<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CVE-2004-2761 with ICA in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CVE-2004-2761-with-ICA/m-p/208803#M39544</link>
    <description>&lt;P&gt;Not sure it may fix the problem, but worth a try.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Thu, 14 Mar 2024 19:08:15 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2024-03-14T19:08:15Z</dc:date>
    <item>
      <title>CVE-2004-2761 with ICA</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CVE-2004-2761-with-ICA/m-p/208295#M39438</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;Our R81 Gateway was found to have the vulnerability CVE-2004-2761 and needs to be replaced with a stronger SSL certificate.&lt;/P&gt;&lt;P&gt;However, looking at the details of the weak scan report, the problematic part seems to be related to the Internal CA (still using SHA-1), which means that the Internal CA may need to re-sign.&lt;/P&gt;&lt;P&gt;In addition to re-signing a certificate, is there any other way to solve the problem of ICA using SHA-1?&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2024 10:11:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CVE-2004-2761-with-ICA/m-p/208295#M39438</guid>
      <dc:creator>GigaYang</dc:creator>
      <dc:date>2024-03-11T10:11:12Z</dc:date>
    </item>
    <item>
      <title>Re: CVE-2004-2761 with ICA</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CVE-2004-2761-with-ICA/m-p/208686#M39511</link>
      <description>&lt;P&gt;For background, see:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk103840" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk103840&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;You need to renew the ICA, which should change it to SHA-256: &lt;A href="https://support.checkpoint.com/results/sk/sk43783" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk43783&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Mar 2024 15:32:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CVE-2004-2761-with-ICA/m-p/208686#M39511</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-03-13T15:32:35Z</dc:date>
    </item>
    <item>
      <title>Re: CVE-2004-2761 with ICA</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CVE-2004-2761-with-ICA/m-p/208718#M39520</link>
      <description>&lt;P&gt;Hi Sir,&lt;/P&gt;&lt;P&gt;This vulnerability was discovered when Nessus scanned Gateway's TCP 443 Port, but when checking the GAiA Web Portal certificate through the browser, it was already using SHA-256.&lt;/P&gt;&lt;P&gt;Do you still need to regenerate ICA?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 14 Mar 2024 01:04:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CVE-2004-2761-with-ICA/m-p/208718#M39520</guid>
      <dc:creator>GigaYang</dc:creator>
      <dc:date>2024-03-14T01:04:27Z</dc:date>
    </item>
    <item>
      <title>Re: CVE-2004-2761 with ICA</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CVE-2004-2761-with-ICA/m-p/208784#M39535</link>
      <description>&lt;P&gt;While the Gaia portal might have a certificate with SHA-256 hash, that certificate is signed by a CA that uses a SHA-1 hash.&lt;BR /&gt;Therein lies the problem.&amp;nbsp;&lt;BR /&gt;The only way to fix that is to regenerate the ICA.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Mar 2024 15:28:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CVE-2004-2761-with-ICA/m-p/208784#M39535</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-03-14T15:28:16Z</dc:date>
    </item>
    <item>
      <title>Re: CVE-2004-2761 with ICA</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CVE-2004-2761-with-ICA/m-p/208802#M39543</link>
      <description>&lt;P&gt;Does sk147272 can solve this problem?&lt;/P&gt;&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk147272" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk147272&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Mar 2024 18:56:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CVE-2004-2761-with-ICA/m-p/208802#M39543</guid>
      <dc:creator>GigaYang</dc:creator>
      <dc:date>2024-03-14T18:56:19Z</dc:date>
    </item>
    <item>
      <title>Re: CVE-2004-2761 with ICA</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CVE-2004-2761-with-ICA/m-p/208803#M39544</link>
      <description>&lt;P&gt;Not sure it may fix the problem, but worth a try.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 14 Mar 2024 19:08:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CVE-2004-2761-with-ICA/m-p/208803#M39544</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-03-14T19:08:15Z</dc:date>
    </item>
    <item>
      <title>Re: CVE-2004-2761 with ICA</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CVE-2004-2761-with-ICA/m-p/208804#M39545</link>
      <description>&lt;P&gt;SSL cipher suites would be different than certificate hash algorithms.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Mar 2024 19:18:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CVE-2004-2761-with-ICA/m-p/208804#M39545</guid>
      <dc:creator>CaseyB</dc:creator>
      <dc:date>2024-03-14T19:18:29Z</dc:date>
    </item>
  </channel>
</rss>

