<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Check Point LDAPS connection breaks everytime AD certificate is renewed in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-LDAPS-connection-breaks-everytime-AD-certificate-is/m-p/194241#M36133</link>
    <description>&lt;P&gt;sorry for the late reply but yeah, that works.&lt;/P&gt;</description>
    <pubDate>Wed, 04 Oct 2023 14:47:01 GMT</pubDate>
    <dc:creator>Machine_Head</dc:creator>
    <dc:date>2023-10-04T14:47:01Z</dc:date>
    <item>
      <title>Check Point LDAPS connection breaks everytime AD certificate is renewed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-LDAPS-connection-breaks-everytime-AD-certificate-is/m-p/100671#M10304</link>
      <description>&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Not sure if someone also has or had this problem but this is the 2nd recurrent year we had been in this situation. We use LDAPS (port 636, LDAP Account UnIt) config to connect to our ADs for Remote Access Usage and IA. Microsoft DCs generate a 1year expiration certificate which Check Point firewall validates using the fingerprint fetch process (Servers &amp;gt; Edit &amp;gt; Encryption &amp;gt; Fetch).&lt;/P&gt;&lt;P&gt;The thing is every year this certificate auto-renews and turns out the old fingerprint becomes invalid and that's where our lives stress out: no one is then able to access Internet through IA rules or connect to the environment through Remote access VPN until we manually fetch the new fingerprint in every LDAP server configured then push policy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I haven't seen any statement from Check Point showing a permanent fix for this (Hotfix or Patch) or any other option that allow us to use LDAPS and auto-fetch the fingerprint or something that not let this happen again.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please help!!!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Firewall version is R80.20&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Oct 2020 15:00:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-LDAPS-connection-breaks-everytime-AD-certificate-is/m-p/100671#M10304</guid>
      <dc:creator>Tierre_Amaral</dc:creator>
      <dc:date>2020-10-30T15:00:57Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point LDAPS connection breaks everytime AD certificate is renewed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-LDAPS-connection-breaks-everytime-AD-certificate-is/m-p/100713#M10305</link>
      <description>&lt;P&gt;I created a supportcase with TAC on this issue a few years ago. They didn't have a fix, but asked if I could just remove the fingerprint from the account unit. That way Check Point won't try to validate it and will accept any certificate. (This was for R77.30)&lt;/P&gt;&lt;P&gt;This was a good enough workaround for us at the time, since its a closed environment and we don't see any big chances of a mitm or anything.&lt;/P&gt;&lt;P&gt;But it feels like something that should be added to an API if it isn't already.&lt;/P&gt;&lt;P&gt;I'll check the api docuementation for account units on monday, and register an rfe is I cant find a way to fix it.&lt;/P&gt;</description>
      <pubDate>Sat, 31 Oct 2020 14:35:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-LDAPS-connection-breaks-everytime-AD-certificate-is/m-p/100713#M10305</guid>
      <dc:creator>Sigbjorn</dc:creator>
      <dc:date>2020-10-31T14:35:19Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point LDAPS connection breaks everytime AD certificate is renewed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-LDAPS-connection-breaks-everytime-AD-certificate-is/m-p/100722#M10306</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/19856"&gt;@Tierre_Amaral&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;this is a very old known limitation.&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?action=portlets.SearchResultMainAction&amp;amp;eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk42905" target="_blank" rel="noopener"&gt;LDAP failing with "SSL finger print does not match"&lt;/A&gt;&amp;nbsp;shows the solution mentioned by&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21279"&gt;@Sigbjorn&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;A lot of the members here are waiting for a solution, don‘t know if something changed with R81? Did not tried yet but maybe someone here did ?&lt;/P&gt;
&lt;P&gt;Wolfgang&lt;/P&gt;</description>
      <pubDate>Sat, 31 Oct 2020 17:44:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-LDAPS-connection-breaks-everytime-AD-certificate-is/m-p/100722#M10306</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2020-10-31T17:44:22Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point LDAPS connection breaks everytime AD certificate is renewed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-LDAPS-connection-breaks-everytime-AD-certificate-is/m-p/100788#M10307</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/19856"&gt;@Tierre_Amaral&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;This is not a specific problem to Identity Awareness, but to our authentication I/S.&lt;/P&gt;
&lt;P&gt;We had a customer release to change the trust mechanism to be based on PKI, and this way a certificate renewal won't affect the LDAPS query operations.&lt;/P&gt;
&lt;P&gt;You are more than welcome to open an RFE for getting this change, until it will be included in our GA versions.&lt;/P&gt;</description>
      <pubDate>Sun, 01 Nov 2020 12:17:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-LDAPS-connection-breaks-everytime-AD-certificate-is/m-p/100788#M10307</guid>
      <dc:creator>Royi_Priov</dc:creator>
      <dc:date>2020-11-01T12:17:15Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point LDAPS connection breaks everytime AD certificate is renewed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-LDAPS-connection-breaks-everytime-AD-certificate-is/m-p/100887#M10308</link>
      <description>&lt;P&gt;I see you'll get the fingerprint in the show-generic-object API, under ldapServers -&amp;gt; ldapSslSettings -&amp;gt; ldapSslFingerprints, so you should be able to update it via set-generic-object as well. (But I haven't had time to figure out the correct syntax for that yet)&lt;/P&gt;
&lt;P&gt;To get the current certificate fingerprint you can run this one-liner from the management: cpopenssl s_client -connect 10.10.10.10:636 2&amp;gt;&amp;amp;1 &amp;lt;/dev/null | sed -ne '/-BEGIN CERTIFICATE-/,/-END CERTIFICATE-/p' | cpopenssl x509 -noout -md5 -fingerprint&lt;/P&gt;
&lt;P&gt;But putting all that aside, the PKI option Royi mentions sounds like the best approach. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; (Hopefully this will be in the default release soon.)&lt;/P&gt;</description>
      <pubDate>Mon, 02 Nov 2020 12:06:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-LDAPS-connection-breaks-everytime-AD-certificate-is/m-p/100887#M10308</guid>
      <dc:creator>Sigbjorn</dc:creator>
      <dc:date>2020-11-02T12:06:02Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point LDAPS connection breaks everytime AD certificate is renewed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-LDAPS-connection-breaks-everytime-AD-certificate-is/m-p/122172#M17481</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/8232"&gt;@Royi_Priov&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any update on this? All of our IA functionality broke yesterday because of the certificate rotation on our domain controllers.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Dave&lt;/P&gt;</description>
      <pubDate>Fri, 25 Jun 2021 12:59:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-LDAPS-connection-breaks-everytime-AD-certificate-is/m-p/122172#M17481</guid>
      <dc:creator>David_C1</dc:creator>
      <dc:date>2021-06-25T12:59:16Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point LDAPS connection breaks everytime AD certificate is renewed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-LDAPS-connection-breaks-everytime-AD-certificate-is/m-p/122177#M17482</link>
      <description>&lt;P&gt;I agree with&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1447"&gt;@Wolfgang&lt;/a&gt;&amp;nbsp;. I also saw this before and TAC told me it was a known problem...not sure when CP plans on fixing it though.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Jun 2021 13:55:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-LDAPS-connection-breaks-everytime-AD-certificate-is/m-p/122177#M17482</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-06-25T13:55:01Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point LDAPS connection breaks everytime AD certificate is renewed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-LDAPS-connection-breaks-everytime-AD-certificate-is/m-p/128104#M18632</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/8232"&gt;@Royi_Priov&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;we have the same problem as &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/19856"&gt;@Tierre_Amaral&lt;/a&gt;&amp;nbsp;and opened a SR, however Check Point Support told us there is no private fix for this. How are we able to get the fix for this?&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Steph&lt;/P&gt;</description>
      <pubDate>Thu, 26 Aug 2021 13:05:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-LDAPS-connection-breaks-everytime-AD-certificate-is/m-p/128104#M18632</guid>
      <dc:creator>StephS</dc:creator>
      <dc:date>2021-08-26T13:05:34Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point LDAPS connection breaks everytime AD certificate is renewed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-LDAPS-connection-breaks-everytime-AD-certificate-is/m-p/169394#M30657</link>
      <description>&lt;P&gt;is it going to be fixed in any GA version? it's kind of annoying to re fetch certificates&lt;/P&gt;</description>
      <pubDate>Fri, 27 Jan 2023 10:18:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-LDAPS-connection-breaks-everytime-AD-certificate-is/m-p/169394#M30657</guid>
      <dc:creator>Martin_Valenta</dc:creator>
      <dc:date>2023-01-27T10:18:16Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point LDAPS connection breaks everytime AD certificate is renewed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-LDAPS-connection-breaks-everytime-AD-certificate-is/m-p/169407#M30663</link>
      <description>&lt;P&gt;Just leave the fingerprint field empty &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Jan 2023 12:07:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-LDAPS-connection-breaks-everytime-AD-certificate-is/m-p/169407#M30663</guid>
      <dc:creator>Machine_Head</dc:creator>
      <dc:date>2023-01-27T12:07:09Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point LDAPS connection breaks everytime AD certificate is renewed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-LDAPS-connection-breaks-everytime-AD-certificate-is/m-p/171001#M30983</link>
      <description>&lt;P&gt;Is that a joke or a true story?&lt;/P&gt;</description>
      <pubDate>Fri, 10 Feb 2023 13:30:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-LDAPS-connection-breaks-everytime-AD-certificate-is/m-p/171001#M30983</guid>
      <dc:creator>piteyyy</dc:creator>
      <dc:date>2023-02-10T13:30:12Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point LDAPS connection breaks everytime AD certificate is renewed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-LDAPS-connection-breaks-everytime-AD-certificate-is/m-p/194089#M36088</link>
      <description>&lt;P&gt;Still unfixed?&lt;/P&gt;</description>
      <pubDate>Tue, 03 Oct 2023 06:46:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-LDAPS-connection-breaks-everytime-AD-certificate-is/m-p/194089#M36088</guid>
      <dc:creator>Arskaz</dc:creator>
      <dc:date>2023-10-03T06:46:15Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point LDAPS connection breaks everytime AD certificate is renewed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-LDAPS-connection-breaks-everytime-AD-certificate-is/m-p/194162#M36111</link>
      <description>&lt;P&gt;I can confirm, at least in R81.10 JHFA Take 95, this is still a problem.&lt;/P&gt;
&lt;P&gt;Dave&lt;/P&gt;</description>
      <pubDate>Tue, 03 Oct 2023 16:54:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-LDAPS-connection-breaks-everytime-AD-certificate-is/m-p/194162#M36111</guid>
      <dc:creator>David_C1</dc:creator>
      <dc:date>2023-10-03T16:54:06Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point LDAPS connection breaks everytime AD certificate is renewed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-LDAPS-connection-breaks-everytime-AD-certificate-is/m-p/194163#M36112</link>
      <description>&lt;P&gt;Did TAC confirm the same?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 03 Oct 2023 17:11:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-LDAPS-connection-breaks-everytime-AD-certificate-is/m-p/194163#M36112</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-10-03T17:11:42Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point LDAPS connection breaks everytime AD certificate is renewed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-LDAPS-connection-breaks-everytime-AD-certificate-is/m-p/194164#M36113</link>
      <description>&lt;P&gt;TAC didn't need to confirm, my broken IA was all the confirmation I needed (fixed once we re-fetched fingerprints).&lt;/P&gt;
&lt;P&gt;Dave&lt;/P&gt;</description>
      <pubDate>Tue, 03 Oct 2023 17:25:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-LDAPS-connection-breaks-everytime-AD-certificate-is/m-p/194164#M36113</guid>
      <dc:creator>David_C1</dc:creator>
      <dc:date>2023-10-03T17:25:18Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point LDAPS connection breaks everytime AD certificate is renewed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-LDAPS-connection-breaks-everytime-AD-certificate-is/m-p/194165#M36114</link>
      <description>&lt;P&gt;Ok, gotcha...so version/jumbo is still the same, you just refetched the fingerprint?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 03 Oct 2023 17:35:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-LDAPS-connection-breaks-everytime-AD-certificate-is/m-p/194165#M36114</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-10-03T17:35:45Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point LDAPS connection breaks everytime AD certificate is renewed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-LDAPS-connection-breaks-everytime-AD-certificate-is/m-p/194172#M36118</link>
      <description>&lt;P&gt;Correct.&lt;/P&gt;
&lt;P&gt;Dave&lt;/P&gt;</description>
      <pubDate>Tue, 03 Oct 2023 18:17:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-LDAPS-connection-breaks-everytime-AD-certificate-is/m-p/194172#M36118</guid>
      <dc:creator>David_C1</dc:creator>
      <dc:date>2023-10-03T18:17:05Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point LDAPS connection breaks everytime AD certificate is renewed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-LDAPS-connection-breaks-everytime-AD-certificate-is/m-p/194241#M36133</link>
      <description>&lt;P&gt;sorry for the late reply but yeah, that works.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Oct 2023 14:47:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-LDAPS-connection-breaks-everytime-AD-certificate-is/m-p/194241#M36133</guid>
      <dc:creator>Machine_Head</dc:creator>
      <dc:date>2023-10-04T14:47:01Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point LDAPS connection breaks everytime AD certificate is renewed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-LDAPS-connection-breaks-everytime-AD-certificate-is/m-p/204035#M38486</link>
      <description>&lt;P&gt;Hi Royi,&lt;/P&gt;&lt;P&gt;this change is already happened on R81.20?&lt;/P&gt;&lt;P&gt;Best Regards,&lt;BR /&gt;Yossi.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jan 2024 10:55:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-LDAPS-connection-breaks-everytime-AD-certificate-is/m-p/204035#M38486</guid>
      <dc:creator>gm446</dc:creator>
      <dc:date>2024-01-24T10:55:26Z</dc:date>
    </item>
  </channel>
</rss>

