<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic HTTPS-inspection certificate in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-certificate/m-p/180089#M32941</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have a gateway with Web Application and HTTPS-inspection. HTTPS-inspection certificate is going to expire, but it's set to bypass!&lt;/P&gt;&lt;P&gt;CA certificate is installed on all our Client.&lt;/P&gt;&lt;P&gt;The&amp;nbsp;Web-Application is completely active.&lt;/P&gt;&lt;P&gt;I would rather not renew the certificate.&lt;/P&gt;&lt;P&gt;Now I want to know, I'm going to get in trouble, or it's not impotent?&lt;/P&gt;&lt;P&gt;Thank you&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 05 May 2023 18:15:00 GMT</pubDate>
    <dc:creator>Cyrus</dc:creator>
    <dc:date>2023-05-05T18:15:00Z</dc:date>
    <item>
      <title>HTTPS-inspection certificate</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-certificate/m-p/180089#M32941</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have a gateway with Web Application and HTTPS-inspection. HTTPS-inspection certificate is going to expire, but it's set to bypass!&lt;/P&gt;&lt;P&gt;CA certificate is installed on all our Client.&lt;/P&gt;&lt;P&gt;The&amp;nbsp;Web-Application is completely active.&lt;/P&gt;&lt;P&gt;I would rather not renew the certificate.&lt;/P&gt;&lt;P&gt;Now I want to know, I'm going to get in trouble, or it's not impotent?&lt;/P&gt;&lt;P&gt;Thank you&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 05 May 2023 18:15:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-certificate/m-p/180089#M32941</guid>
      <dc:creator>Cyrus</dc:creator>
      <dc:date>2023-05-05T18:15:00Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS-inspection certificate</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-certificate/m-p/180092#M32942</link>
      <description>&lt;P&gt;If cert is going to expire,you need to renew and then send to users again. Thats done from legacy dashboard as per below screenshots.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/20799i2CBB38DA58E138B3/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_2.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/20800iA355F51E1A6A4EE3/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_2.png" alt="Screenshot_2.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Fri, 05 May 2023 19:18:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-certificate/m-p/180092#M32942</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-05-05T19:18:25Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS-inspection certificate</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-certificate/m-p/180097#M32944</link>
      <description>&lt;P&gt;I saw the email with your question&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/91081"&gt;@R_Y&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Though seems it was deleted, I will answer it regardless &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Im fairly positive nothing would happen if you renewed the cert, as I did this with 2 customers before. Just MAKE SURE users get correct https inspection certificate once renewed, no need to change any other config/rules.&lt;/P&gt;
&lt;P&gt;HTH&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;Have a nice weekend&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":soccer_ball:"&gt;⚽&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 06 May 2023 14:56:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-certificate/m-p/180097#M32944</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-05-06T14:56:59Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS-inspection certificate</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-certificate/m-p/180137#M32957</link>
      <description>&lt;P&gt;One thing&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/91081"&gt;@R_Y&lt;/a&gt;&amp;nbsp;that I forgot to mention : - )&lt;/P&gt;
&lt;P&gt;I had customer do this in midday hours (very small company) and it was fine. We simply sent the renewed cert to few users and everything worked like a charm, nothing else was changed.&lt;/P&gt;
&lt;P&gt;Now, I will go watch some football (or soccer as our American friends call it) and cheer for my favorite team, AC Milan&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":italy:"&gt;🇮🇹&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 06 May 2023 14:59:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-certificate/m-p/180137#M32957</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-05-06T14:59:35Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS-inspection certificate</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-certificate/m-p/198462#M37153</link>
      <description>&lt;P&gt;Hello Andy,&lt;/P&gt;&lt;P&gt;I'm in the same situation where i have to renew the outbound https inspection certificate but i'm a bit hesitant to push the 'renew certificate' button as i have no idea what the consequences are.&lt;/P&gt;&lt;P&gt;What will happen once i do this? Will all users be impacted until the certificate renewal process has been rounded off properly?&lt;/P&gt;&lt;P&gt;What will the workflow look like once i clicked on 'renew certificate'? Would be good if you could post some screenshots from this as well since this is the first time i have to do this and don't want to create an outage at the customer.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Nov 2023 07:39:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-certificate/m-p/198462#M37153</guid>
      <dc:creator>Dave</dc:creator>
      <dc:date>2023-11-21T07:39:24Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS-inspection certificate</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-certificate/m-p/198495#M37162</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/30940"&gt;@Dave&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;I dont foresee any issues myself in such a scenario. I had done it many times in the lab and worked fine, all I had to do is distribute renewed cert to machine behind the firewall and that was it, worked like a charm afterwards.&lt;/P&gt;
&lt;P&gt;I sort of compare it to if you say make bunch of changes in smart console, but only save it and dont install the policy...in case like that, firewalls would not be affected, since those changes would not have been pushed as of yet.&lt;/P&gt;
&lt;P&gt;Makes sense?&lt;/P&gt;
&lt;P&gt;If you need help with it, Im willing to do remote and show you in my lab.&lt;/P&gt;
&lt;P&gt;Cheers mate.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 21 Nov 2023 11:54:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-certificate/m-p/198495#M37162</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-11-21T11:54:23Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS-inspection certificate</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-certificate/m-p/198623#M37196</link>
      <description>&lt;P&gt;Current https inspection cert is signed by our RootCA, the RootCA cert is installed on all machines, so i assume once i renew the https inspection cert that this is to be trusted automatically and i don't have to deploy this renewed https inspection cert to all host?&lt;/P&gt;&lt;P&gt;Is my hypothesis making sense here or i'm missing something &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Because currently, when i check the https cert being in use and configured on our gateway, this cert is nowhere to find on my client pc in Trusted Root Certification Authorities certificate store or anywhere else.&lt;/P&gt;&lt;P&gt;So, i'm confused.&lt;/P&gt;&lt;P&gt;Thanks a bunch already &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Dave&lt;/P&gt;</description>
      <pubDate>Wed, 22 Nov 2023 12:37:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-certificate/m-p/198623#M37196</guid>
      <dc:creator>Dave</dc:creator>
      <dc:date>2023-11-22T12:37:54Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS-inspection certificate</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-certificate/m-p/198639#M37198</link>
      <description>&lt;P&gt;I always had to move the cert over to test machine, so Im fairly sure that will have to be done.&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 22 Nov 2023 12:37:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-certificate/m-p/198639#M37198</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-11-22T12:37:38Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS-inspection certificate</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-certificate/m-p/198642#M37199</link>
      <description>&lt;P&gt;Even when your https cert has been signed by the subCA of your internal PKI, and not Checkpoint CA?&lt;/P&gt;</description>
      <pubDate>Wed, 22 Nov 2023 13:08:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-certificate/m-p/198642#M37199</guid>
      <dc:creator>Dave</dc:creator>
      <dc:date>2023-11-22T13:08:01Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS-inspection certificate</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-certificate/m-p/198647#M37201</link>
      <description>&lt;P&gt;Ok, sorry, in that case, Im pretty sure you dont need to do anything, correct.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 22 Nov 2023 13:43:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-certificate/m-p/198647#M37201</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-11-22T13:43:24Z</dc:date>
    </item>
  </channel>
</rss>

