<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: MDS config - how to update internal CA in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MDS-config-how-to-update-internal-CA/m-p/18364#M1384</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you're running R77.30 or earlier and haven't applied a recent Jumbo Hotfix, you may be running into this issue:&amp;nbsp;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk122612" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk122612"&gt;Connectivity between SmartDashboard / SmartDomain Manager and Security Management / Multi-Domain Management Server R77.3…&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 26 Apr 2018 16:42:28 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2018-04-26T16:42:28Z</dc:date>
    <item>
      <title>MDS config - how to update internal CA</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MDS-config-how-to-update-internal-CA/m-p/18363#M1383</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;little issue when executing mdsconfig and creating the new internal CA, it takes the default IP whereas I updated the ip and hostname earlier :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Internal Certificate Authority created successfully&lt;BR /&gt; Certificate was created successfully&lt;BR /&gt;&lt;STRONG&gt;Setting FQDN to: 192.168.1.1&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;Executing "$CPDIR/bin/cp_conf ca fqdn 192.168.1.1" in order to set FQDN&lt;/STRONG&gt;&lt;BR /&gt;Trying to contact Certificate Authority. It might take a while...&lt;BR /&gt;192.168.1.1 was successfully set to the Internal CA&lt;BR /&gt;E&lt;STRONG&gt;xecuting "$CPDIR/bin/cp_conf ca fqdn 192.168.1.1" in order to set FQDN - Done&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;Certificate Authority initialization ended successfully&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think it is one of the reasons that might prevent the MDS processes from running because it does not find the correct CA for instance, find below the error I get when trying to start MDS services&amp;nbsp; :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ERROR: Couldn't create the Internal CA object. Check that the Internal CA process is running.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance for the help.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 Apr 2018 10:09:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MDS-config-how-to-update-internal-CA/m-p/18363#M1383</guid>
      <dc:creator>Furil</dc:creator>
      <dc:date>2018-04-26T10:09:31Z</dc:date>
    </item>
    <item>
      <title>Re: MDS config - how to update internal CA</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MDS-config-how-to-update-internal-CA/m-p/18364#M1384</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you're running R77.30 or earlier and haven't applied a recent Jumbo Hotfix, you may be running into this issue:&amp;nbsp;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk122612" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk122612"&gt;Connectivity between SmartDashboard / SmartDomain Manager and Security Management / Multi-Domain Management Server R77.3…&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 Apr 2018 16:42:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MDS-config-how-to-update-internal-CA/m-p/18364#M1384</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-04-26T16:42:28Z</dc:date>
    </item>
    <item>
      <title>Re: MDS config - how to update internal CA</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MDS-config-how-to-update-internal-CA/m-p/18365#M1385</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Dameon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;First, thanks for the reply &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;Ha! yes I did forget to precise the version ... Indeed it is a 77.30 recently upgraded from R76 (lab &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;) . But what I find strange is that I manualy installed the last CPuse agent (section 3-A):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk92449#Latest%20build%20of%20CPUSE%20and%20What" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk92449#Latest%20build%20of%20CPUSE%20and%20What"&gt;Check Point Upgrade Service Engine (CPUSE) - Gaia Deployment Agent&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then I also did install the last hotfix compatible with R77.30 (302) :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk106389" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk106389"&gt;R77.30 Recommended Hotfixes&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As hotfix are incremental, should it not be ok like that ? If yes then the only thing I can think of is that I did not follow correctly the migration procedure then.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Well I will setup a new lab later to debug further ... for the moment I took a snapshot of another MDS which does have same hardware and OS for migration purpose &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again and have a nice weekend &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 28 Apr 2018 09:13:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MDS-config-how-to-update-internal-CA/m-p/18365#M1385</guid>
      <dc:creator>Furil</dc:creator>
      <dc:date>2018-04-28T09:13:57Z</dc:date>
    </item>
    <item>
      <title>Re: MDS config - how to update internal CA</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MDS-config-how-to-update-internal-CA/m-p/50815#M3770</link>
      <description>Hello,&lt;BR /&gt;&lt;BR /&gt;Sorry for the delay, it did indeed resolve the issue I just had to run the wizard via mdsconfig again and it works ...&lt;BR /&gt;I cannot believe I did this mistake... Thank for your help&lt;BR /&gt;</description>
      <pubDate>Sat, 13 Apr 2019 11:10:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MDS-config-how-to-update-internal-CA/m-p/50815#M3770</guid>
      <dc:creator>Furil</dc:creator>
      <dc:date>2019-04-13T11:10:09Z</dc:date>
    </item>
  </channel>
</rss>

