<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Checkpoint 790 Appliance - SSL VPN Certificate Renewal in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-790-Appliance-SSL-VPN-Certificate-Renewal/m-p/190608#M35177</link>
    <description>&lt;P&gt;See if you can find the relevant certificate (a .crt file) in one of&amp;nbsp;&lt;SPAN&gt;/pfrm2.0/config1/fw1/conf/ or /pfrm2.0/config2/fw1/conf/&lt;BR /&gt;&lt;/SPAN&gt;If it's there, I believe it will be safe to remove the file and it should resolve the issue.&lt;BR /&gt;If this doesn't resolve the issue, I suggest contacting the TAC.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 25 Aug 2023 13:48:32 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2023-08-25T13:48:32Z</dc:date>
    <item>
      <title>Checkpoint 790 Appliance - SSL VPN Certificate Renewal</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-790-Appliance-SSL-VPN-Certificate-Renewal/m-p/190589#M35172</link>
      <description>&lt;P&gt;I need to update an SSL VPN certificate on a Checkpoint 790 Appliance.&lt;/P&gt;
&lt;P&gt;I have the pfx file to import generated from Entrust.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I thought the import option would be able to update the existing certificates, but when importing "Certificate already exists" is returned.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To remove the existing certificate, under VPN &amp;gt; Remote Access &amp;gt; Advanced I deselected the existing certificate (cant be deleted if the current certificate is selected). I then deleted the certificate from the table.&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;When I try to import the new certificate, it still returns "Certificate already installed".&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I was thinking it might be the existing Entrust intermediate certificate located under Certificates &amp;gt; Trusted CAs that might also need to be removed before I can import the new certificate.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;The import option does not seem to be able to automatically update the existing certificates.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Aug 2023 12:42:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-790-Appliance-SSL-VPN-Certificate-Renewal/m-p/190589#M35172</guid>
      <dc:creator>Simon_Macpherso</dc:creator>
      <dc:date>2023-08-25T12:42:06Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint 790 Appliance - SSL VPN Certificate Renewal</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-790-Appliance-SSL-VPN-Certificate-Renewal/m-p/190594#M35173</link>
      <description>&lt;P&gt;Can you send a screenshot of it please? I dont ever recall having issue with this in the past.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 25 Aug 2023 13:03:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-790-Appliance-SSL-VPN-Certificate-Renewal/m-p/190594#M35173</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-08-25T13:03:13Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint 790 Appliance - SSL VPN Certificate Renewal</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-790-Appliance-SSL-VPN-Certificate-Renewal/m-p/190608#M35177</link>
      <description>&lt;P&gt;See if you can find the relevant certificate (a .crt file) in one of&amp;nbsp;&lt;SPAN&gt;/pfrm2.0/config1/fw1/conf/ or /pfrm2.0/config2/fw1/conf/&lt;BR /&gt;&lt;/SPAN&gt;If it's there, I believe it will be safe to remove the file and it should resolve the issue.&lt;BR /&gt;If this doesn't resolve the issue, I suggest contacting the TAC.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Aug 2023 13:48:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-790-Appliance-SSL-VPN-Certificate-Renewal/m-p/190608#M35177</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-08-25T13:48:32Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint 790 Appliance - SSL VPN Certificate Renewal</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-790-Appliance-SSL-VPN-Certificate-Renewal/m-p/190679#M35184</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2023-08-28 121648.png" style="width: 607px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/22213iCDD31DF131E5A139/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2023-08-28 121648.png" alt="Screenshot 2023-08-28 121648.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;It seems the PFX in this instance doesn't contain the intermediate certificate - I removed the intermediate certificate from the Trusted CAs table and when trying to import the PFX it returned that the intermediate certificate for the import could not be found. So its not the existing intermediate certificate that is causing the issue.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Aug 2023 02:21:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-790-Appliance-SSL-VPN-Certificate-Renewal/m-p/190679#M35184</guid>
      <dc:creator>Simon_Macpherso</dc:creator>
      <dc:date>2023-08-28T02:21:05Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint 790 Appliance - SSL VPN Certificate Renewal</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-790-Appliance-SSL-VPN-Certificate-Renewal/m-p/190680#M35185</link>
      <description>&lt;P&gt;There are /crt files in&amp;nbsp;&lt;SPAN&gt;/pfrm2.0/config1/fw1/conf/&amp;nbsp;but the filenames appear encoded.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Are the .crt file names encoded? If so which encoding is used? &lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Aug 2023 02:26:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-790-Appliance-SSL-VPN-Certificate-Renewal/m-p/190680#M35185</guid>
      <dc:creator>Simon_Macpherso</dc:creator>
      <dc:date>2023-08-28T02:26:43Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint 790 Appliance - SSL VPN Certificate Renewal</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-790-Appliance-SSL-VPN-Certificate-Renewal/m-p/190693#M35189</link>
      <description>&lt;P&gt;Better contact TAC - there is some issue with certificate renewal on SMBs, currently a customer using 1480 experiences a similar problem.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Aug 2023 06:52:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-790-Appliance-SSL-VPN-Certificate-Renewal/m-p/190693#M35189</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-08-28T06:52:03Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint 790 Appliance - SSL VPN Certificate Renewal</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-790-Appliance-SSL-VPN-Certificate-Renewal/m-p/190701#M35192</link>
      <description>&lt;P&gt;This was suggested by TAC:&lt;/P&gt;
&lt;P&gt;1. Take a backup (Important!)&lt;/P&gt;
&lt;P&gt;2. Delete trusted CAs&lt;BR /&gt;Remove the old certificate. (VPN -&amp;gt; Installed Certificates)&lt;BR /&gt;Go to VPN -&amp;gt; Trusted CAs , Delete your certificate.&lt;/P&gt;
&lt;P&gt;3. While in expert mode go to '/pfrm2.0/config1/fw1/conf/' directory.&lt;BR /&gt;List all the certificates found under that directory by using the command:&lt;BR /&gt;[Expert@GW]# ls -ltr | grep crt&lt;BR /&gt;You will find a number of certificates that have characters as names [e.g.]:&lt;BR /&gt;-rw-r--r-- 1 root root 1050 Jun 27 18:42 c9720cf17d8ae1f993fe0b22.crt&lt;BR /&gt;-rw-r--r-- 1 root root 633 Jun 29 12:10 ccf7997d7404c47982732e29.crt&lt;BR /&gt;-rw-r--r-- 1 root root 734 Jun 29 12:10 e627755460d5431429e54b6e.crt&lt;BR /&gt;-rw-r--r-- 1 root root 645 Jun 29 12:10 f4270c849a7eaef38bef7989.crt&lt;BR /&gt;Delete these certificates.&lt;BR /&gt;Reboot the appliance and check again.&lt;/P&gt;
&lt;P&gt;Please run the following command in expert mode and confirm the status of the convention blade.&lt;BR /&gt;#configload_Status&lt;/P&gt;</description>
      <pubDate>Mon, 28 Aug 2023 08:17:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-790-Appliance-SSL-VPN-Certificate-Renewal/m-p/190701#M35192</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-08-28T08:17:23Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint 790 Appliance - SSL VPN Certificate Renewal</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-790-Appliance-SSL-VPN-Certificate-Renewal/m-p/190750#M35203</link>
      <description>&lt;P&gt;Not exactly sure how the files are named.&lt;BR /&gt;In any case, you will have to review the contents of each file to find the relevant one to remove.&lt;BR /&gt;I believe you can use the openssl CLI command to see the contents of these files (though can’t immediately find the correct syntax).&lt;/P&gt;</description>
      <pubDate>Mon, 28 Aug 2023 14:33:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-790-Appliance-SSL-VPN-Certificate-Renewal/m-p/190750#M35203</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-08-28T14:33:14Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint 790 Appliance - SSL VPN Certificate Renewal</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-790-Appliance-SSL-VPN-Certificate-Renewal/m-p/191169#M35292</link>
      <description>&lt;P&gt;Thanks I haven't performed this procedure yet but the certificate expiry date was the 29th and users are still able to connect, suggesting the certificate was installed even though it didn't return a certificate successfully installed message. Oddly, the certificate also is not displayed in the installed certificates table.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Aug 2023 23:15:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-790-Appliance-SSL-VPN-Certificate-Renewal/m-p/191169#M35292</guid>
      <dc:creator>Simon_Macpherso</dc:creator>
      <dc:date>2023-08-30T23:15:46Z</dc:date>
    </item>
  </channel>
</rss>

