<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Identity Collector does not trust gateway certificate in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-does-not-trust-gateway-certificate/m-p/184121#M33802</link>
    <description>&lt;P&gt;After updating the certificate info in the collectors, the issue is resolved. We would like to understand why we didn't face any issues with the IA rules on the firewall, given the fact that the certificate was untrusted for two whole weeks! Is it possible that the gateway learnt about the user/group info, by some other means?&lt;/P&gt;</description>
    <pubDate>Thu, 15 Jun 2023 16:45:16 GMT</pubDate>
    <dc:creator>kadar2</dc:creator>
    <dc:date>2023-06-15T16:45:16Z</dc:date>
    <item>
      <title>Identity Collector does not trust gateway certificate</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-does-not-trust-gateway-certificate/m-p/184079#M33776</link>
      <description>&lt;P&gt;Dear community,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;recently we faced the following issue in our infrastructure.&lt;/P&gt;&lt;P&gt;We have two identity collectors running on WindowsServer 2012R2. The certificate under Mobile Access --&amp;gt; Portal Settings on one of our gateways was changed to a new wildcard certificate. The previous certificate was also a wildcard. The gateway is R81.10.&lt;/P&gt;&lt;P&gt;As a result of the change, both identity collectors displayed "Gateway Certificate Untrusted", until we performed an update certificate info. The "update" action was performed two weeks after the certificate replacement!&lt;/P&gt;&lt;P&gt;IA rules on the gateway were functioning normally for the two weeks period! We are trying to understand why we did not face any service disruption during this time. Identity awareness logs on the gateway show that AD user/group information was updated to the firewall. If the trust between identity collector/firewall is broken, how is this possible?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Jun 2023 12:45:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-does-not-trust-gateway-certificate/m-p/184079#M33776</guid>
      <dc:creator>kadar2</dc:creator>
      <dc:date>2023-06-15T12:45:17Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector does not trust gateway certificate</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-does-not-trust-gateway-certificate/m-p/184097#M33787</link>
      <description>&lt;P&gt;Hi kada2,&lt;/P&gt;&lt;P&gt;Does the new cert contain the IP in the SAN field?&lt;BR /&gt;If not, the create one with the IP&lt;/P&gt;&lt;P&gt;A&lt;/P&gt;</description>
      <pubDate>Thu, 15 Jun 2023 13:46:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-does-not-trust-gateway-certificate/m-p/184097#M33787</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2023-06-15T13:46:03Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector does not trust gateway certificate</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-does-not-trust-gateway-certificate/m-p/184121#M33802</link>
      <description>&lt;P&gt;After updating the certificate info in the collectors, the issue is resolved. We would like to understand why we didn't face any issues with the IA rules on the firewall, given the fact that the certificate was untrusted for two whole weeks! Is it possible that the gateway learnt about the user/group info, by some other means?&lt;/P&gt;</description>
      <pubDate>Thu, 15 Jun 2023 16:45:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-does-not-trust-gateway-certificate/m-p/184121#M33802</guid>
      <dc:creator>kadar2</dc:creator>
      <dc:date>2023-06-15T16:45:16Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector does not trust gateway certificate</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-does-not-trust-gateway-certificate/m-p/205512#M38785</link>
      <description>&lt;P&gt;Did you solve this mistery?&lt;/P&gt;</description>
      <pubDate>Thu, 08 Feb 2024 20:39:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-does-not-trust-gateway-certificate/m-p/205512#M38785</guid>
      <dc:creator>CheckPointerXL</dc:creator>
      <dc:date>2024-02-08T20:39:21Z</dc:date>
    </item>
  </channel>
</rss>

