<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: how to import private key in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/how-to-import-private-key/m-p/188974#M34771</link>
    <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/25382"&gt;@Gary_Fowler&lt;/a&gt;&amp;nbsp;Incorrect. You can use external certificates for anything, IPsec VPN included. Please refer to the admin guide.&lt;/P&gt;</description>
    <pubDate>Tue, 08 Aug 2023 15:13:27 GMT</pubDate>
    <dc:creator>_Val_</dc:creator>
    <dc:date>2023-08-08T15:13:27Z</dc:date>
    <item>
      <title>how to import private key</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/how-to-import-private-key/m-p/155657#M26534</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;i would like to import private key on checkpoint . i am using&amp;nbsp;&amp;nbsp;5600 security appliance.&lt;/P&gt;&lt;P&gt;My plan is i want to deploy using certificate.I will use third party certificate.&lt;/P&gt;&lt;P&gt;for example , i don't want to generate CSR from checkpoint. i will generate root cert ,private key and certificate for checkpoint by using openssl or other certificate server. This private will help to generate public key and map to VPN.&lt;/P&gt;&lt;P&gt;i will use this certificate for VPN. This process can do on cisco,hp and huwawei.&lt;/P&gt;&lt;P&gt;But i cannot find the reference for checkpoint.&lt;/P&gt;&lt;P&gt;Please let me know how to import private key and how to map this key to VPN certificate point ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Aug 2022 00:44:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/how-to-import-private-key/m-p/155657#M26534</guid>
      <dc:creator>RioAung</dc:creator>
      <dc:date>2022-08-25T00:44:02Z</dc:date>
    </item>
    <item>
      <title>Re: how to import private key</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/how-to-import-private-key/m-p/155661#M26535</link>
      <description>&lt;P&gt;Not sure if below may help...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk170395&amp;amp;partition=Advanced&amp;amp;product=Quantum" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk170395&amp;amp;partition=Advanced&amp;amp;product=Quantum&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Aug 2022 01:22:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/how-to-import-private-key/m-p/155661#M26535</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-08-25T01:22:27Z</dc:date>
    </item>
    <item>
      <title>Re: how to import private key</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/how-to-import-private-key/m-p/155692#M26539</link>
      <description>&lt;P&gt;Hello RioAung,&lt;/P&gt;&lt;P&gt;I think you can generate the CSR directly from the SGW, after that, you can export it and sign the certificate externally using your prefered method (openssl, any app, or what you want).&lt;/P&gt;&lt;P&gt;Once you have the certificate signed with a third-party CA, not the ICA, you have to complete the procedure and import the certificate, the CRT.&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;Export the CSR&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="unsigned.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/17568iC94392BA28249A48/image-size/medium?v=v2&amp;amp;px=400" role="button" title="unsigned.png" alt="unsigned.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Import the CRT:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="signed.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/17569i777CDEFA26EBECD3/image-size/medium?v=v2&amp;amp;px=400" role="button" title="signed.png" alt="signed.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;You have to import the 3-Party-CA as Trusted, type OPSEC PKI&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are you going to deploy a Site-to-site certificate based VPN? Check that post:&lt;/P&gt;&lt;P&gt;&lt;A href="https://ciberseguridad.blog/check-point-vpn-ipsec-certificated-based/" target="_blank" rel="noopener"&gt;https://ciberseguridad.blog/check-point-vpn-ipsec-certificated-based/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards!&lt;/P&gt;</description>
      <pubDate>Thu, 25 Aug 2022 09:19:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/how-to-import-private-key/m-p/155692#M26539</guid>
      <dc:creator>delToro1</dc:creator>
      <dc:date>2022-08-25T09:19:24Z</dc:date>
    </item>
    <item>
      <title>Re: how to import private key</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/how-to-import-private-key/m-p/188950#M34767</link>
      <description>&lt;P&gt;To my knowledge, checkpoint does not have the ability to import an existing private key, with certificate, into a gateways's IPSec VPN key DB.&amp;nbsp;&amp;nbsp; It would be a simple thing to code, but unfortunately, CheckPoint has not done for reason's I can not fathom.&lt;/P&gt;&lt;P&gt;If you need to use an existing certificate with existing key, then enabling Mobile Access Blade does give you the ability to import a key/cert pair in pkcs12 format..&amp;nbsp; But it will only be presented by the tcp/443 listener on the gateway; not the IPSec VPN IKE daemon.&lt;/P&gt;&lt;P&gt;Pretty piss poor in my opinion..&amp;nbsp; again, should be easy to code.. but has never been done.&lt;/P&gt;&lt;P&gt;Maybe someone knows a way to import a private key into a gateway object using CLI commands on the management server..&amp;nbsp; anyone?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Aug 2023 13:02:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/how-to-import-private-key/m-p/188950#M34767</guid>
      <dc:creator>Gary_Fowler</dc:creator>
      <dc:date>2023-08-08T13:02:54Z</dc:date>
    </item>
    <item>
      <title>Re: how to import private key</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/how-to-import-private-key/m-p/188974#M34771</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/25382"&gt;@Gary_Fowler&lt;/a&gt;&amp;nbsp;Incorrect. You can use external certificates for anything, IPsec VPN included. Please refer to the admin guide.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Aug 2023 15:13:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/how-to-import-private-key/m-p/188974#M34771</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2023-08-08T15:13:27Z</dc:date>
    </item>
    <item>
      <title>Re: how to import private key</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/how-to-import-private-key/m-p/212319#M40295</link>
      <description>&lt;P&gt;I didn't found the point to import existing key to gateway, too. Could you explain how that is possible? I need it for import a wildcard key for VPN client dial-in to authenticate the gateway by themself.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Apr 2024 15:31:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/how-to-import-private-key/m-p/212319#M40295</guid>
      <dc:creator>DH</dc:creator>
      <dc:date>2024-04-25T15:31:03Z</dc:date>
    </item>
  </channel>
</rss>

