<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Mobile Access Client Certificate auto choice in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mobile-Access-Client-Certificate-auto-choice/m-p/140121#M21462</link>
    <description>&lt;P&gt;Hello!&lt;/P&gt;&lt;P&gt;We ran into a rather strange issue where we our mobile access clients suddently chooses the other certificate of the two, resulting in authentication issues when connecting to our site.&lt;BR /&gt;&lt;BR /&gt;No changes have been made to either the client package, Check Point gateway or anything.&lt;BR /&gt;&lt;BR /&gt;Before diving in too deeply, I just want to ask.&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;How does the Mobile Access client decide on which certificate in its list to present when connecting to its site?&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;It has worked without any client intervention before with auto-connect, but suddenly they get an authentication error and have to choose the correct certificate manually.&lt;BR /&gt;&lt;BR /&gt;Any input here would be appreciated, so I know where to start looking.&lt;/P&gt;</description>
    <pubDate>Tue, 01 Feb 2022 21:36:43 GMT</pubDate>
    <dc:creator>Henrik_J</dc:creator>
    <dc:date>2022-02-01T21:36:43Z</dc:date>
    <item>
      <title>Mobile Access Client Certificate auto choice</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mobile-Access-Client-Certificate-auto-choice/m-p/140121#M21462</link>
      <description>&lt;P&gt;Hello!&lt;/P&gt;&lt;P&gt;We ran into a rather strange issue where we our mobile access clients suddently chooses the other certificate of the two, resulting in authentication issues when connecting to our site.&lt;BR /&gt;&lt;BR /&gt;No changes have been made to either the client package, Check Point gateway or anything.&lt;BR /&gt;&lt;BR /&gt;Before diving in too deeply, I just want to ask.&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;How does the Mobile Access client decide on which certificate in its list to present when connecting to its site?&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;It has worked without any client intervention before with auto-connect, but suddenly they get an authentication error and have to choose the correct certificate manually.&lt;BR /&gt;&lt;BR /&gt;Any input here would be appreciated, so I know where to start looking.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Feb 2022 21:36:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mobile-Access-Client-Certificate-auto-choice/m-p/140121#M21462</guid>
      <dc:creator>Henrik_J</dc:creator>
      <dc:date>2022-02-01T21:36:43Z</dc:date>
    </item>
    <item>
      <title>Re: Mobile Access Client Certificate auto choice</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mobile-Access-Client-Certificate-auto-choice/m-p/140156#M21472</link>
      <description>&lt;P&gt;What precise client and version on what precise gateway version?&lt;/P&gt;</description>
      <pubDate>Wed, 02 Feb 2022 06:48:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mobile-Access-Client-Certificate-auto-choice/m-p/140156#M21472</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-02-02T06:48:52Z</dc:date>
    </item>
    <item>
      <title>Re: Mobile Access Client Certificate auto choice</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mobile-Access-Client-Certificate-auto-choice/m-p/140163#M21474</link>
      <description>&lt;P&gt;In add-remove programs it is mentioned as Check Point VPN with version 98.61.2331, checked&amp;nbsp;sk102150 but can't really find the exact version number there.&lt;BR /&gt;The client is Check Point Mobile.&lt;BR /&gt;&lt;BR /&gt;We will start the process to upgrade to a newer version, but to my knowledge, no changes have been made to the firewall nor the client and its configuration during the holidays.&lt;BR /&gt;&lt;BR /&gt;Only thing worth mentioning is that they may have had issues with the certificate enrollment, as the client started telling users that their certificate was expiring within x amount of days.&lt;BR /&gt;&lt;BR /&gt;Check Point is not the Certificate enroller here.&lt;BR /&gt;&lt;BR /&gt;So I was hoping to see if their certificate enrollment perhaps made any changes, which then changed the order of the certificate in some way or another.&lt;BR /&gt;&lt;BR /&gt;Hence why I want to know how mobile access selects a certificate in its list if more are available.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Feb 2022 07:50:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mobile-Access-Client-Certificate-auto-choice/m-p/140163#M21474</guid>
      <dc:creator>Henrik_J</dc:creator>
      <dc:date>2022-02-02T07:50:38Z</dc:date>
    </item>
    <item>
      <title>Re: Mobile Access Client Certificate auto choice</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mobile-Access-Client-Certificate-auto-choice/m-p/140179#M21477</link>
      <description>&lt;P&gt;My guess is it's E84.30.&lt;BR /&gt;Also, it's possible older certificates may need to be removed as the client is picking the "first" one (not necessarily the most recent one), at least based on my recent experience.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Feb 2022 09:29:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mobile-Access-Client-Certificate-auto-choice/m-p/140179#M21477</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-02-02T09:29:40Z</dc:date>
    </item>
    <item>
      <title>Re: Mobile Access Client Certificate auto choice</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mobile-Access-Client-Certificate-auto-choice/m-p/140472#M21565</link>
      <description>&lt;P&gt;thanks for the input.&lt;BR /&gt;&lt;BR /&gt;The current problem though is that another PKI's certificate is being selected as first.&lt;BR /&gt;Not that the old certificate in the valid PKI is being chosen.&lt;BR /&gt;&lt;BR /&gt;So what decision-making process does it use to have a cert being considered first and what not?&lt;BR /&gt;&lt;BR /&gt;Thanks again.&lt;/P&gt;</description>
      <pubDate>Fri, 04 Feb 2022 07:33:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mobile-Access-Client-Certificate-auto-choice/m-p/140472#M21565</guid>
      <dc:creator>Henrik_J</dc:creator>
      <dc:date>2022-02-04T07:33:32Z</dc:date>
    </item>
    <item>
      <title>Re: Mobile Access Client Certificate auto choice</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mobile-Access-Client-Certificate-auto-choice/m-p/140479#M21568</link>
      <description>&lt;P&gt;Just had time to troubleshoot this further.&lt;BR /&gt;&lt;BR /&gt;So the problem isn't really it just automagically choosing another certificate in the list, it is due to certificate renewal in combination with auto-connect.&lt;BR /&gt;&lt;BR /&gt;In the list, most if not all clients have at least two certificates to choose from, but the client has since long cached the certificate to use when auto-connecting.&lt;BR /&gt;&lt;BR /&gt;What we saw, was when I renewed the certificate, and immediately rebooted my computer, we received the error that it was unable to find a valid certificate during auto connect.&lt;/P&gt;&lt;P&gt;I'm just assuming here, but I suppose it is looking for the old certificate prior to the renewal, and doesn't find the new one properly.&lt;/P&gt;&lt;P&gt;Is there a workaround to this? Working as intended? Newer version has a fix?&lt;BR /&gt;&lt;BR /&gt;Thanks again.&lt;/P&gt;</description>
      <pubDate>Fri, 04 Feb 2022 09:58:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mobile-Access-Client-Certificate-auto-choice/m-p/140479#M21568</guid>
      <dc:creator>Henrik_J</dc:creator>
      <dc:date>2022-02-04T09:58:57Z</dc:date>
    </item>
  </channel>
</rss>

