<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Question about Https inspection Certificate upgrade in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Question-about-Https-inspection-Certificate-upgrade/m-p/131616#M19399</link>
    <description>&lt;P&gt;Thank you mr PhoneBoy,&lt;/P&gt;&lt;P&gt;As I see when generating key as&amp;nbsp;&lt;SPAN&gt;sk115894&amp;nbsp;, it also generates a private key (file called "server.key" in /home/admin). Do I need some actions on this file or leave it as default.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ca1.png" style="width: 347px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/13970iC6E57F943EB8E8B2/image-size/large?v=v2&amp;amp;px=999" role="button" title="ca1.png" alt="ca1.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks!!&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 13 Oct 2021 02:49:00 GMT</pubDate>
    <dc:creator>minhhaivietnam</dc:creator>
    <dc:date>2021-10-13T02:49:00Z</dc:date>
    <item>
      <title>Question about Https inspection Certificate upgrade</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Question-about-Https-inspection-Certificate-upgrade/m-p/131609#M19396</link>
      <description>&lt;P&gt;Hi experts,&lt;/P&gt;&lt;P&gt;My CLUSTER security gateway (R80.10) is using https inspection to control internet access. It is using certificate with SHA1. Now I need to upgrade SHA1 to SHA256.&lt;/P&gt;&lt;P&gt;I think I will follow&amp;nbsp;&lt;SPAN&gt;sk115894 to generate new cert, but I still have some questions , please help clear, thank in advance:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;gt;&amp;gt; I have a cluster, so where to generate cert (gateway 1 or 2 or on SMC) ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;gt;&amp;gt; After generating new cert, I will import cert into SMC as sk115894 guide. But about file server.key, its default location is /home/admin of firewall (where it was born) , so Do I need to move it to some required location?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;gt;&amp;gt; If this new cert gets problem after activating on SMC (as sk115894 guide) , could I rollback to old cert like this below ?&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ca1.png" style="width: 448px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/13969iB4450AE677D8E04C/image-size/large?v=v2&amp;amp;px=999" role="button" title="ca1.png" alt="ca1.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thank you!!!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Oct 2021 01:30:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Question-about-Https-inspection-Certificate-upgrade/m-p/131609#M19396</guid>
      <dc:creator>minhhaivietnam</dc:creator>
      <dc:date>2021-10-13T01:30:58Z</dc:date>
    </item>
    <item>
      <title>Re: Question about Https inspection Certificate upgrade</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Question-about-Https-inspection-Certificate-upgrade/m-p/131610#M19397</link>
      <description>&lt;P&gt;First of all, R80.10 is very close to End of Support.&lt;BR /&gt;Also, HTTPS Inspection has been improved substantially in later versions and it's highly recommended you upgrade to at least R80.40.&lt;/P&gt;
&lt;P&gt;Anyway, to your question: what you are generating in sk115894 is a Certificate Authority key.&lt;BR /&gt;You can generate the CA key on a gateway, management, or any other system.&lt;/P&gt;
&lt;P&gt;When you upload the CA key via SmartConsole and push policy, the gateways will be updated with the new CA key, which will be used to generate certificates for HTTPS traffic.&amp;nbsp;&lt;BR /&gt;And, likewise, you can revert by simply uploading the old CA key and pushing policy.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Oct 2021 02:02:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Question-about-Https-inspection-Certificate-upgrade/m-p/131610#M19397</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-10-13T02:02:28Z</dc:date>
    </item>
    <item>
      <title>Re: Question about Https inspection Certificate upgrade</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Question-about-Https-inspection-Certificate-upgrade/m-p/131616#M19399</link>
      <description>&lt;P&gt;Thank you mr PhoneBoy,&lt;/P&gt;&lt;P&gt;As I see when generating key as&amp;nbsp;&lt;SPAN&gt;sk115894&amp;nbsp;, it also generates a private key (file called "server.key" in /home/admin). Do I need some actions on this file or leave it as default.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ca1.png" style="width: 347px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/13970iC6E57F943EB8E8B2/image-size/large?v=v2&amp;amp;px=999" role="button" title="ca1.png" alt="ca1.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks!!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Oct 2021 02:49:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Question-about-Https-inspection-Certificate-upgrade/m-p/131616#M19399</guid>
      <dc:creator>minhhaivietnam</dc:creator>
      <dc:date>2021-10-13T02:49:00Z</dc:date>
    </item>
    <item>
      <title>Re: Question about Https inspection Certificate upgrade</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Question-about-Https-inspection-Certificate-upgrade/m-p/131618#M19401</link>
      <description>&lt;P&gt;server.key is an intermediary file that is used to create the .p12 file, which is what is ultimately being uploaded.&lt;BR /&gt;Don't believe you need to do anything with the server.key file.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Oct 2021 03:11:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Question-about-Https-inspection-Certificate-upgrade/m-p/131618#M19401</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-10-13T03:11:49Z</dc:date>
    </item>
    <item>
      <title>Re: Question about Https inspection Certificate upgrade</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Question-about-Https-inspection-Certificate-upgrade/m-p/131619#M19402</link>
      <description>&lt;P&gt;Thank PhoneBoy for instanting reply me.&lt;/P&gt;&lt;P&gt;I summary two ways , I can process my work:&lt;/P&gt;&lt;P&gt;1- upgrade to higher version checkpoint (ex R80.40)&lt;/P&gt;&lt;P&gt;2- if still R80.10, I generate a cert as SK above mentioned. Then I upload CA file (*&lt;STRONG&gt;.crt extension -&amp;gt; is this exactly?) &lt;/STRONG&gt;to SMC, and then push policy, using GPO push crt file to PC desktop....&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Thanks!&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Oct 2021 04:11:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Question-about-Https-inspection-Certificate-upgrade/m-p/131619#M19402</guid>
      <dc:creator>minhhaivietnam</dc:creator>
      <dc:date>2021-10-13T04:11:52Z</dc:date>
    </item>
    <item>
      <title>Re: Question about Https inspection Certificate upgrade</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Question-about-Https-inspection-Certificate-upgrade/m-p/131620#M19403</link>
      <description>&lt;P&gt;Actually, you'll need to upload the new .p12 file regardless of what version you are on.&lt;BR /&gt;Upgrading to at least R80.40 is recommended for many many other reasons.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Oct 2021 04:22:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Question-about-Https-inspection-Certificate-upgrade/m-p/131620#M19403</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-10-13T04:22:33Z</dc:date>
    </item>
    <item>
      <title>Re: Question about Https inspection Certificate upgrade</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Question-about-Https-inspection-Certificate-upgrade/m-p/131622#M19404</link>
      <description>&lt;P&gt;oh; I just see again, I need upload file *p12, not file *crt.&amp;nbsp;&lt;/P&gt;&lt;P&gt;In case of rollback to old cert, I also need file p12 of old cert, but when the time, I created old cert on smart console , I didn't know where *p12 file of old cert is located.&lt;/P&gt;&lt;P&gt;Could you please tell me where location on firewall is storing it ?&lt;/P&gt;</description>
      <pubDate>Wed, 13 Oct 2021 04:54:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Question-about-Https-inspection-Certificate-upgrade/m-p/131622#M19404</guid>
      <dc:creator>minhhaivietnam</dc:creator>
      <dc:date>2021-10-13T04:54:38Z</dc:date>
    </item>
    <item>
      <title>Re: Question about Https inspection Certificate upgrade</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Question-about-Https-inspection-Certificate-upgrade/m-p/131708#M19427</link>
      <description>&lt;P&gt;I don't believe it is stored in a .p12 file or in any format that is easily extractable.&lt;BR /&gt;TAC might be able to assist here.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regardless, provided you've distributed the new CA key to the relevant clients, there shouldn't be an issue that requires you to back out.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Oct 2021 15:53:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Question-about-Https-inspection-Certificate-upgrade/m-p/131708#M19427</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-10-13T15:53:28Z</dc:date>
    </item>
  </channel>
</rss>

