<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Access Roles do not get automatically updated after moving users from OUs in Active Directory server in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Access-Roles-do-not-get-automatically-updated-after-moving-users/m-p/195628#M36448</link>
    <description>&lt;P&gt;Hi Community,&lt;/P&gt;&lt;P&gt;i just hit the "problem" that if a user object is moved in the AD from one OU to another, the existing Access Role Object for that user will stop matching because the unique identifier in the access role will not update.&lt;/P&gt;&lt;P&gt;I found a SK about that.&lt;/P&gt;&lt;P&gt;sk105494&lt;/P&gt;&lt;P&gt;So it got "fixed" with R.81 and the solution is mentioned in the Identity Awarness Administration Guide under the topic "Configuring Security Identifier (SID) for LDAP Users"&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;Note&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;- SID support is not activated by default.&lt;BR /&gt;To enable SID support on the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Check Point&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Security Gateway&lt;/SPAN&gt;:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;P&gt;Run&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;#cpstop&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;command.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Edit the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;$CPDIR/tmp/.CPprofile.sh&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;file.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Add the line:&lt;/P&gt;&lt;P&gt;&lt;EM&gt;export LDAP_SID=1&lt;/EM&gt;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Save the file.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Reboot the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Security Gateway&lt;/SPAN&gt;.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Run this command:&lt;/P&gt;&lt;P&gt;#pdp nested status&lt;/P&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;First question - why wasn't that set as default from Checkpoint? It feels somehow "experimental" and i don't want to run into problems after setting this up. It should be default to update AD user objects in the case of a OU move.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Second question - did someone make that change and run into any problems? &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Many thanks.&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;P&gt;Matt&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 19 Oct 2023 13:09:40 GMT</pubDate>
    <dc:creator>Matthew81</dc:creator>
    <dc:date>2023-10-19T13:09:40Z</dc:date>
    <item>
      <title>Access Roles do not get automatically updated after moving users from OUs in Active Directory server</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Access-Roles-do-not-get-automatically-updated-after-moving-users/m-p/195628#M36448</link>
      <description>&lt;P&gt;Hi Community,&lt;/P&gt;&lt;P&gt;i just hit the "problem" that if a user object is moved in the AD from one OU to another, the existing Access Role Object for that user will stop matching because the unique identifier in the access role will not update.&lt;/P&gt;&lt;P&gt;I found a SK about that.&lt;/P&gt;&lt;P&gt;sk105494&lt;/P&gt;&lt;P&gt;So it got "fixed" with R.81 and the solution is mentioned in the Identity Awarness Administration Guide under the topic "Configuring Security Identifier (SID) for LDAP Users"&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;Note&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;- SID support is not activated by default.&lt;BR /&gt;To enable SID support on the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Check Point&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Security Gateway&lt;/SPAN&gt;:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;P&gt;Run&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;#cpstop&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;command.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Edit the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;$CPDIR/tmp/.CPprofile.sh&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;file.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Add the line:&lt;/P&gt;&lt;P&gt;&lt;EM&gt;export LDAP_SID=1&lt;/EM&gt;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Save the file.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Reboot the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Security Gateway&lt;/SPAN&gt;.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Run this command:&lt;/P&gt;&lt;P&gt;#pdp nested status&lt;/P&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;First question - why wasn't that set as default from Checkpoint? It feels somehow "experimental" and i don't want to run into problems after setting this up. It should be default to update AD user objects in the case of a OU move.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Second question - did someone make that change and run into any problems? &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Many thanks.&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;P&gt;Matt&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Oct 2023 13:09:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Access-Roles-do-not-get-automatically-updated-after-moving-users/m-p/195628#M36448</guid>
      <dc:creator>Matthew81</dc:creator>
      <dc:date>2023-10-19T13:09:40Z</dc:date>
    </item>
    <item>
      <title>Re: Access Roles do not get automatically updated after moving users from OUs in Active Directory se</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Access-Roles-do-not-get-automatically-updated-after-moving-users/m-p/195657#M36454</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;I can't answer your first question, but we have been using SID for two years without any problems and I would say it is no longer "experimental".&lt;/P&gt;&lt;P&gt;We made the change at the end of 2021. We needed to make sure that access groups and users had their SID updated after the management upgrade to R81.X. This is done automatically during the upgrade process, but we had a very large number of AD groups/users (4 digits) - TAC provided us with two shell scripts to update all objects with the SID entry.&lt;/P&gt;&lt;P&gt;You can check this using GuiDBedit. See this post: Re: Identity Awareness - SID instead of DN for AD ... - Check Point CheckMates&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Regarding your second question - we haven't seen any problems after activation. You just need to check that the SID field is filled in.&lt;BR /&gt;&lt;BR /&gt;Best regards&lt;/P&gt;</description>
      <pubDate>Thu, 19 Oct 2023 14:55:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Access-Roles-do-not-get-automatically-updated-after-moving-users/m-p/195657#M36454</guid>
      <dc:creator>ProxyOps</dc:creator>
      <dc:date>2023-10-19T14:55:25Z</dc:date>
    </item>
    <item>
      <title>Re: Access Roles do not get automatically updated after moving users from OUs in Active Directory se</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Access-Roles-do-not-get-automatically-updated-after-moving-users/m-p/195691#M36475</link>
      <description>&lt;P&gt;To answer your second question, be aware that SID support will only exist for related objects created after the change was made per sk105494.&lt;BR /&gt;See:&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/General-Topics/Identity-Awareness-SID-instead-of-DN-for-AD-Users-Migration-for/m-p/195364#M32758" target="_blank"&gt;https://community.checkpoint.com/t5/General-Topics/Identity-Awareness-SID-instead-of-DN-for-AD-Users-Migration-for/m-p/195364#M32758&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;TAC can provide a script that will update the existing objects: &lt;A href="https://help.checkpoint.com" target="_blank"&gt;https://help.checkpoint.com&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Oct 2023 21:10:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Access-Roles-do-not-get-automatically-updated-after-moving-users/m-p/195691#M36475</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-10-19T21:10:04Z</dc:date>
    </item>
    <item>
      <title>Re: Access Roles do not get automatically updated after moving users from OUs in Active Directory se</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Access-Roles-do-not-get-automatically-updated-after-moving-users/m-p/195725#M36494</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Many thanks - we will contact TAC and get that script.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Oct 2023 05:29:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Access-Roles-do-not-get-automatically-updated-after-moving-users/m-p/195725#M36494</guid>
      <dc:creator>Matthew81</dc:creator>
      <dc:date>2023-10-20T05:29:34Z</dc:date>
    </item>
    <item>
      <title>Re: Access Roles do not get automatically updated after moving users from OUs in Active Directory se</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Access-Roles-do-not-get-automatically-updated-after-moving-users/m-p/195727#M36496</link>
      <description>&lt;P&gt;...ah one more thing - do i really need to edit the file on every security gateway? Or only the one who is PDP?&lt;/P&gt;</description>
      <pubDate>Fri, 20 Oct 2023 06:18:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Access-Roles-do-not-get-automatically-updated-after-moving-users/m-p/195727#M36496</guid>
      <dc:creator>Matthew81</dc:creator>
      <dc:date>2023-10-20T06:18:07Z</dc:date>
    </item>
    <item>
      <title>Re: Access Roles do not get automatically updated after moving users from OUs in Active Directory se</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Access-Roles-do-not-get-automatically-updated-after-moving-users/m-p/195782#M36513</link>
      <description>&lt;P&gt;The documentation states every security gateway needs this changed.&lt;/P&gt;</description>
      <pubDate>Fri, 20 Oct 2023 20:04:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Access-Roles-do-not-get-automatically-updated-after-moving-users/m-p/195782#M36513</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-10-20T20:04:36Z</dc:date>
    </item>
    <item>
      <title>Re: Access Roles do not get automatically updated after moving users from OUs in Active Directory se</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Access-Roles-do-not-get-automatically-updated-after-moving-users/m-p/195877#M36528</link>
      <description>&lt;P&gt;Yes, thats why i am asking &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;Because we have gateways not doing PDP or PEP. So i do not understand why to add that line into every .sh file mentioned in the documentation.&lt;/P&gt;&lt;P&gt;We have one cluster what is our PDP and some what are PEP getting the infos from the one PDP cluster.&lt;BR /&gt;So in my logic only the PDP cluster needs that change.&lt;/P&gt;&lt;P&gt;But sure, if i should add it to every gateway in our Environment, then i will do that. Will take some time i guess.&lt;BR /&gt;Somehow it would be better if Checkpoint will do that change by default in a future release &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Oct 2023 05:16:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Access-Roles-do-not-get-automatically-updated-after-moving-users/m-p/195877#M36528</guid>
      <dc:creator>Matthew81</dc:creator>
      <dc:date>2023-10-23T05:16:55Z</dc:date>
    </item>
    <item>
      <title>Re: Access Roles do not get automatically updated after moving users from OUs in Active Directory se</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Access-Roles-do-not-get-automatically-updated-after-moving-users/m-p/195879#M36529</link>
      <description>&lt;P&gt;Hi Matthew,&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;we only adjusted this profile.sh setting on the relevant PDP Gateways. This setting is relevant for the LDAP part&amp;nbsp; of the IA process flow .&amp;nbsp;&lt;BR /&gt;The LDAP process is only relevant on the Gateways with active PDP&amp;nbsp;functionality.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I would recommend to enable it on all gateways with active PDP and test it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;</description>
      <pubDate>Mon, 23 Oct 2023 08:19:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Access-Roles-do-not-get-automatically-updated-after-moving-users/m-p/195879#M36529</guid>
      <dc:creator>ProxyOps</dc:creator>
      <dc:date>2023-10-23T08:19:33Z</dc:date>
    </item>
  </channel>
</rss>

