.crt&lt;BR /&gt;SSLCertificateKeyFile /usr/local/apache2/conf/server.key&lt;BR /&gt;#SSLCACertificateFile /usr/local/apache2/conf/ssl.crt/&lt;STRONG&gt;ca-bundle.crt&amp;nbsp;&lt;/STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;=&amp;gt; that one which is unique and does not exist in /web/conf (this file is the CA bundle file from Comodo)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--- still no joy &lt;img id="smileysad" class="emoticon emoticon-smileysad" src="https://community.checkpoint.com/i/smilies/16x16_smiley-sad.png" alt="Smiley Sad" title="Smiley Sad" /&gt;&lt;/P&gt;&lt;P&gt;- template points to above files whilst server.crt and .key is the alias which goes directly towards /web/conf where those files physically exist&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;... I'm like lost to be frank, none of my combinations works and still got the self-signed on GAIA&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ps. bear in mind that in a config file called&amp;nbsp;httpd-ssl.conf.templ I do gave a proper port this is listening on (4434). still no matter which files I've replace (having backups ofc in hand) - no joy&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;any clues ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Aug 2017 19:48:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-10-GAiA-Portal-Problems-Importing-already-issued-WILDCARD/m-p/5283#M121</guid>
      <dc:creator>Jerry</dc:creator>
      <dc:date>2017-08-11T19:48:04Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 GAiA Portal - Problems Importing already issued WILDCARD 2048 Certificate</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-10-GAiA-Portal-Problems-Importing-already-issued-WILDCARD/m-p/5284#M122</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;IMG alt="still same error ... any idea ?" class="image-1 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/57901_gaia.PNG" style="width: 620px; height: 711px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Aug 2017 19:50:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-10-GAiA-Portal-Problems-Importing-already-issued-WILDCARD/m-p/5284#M122</guid>
      <dc:creator>Jerry</dc:creator>
      <dc:date>2017-08-11T19:50:27Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 GAiA Portal - Problems Importing already issued WILDCARD 2048 Certificate</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-10-GAiA-Portal-Problems-Importing-already-issued-WILDCARD/m-p/5285#M123</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;also content of the responsible file&amp;nbsp;&lt;/P&gt;&lt;P&gt;[Expert@cp:0]# cat &lt;STRONG&gt;httpd-ssl.conf&lt;/STRONG&gt; | grep /usr/local/apache2/conf/&lt;BR /&gt;SSLCertificateFile /usr/local/apache2/conf/server.crt&lt;BR /&gt;#SSLCertificateFile /usr/local/apache2/conf/server-dsa.crt&lt;BR /&gt;SSLCertificateKeyFile /usr/local/apache2/conf/server.key&lt;BR /&gt;#SSLCertificateKeyFile /usr/local/apache2/conf/server-dsa.key&lt;BR /&gt;SSLCertificateChainFile /usr/local/apache2/conf/server-ca.crt&lt;BR /&gt;#SSLCACertificatePath /usr/local/apache2/conf/ssl.crt&lt;BR /&gt;#SSLCACertificateFile /usr/local/apache2/conf/ssl.crt/ca-bundle.crt&lt;BR /&gt;#SSLCARevocationPath /usr/local/apache2/conf/ssl.crl&lt;BR /&gt;#SSLCARevocationFile /usr/local/apache2/conf/ssl.crl/ca-bundle.crl&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;which makes me think if those files will be from Comodo CA wildcard Cert it should work - but it doesn't &lt;img id="smileysad" class="emoticon emoticon-smileysad" src="https://community.checkpoint.com/i/smilies/16x16_smiley-sad.png" alt="Smiley Sad" title="Smiley Sad" /&gt;&amp;nbsp;or I haven't un-hashed some important params myself ...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Aug 2017 19:52:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-10-GAiA-Portal-Problems-Importing-already-issued-WILDCARD/m-p/5285#M123</guid>
      <dc:creator>Jerry</dc:creator>
      <dc:date>2017-08-11T19:52:44Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 GAiA Portal - Problems Importing already issued WILDCARD 2048 Certificate</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-10-GAiA-Portal-Problems-Importing-already-issued-WILDCARD/m-p/5286#M124</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Did you uncomment&amp;nbsp;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;SSLCACertificateFile?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;Also did you verify /web/conf/httpd2.conf was updated appropriately after starting?&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Aug 2017 21:05:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-10-GAiA-Portal-Problems-Importing-already-issued-WILDCARD/m-p/5286#M124</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2017-08-11T21:05:14Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 GAiA Portal - Problems Importing already issued WILDCARD 2048 Certificate</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-10-GAiA-Portal-Problems-Importing-already-issued-WILDCARD/m-p/5287#M125</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;also found this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[Fri Aug 11 21:56:23.000114 2017] [ssl:warn] [pid 21458] AH01906: a.b.c.d:4434:0 server certificate is a CA certificate (BasicConstraints: CA == TRUE !?)&lt;BR /&gt;[Fri Aug 11 21:56:23.000151 2017] [ssl:warn] [pid 21458] AH01909: a.b.c.d:4434:0 server certificate does NOT include an ID which matches the server name&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think I've got an issue with CA Root ... but even OPSEC one I've got root from root CA ...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Aug 2017 21:07:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-10-GAiA-Portal-Problems-Importing-already-issued-WILDCARD/m-p/5287#M125</guid>
      <dc:creator>Jerry</dc:creator>
      <dc:date>2017-08-11T21:07:50Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 GAiA Portal - Problems Importing already issued WILDCARD 2048 Certificate</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-10-GAiA-Portal-Problems-Importing-already-issued-WILDCARD/m-p/5288#M126</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I did all this seeing no diff frankly ...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Aug 2017 21:08:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-10-GAiA-Portal-Problems-Importing-already-issued-WILDCARD/m-p/5288#M126</guid>
      <dc:creator>Jerry</dc:creator>
      <dc:date>2017-08-11T21:08:43Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 GAiA Portal - Problems Importing already issued WILDCARD 2048 Certificate</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-10-GAiA-Portal-Problems-Importing-already-issued-WILDCARD/m-p/5289#M127</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;changing&amp;nbsp;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;SSLCACertificateFile by unhashing it makes it even worse, httpd2 won't work&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;I think this is all about the proper CA root crt file somewhere ... so wired and annoying ...&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Aug 2017 21:14:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-10-GAiA-Portal-Problems-Importing-already-issued-WILDCARD/m-p/5289#M127</guid>
      <dc:creator>Jerry</dc:creator>
      <dc:date>2017-08-11T21:14:48Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 GAiA Portal - Problems Importing already issued WILDCARD 2048 Certificate</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-10-GAiA-Portal-Problems-Importing-already-issued-WILDCARD/m-p/5290#M128</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So restarting the daemon isn't enough.&lt;/P&gt;&lt;P&gt;Try using clish to change the port (e.g. set web ssl-port xxxx), then change it back to 4434.&lt;/P&gt;&lt;P&gt;That should force the file to be reread.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Aug 2017 21:14:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-10-GAiA-Portal-Problems-Importing-already-issued-WILDCARD/m-p/5290#M128</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2017-08-11T21:14:51Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 GAiA Portal - Problems Importing already issued WILDCARD 2048 Certificate</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-10-GAiA-Portal-Problems-Importing-already-issued-WILDCARD/m-p/5291#M129</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;same thing, first it makes tcp/4444 then back to tcp/4434 and same error in chrome:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #646464; background-color: #f7f7f7;"&gt;NET::ERR_CERT_AUTHORITY_INVALID&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #646464; background-color: #f7f7f7;"&gt;I don't think this is the issue with cert but CA root cert on the box ... there is somewhere a conflict between the imported PEM's and p12 one by the GUI Platform Portal record editing SG and CA root somewhere ...&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #646464; background-color: #f7f7f7;"&gt;I did made the opsec root ca with Comodo CA - should I remove it or something ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #646464; background-color: #f7f7f7;"&gt;starting to get really persistent in order to solve that openssl crappy case ...&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Aug 2017 21:24:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-10-GAiA-Portal-Problems-Importing-already-issued-WILDCARD/m-p/5291#M129</guid>
      <dc:creator>Jerry</dc:creator>
      <dc:date>2017-08-11T21:24:21Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 GAiA Portal - Problems Importing already issued WILDCARD 2048 Certificate</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-10-GAiA-Portal-Problems-Importing-already-issued-WILDCARD/m-p/5292#M130</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That's what it seems like to me as well.&lt;/P&gt;&lt;P&gt;Keep in mind there's the Gaia portal but there's also Multiportal, which is low-level infrastructure that allows the same IP/port to be used for multiple things (Gaia portal, SmartView, Mobile Access Blade, etc).&amp;nbsp;&lt;/P&gt;&lt;P&gt;Not sure which one is responsible in this specific case...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Aug 2017 22:35:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-10-GAiA-Portal-Problems-Importing-already-issued-WILDCARD/m-p/5292#M130</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2017-08-11T22:35:30Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 GAiA Portal - Problems Importing already issued WILDCARD 2048 Certificate</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-10-GAiA-Portal-Problems-Importing-already-issued-WILDCARD/m-p/5293#M131</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Can you please clarify regarding:&amp;nbsp;&lt;SPAN style="color: #333333; background-color: #fafafa;"&gt;Gaia Portal has typical per-ip Cert error when you try to log in - that's normal&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #fafafa; color: #333333;"&gt;2) Did you run 8-12 steps in&amp;nbsp;sk109593 (including &lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;RSA key)&lt;/SPAN&gt;? &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #fafafa; color: #333333;"&gt;The question is relevant to the state before all mentioned changes (in&amp;nbsp;&lt;SPAN style="background-color: #ffffff;"&gt;/web/templates)&amp;nbsp;&lt;/SPAN&gt;have done.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #fafafa; color: #333333;"&gt;The CSR step is require only once (wildcard) and by performing steps 8-12, it should be replaced correctly.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #fafafa; color: #333333;"&gt;Note: The CSR (which done once) need to be generated&amp;nbsp;according to the steps mentioned in&amp;nbsp;&lt;SPAN style="background-color: #fafafa;"&gt;sk109593.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 13 Aug 2017 13:02:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-10-GAiA-Portal-Problems-Importing-already-issued-WILDCARD/m-p/5293#M131</guid>
      <dc:creator>Or_Lindner</dc:creator>
      <dc:date>2017-08-13T13:02:19Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 GAiA Portal - Problems Importing already issued WILDCARD 2048 Certificate</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-10-GAiA-Portal-Problems-Importing-already-issued-WILDCARD/m-p/5294#M132</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Or&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;let me clarify then:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. I've done the csr_gen when on the same shell when I was generating CSR for CA in order to get the wildcard cert from them. the procedure I've followed is typical for mab utilization not gaia portal if that answers you question&lt;/P&gt;&lt;P&gt;2. I have followed all the steps of course &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&amp;nbsp;but see what phoneboy wrote to me yesterday here. he has the point !&lt;/P&gt;&lt;P&gt;3. csr can be generated on gaia for use within 2 different "places" - I've unfortunately done the one for httpd not httpd2 (gaia portal) I guess therefore my CSR generation for httpd2 cannot be done, otherwise I need to make it again from scratch loosing all the deployments I've done already with my existing since couple of days certificate.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;hope it all makes a little bit of sense now, if not - let me know I'm happy to run this with you&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ps. my original quest was "&lt;EM&gt;can I import entire either pfx or p12 or all of the pem files onto the gaia webserver folders in order to have gaia portal running already issued wildcard cert&lt;/EM&gt;".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jerry&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 13 Aug 2017 13:31:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-10-GAiA-Portal-Problems-Importing-already-issued-WILDCARD/m-p/5294#M132</guid>
      <dc:creator>Jerry</dc:creator>
      <dc:date>2017-08-13T13:31:33Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 GAiA Portal - Problems Importing already issued WILDCARD 2048 Certificate</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-10-GAiA-Portal-Problems-Importing-already-issued-WILDCARD/m-p/5295#M133</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jerry,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Can you please attach "phoneboy" answer? I didn't find it in this thread.&lt;/P&gt;&lt;P&gt;2) httpd2 is a symbolic link to httpd --&amp;gt; It's the same apache server.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 13 Aug 2017 14:47:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-10-GAiA-Portal-Problems-Importing-already-issued-WILDCARD/m-p/5295#M133</guid>
      <dc:creator>Or_Lindner</dc:creator>
      <dc:date>2017-08-13T14:47:08Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 GAiA Portal - Problems Importing already issued WILDCARD 2048 Certificate</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-10-GAiA-Portal-Problems-Importing-already-issued-WILDCARD/m-p/5296#M134</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;sure mate see below in sequence:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="color: #666666; background-color: #ffffff; font-weight: 300; font-size: 14px;"&gt;&lt;EM&gt;That's what it seems like to me as well.&lt;/EM&gt;&lt;/P&gt;&lt;P style="color: #666666; background-color: #ffffff; font-weight: 300; font-size: 14px;"&gt;&lt;EM&gt;Keep in mind there's the Gaia portal but there's also Multiportal, which is low-level infrastructure that allows the same IP/port to be used for multiple things (Gaia portal, SmartView, Mobile Access Blade, etc).&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;&lt;P style="color: #666666; background-color: #ffffff; font-weight: 300; font-size: 14px;"&gt;&lt;EM&gt;Not sure which one is responsible in this specific case...&lt;/EM&gt;&lt;/P&gt;&lt;P style="color: #666666; background-color: #ffffff; font-weight: 300; font-size: 14px;"&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;So restarting the daemon isn't enough.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Try using clish to change the port (e.g. set web ssl-port xxxx), then change it back to 4434.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;That should force the file to be reread.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="color: #666666; background-color: #ffffff; font-weight: 300; font-size: 14px;"&gt;&lt;EM&gt;Did you uncomment&amp;nbsp;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;SSLCACertificateFile?&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P style="color: #666666; background-color: #ffffff; font-weight: 300; font-size: 14px;"&gt;&lt;EM style="background-color: #ffffff; color: #333333;"&gt;Also did you verify /web/conf/httpd2.conf was updated appropriately after starting?&lt;/EM&gt;&lt;/P&gt;&lt;P style="color: #666666; background-color: #ffffff; font-weight: 300; font-size: 14px;"&gt;&lt;/P&gt;&lt;P style="color: #666666;"&gt;&lt;EM&gt;In theory it should work.&lt;/EM&gt;&lt;/P&gt;&lt;P style="color: #666666;"&gt;&lt;EM&gt;You need to restart httpd2 as I mentioned above for the changes to take effect.&lt;/EM&gt;&lt;/P&gt;&lt;P style="color: #666666;"&gt;&lt;EM&gt;It should regenerate the files in /web/conf (easy to confirm).&lt;/EM&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 13 Aug 2017 15:04:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-10-GAiA-Portal-Problems-Importing-already-issued-WILDCARD/m-p/5296#M134</guid>
      <dc:creator>Jerry</dc:creator>
      <dc:date>2017-08-13T15:04:05Z</dc:date>
    </item>
  </channel>
</rss>

