<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Machine cert authentication and local computer certificate store in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Machine-cert-authentication-and-local-computer-certificate-store/m-p/211629#M40134</link>
    <description>&lt;P&gt;Ok lol&lt;/P&gt;
&lt;P&gt;In that case, I would open TAC ticket and see what gives.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Wed, 17 Apr 2024 15:15:18 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2024-04-17T15:15:18Z</dc:date>
    <item>
      <title>Machine cert authentication and local computer certificate store</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Machine-cert-authentication-and-local-computer-certificate-store/m-p/211429#M40075</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We’re trying to test Remote VPN access with machine cert authentication. It is not clear to me which authentication to select on the client when creating the site.&lt;/P&gt;
&lt;P&gt;I selected Certificate – CAPI but when trying to connect it offers a choice of certificate it finds in the Current user\Personal\Certificates&lt;/P&gt;
&lt;P&gt;We’ve setup automatic cert enrollment for our machines but it puts the certificate in the Local computer\Personal\Certificate&lt;/P&gt;
&lt;P&gt;I feel like I’m missing something here. How do you get the CheckPoint client to look for a certificate in the Local computer certificate store?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Francis&lt;/P&gt;</description>
      <pubDate>Tue, 16 Apr 2024 14:34:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Machine-cert-authentication-and-local-computer-certificate-store/m-p/211429#M40075</guid>
      <dc:creator>flachance</dc:creator>
      <dc:date>2024-04-16T14:34:59Z</dc:date>
    </item>
    <item>
      <title>Re: Machine cert authentication and local computer certificate store</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Machine-cert-authentication-and-local-computer-certificate-store/m-p/211454#M40085</link>
      <description>&lt;P&gt;What version of client?&lt;BR /&gt;What version/JHF of gateway?&lt;BR /&gt;I'm assuming you've followed all the instructions here:&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_RemoteAccessVPN_AdminGuide/Content/Topics-VPNRG/Machine-Certificate.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_RemoteAccessVPN_AdminGuide/Content/Topics-VPNRG/Machine-Certificate.htm&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Apr 2024 17:05:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Machine-cert-authentication-and-local-computer-certificate-store/m-p/211454#M40085</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-04-16T17:05:48Z</dc:date>
    </item>
    <item>
      <title>Re: Machine cert authentication and local computer certificate store</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Machine-cert-authentication-and-local-computer-certificate-store/m-p/211470#M40087</link>
      <description>&lt;P&gt;Had similar issue recently with a customer and TAC fixed it with below 2 SKs, might be worth checking and to answer your question, you most likely select certificate auth on the client, its one called personal cert I believe&lt;/P&gt;
&lt;P&gt;Check out answer I gave in below post.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/Machine-certificate-auth/m-p/210437" target="_blank" rel="noopener"&gt;https://community.checkpoint.com/t5/Security-Gateways/Machine-certificate-auth/m-p/210437&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Apr 2024 18:55:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Machine-cert-authentication-and-local-computer-certificate-store/m-p/211470#M40087</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-04-16T18:55:42Z</dc:date>
    </item>
    <item>
      <title>Re: Machine cert authentication and local computer certificate store</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Machine-cert-authentication-and-local-computer-certificate-store/m-p/211590#M40118</link>
      <description>&lt;P&gt;client is 87.50. Gateway is 81.20 JHF take 53. Yes we've followed the guide and the relevant part of the client guide.&lt;/P&gt;
&lt;P&gt;I think we might not be understanding the authentication part correctly. Can you establish VPN with only the machine cert to authenticate or do you also require user authentication?&lt;/P&gt;</description>
      <pubDate>Wed, 17 Apr 2024 12:08:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Machine-cert-authentication-and-local-computer-certificate-store/m-p/211590#M40118</guid>
      <dc:creator>flachance</dc:creator>
      <dc:date>2024-04-17T12:08:37Z</dc:date>
    </item>
    <item>
      <title>Re: Machine cert authentication and local computer certificate store</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Machine-cert-authentication-and-local-computer-certificate-store/m-p/211592#M40119</link>
      <description>&lt;P&gt;I believe it is possible with just machine cert, but not 100% certain, you may want to confirm with TAC.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Apr 2024 12:32:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Machine-cert-authentication-and-local-computer-certificate-store/m-p/211592#M40119</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-04-17T12:32:23Z</dc:date>
    </item>
    <item>
      <title>Re: Machine cert authentication and local computer certificate store</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Machine-cert-authentication-and-local-computer-certificate-store/m-p/211611#M40125</link>
      <description>&lt;P&gt;You can, the instructions are in the link that Phoneboy has there and then the Remote Access Guide that is linked from there.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/RemoteAccessClients_forWindows_AdminGuide/Content/Topics-RA-VPN-for-Win/Configuring-Machine-Authentication-on-Client.htm?tocpath=Configuring%20Client%20Features%7CMachine%20Authentication%7C_____3" target="_blank"&gt;https://sc1.checkpoint.com/documents/RemoteAccessClients_forWindows_AdminGuide/Content/Topics-RA-VPN-for-Win/Configuring-Machine-Authentication-on-Client.htm?tocpath=Configuring%20Client%20Features%7CMachine%20Authentication%7C_____3&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Apr 2024 13:30:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Machine-cert-authentication-and-local-computer-certificate-store/m-p/211611#M40125</guid>
      <dc:creator>emmap</dc:creator>
      <dc:date>2024-04-17T13:30:33Z</dc:date>
    </item>
    <item>
      <title>Re: Machine cert authentication and local computer certificate store</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Machine-cert-authentication-and-local-computer-certificate-store/m-p/211626#M40131</link>
      <description>&lt;P&gt;I did use the instructions on these two links.&lt;/P&gt;
&lt;P&gt;Something is missing or we’re missing something&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;From &lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_RemoteAccessVPN_AdminGuide/Content/Topics-VPNRG/Machine-Certificate.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_RemoteAccessVPN_AdminGuide/Content/Topics-VPNRG/Machine-Certificate.htm&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The machine must be defined on a&amp;nbsp;&lt;STRONG&gt;Microsoft&lt;/STRONG&gt;&amp;nbsp;AD server – Check&lt;/P&gt;
&lt;P&gt;The Subject field of a machine certificate must not be empty – Check&lt;/P&gt;
&lt;P&gt;The hostname must be the first value – Check&lt;/P&gt;
&lt;P&gt;Machine-only authenticated tunnels require the&amp;nbsp;&lt;SPAN&gt;Security Gateway&lt;/SPAN&gt;&amp;nbsp;authentication method to be “Defined on user record (Legacy authentication)” – Check&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_RemoteAccessVPN_AdminGuide/Content/Topics-VPNRG/Machine-Certificate.htm" target="_blank"&gt;Adding the root CA on the LDAP Server to the Trusted CA in Management&lt;/A&gt; – Check&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_RemoteAccessVPN_AdminGuide/Content/Topics-VPNRG/Machine-Certificate.htm" target="_blank"&gt;Creating LDAP Account Unit&lt;/A&gt; – Check&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_RemoteAccessVPN_AdminGuide/Content/Topics-VPNRG/Machine-Certificate.htm" target="_blank"&gt;Setting up the Authentication enforcement&lt;/A&gt; as When Available – Check&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;From &lt;A href="https://sc1.checkpoint.com/documents/RemoteAccessClients_forWindows_AdminGuide/Content/Topics-RA-VPN-for-Win/Configuring-Machine-Authentication-on-Client.htm?tocpath=Configuring%20Client%20Features%7CMachine%20Authentication%7C_____3" target="_blank"&gt;https://sc1.checkpoint.com/documents/RemoteAccessClients_forWindows_AdminGuide/Content/Topics-RA-VPN-for-Win/Configuring-Machine-Authentication-on-Client.htm?tocpath=Configuring%20Client%20Features%7CMachine%20Authentication%7C_____3&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On the client. Trac.defaults has&lt;/P&gt;
&lt;P&gt;Enable_machine_auth set to true&lt;/P&gt;
&lt;P&gt;Machine_tunnel_site set to the created site name&lt;/P&gt;
&lt;P&gt;Machine_tunnel_before_logon set to true&lt;/P&gt;
&lt;P&gt;Machine_tunnel_after_logon set to false&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As noted in the instructions the machine site was created before but there is no indications of the settings to use. We picked Certificate CAPI. When trying to connect, it offers certificates found in the user certificate store but the machine certificate is in the Local computer certificate store.&lt;/P&gt;
&lt;P&gt;How do we get the client to use the certificate in the Local Computer certificate store?&lt;/P&gt;</description>
      <pubDate>Wed, 17 Apr 2024 14:58:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Machine-cert-authentication-and-local-computer-certificate-store/m-p/211626#M40131</guid>
      <dc:creator>flachance</dc:creator>
      <dc:date>2024-04-17T14:58:09Z</dc:date>
    </item>
    <item>
      <title>Re: Machine cert authentication and local computer certificate store</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Machine-cert-authentication-and-local-computer-certificate-store/m-p/211627#M40132</link>
      <description>&lt;P&gt;Did you check 2 SKs I mentioned in the link from one of my posts? Not sure if they might be relevant in your case, but if not, then I would open TAC case to see what might be missing.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 17 Apr 2024 15:12:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Machine-cert-authentication-and-local-computer-certificate-store/m-p/211627#M40132</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-04-17T15:12:04Z</dc:date>
    </item>
    <item>
      <title>Re: Machine cert authentication and local computer certificate store</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Machine-cert-authentication-and-local-computer-certificate-store/m-p/211628#M40133</link>
      <description>&lt;P&gt;I did. But I'm not even at the point where I'm actually attempting to connect&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":grinning_squinting_face:"&gt;😆&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Apr 2024 15:14:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Machine-cert-authentication-and-local-computer-certificate-store/m-p/211628#M40133</guid>
      <dc:creator>flachance</dc:creator>
      <dc:date>2024-04-17T15:14:10Z</dc:date>
    </item>
    <item>
      <title>Re: Machine cert authentication and local computer certificate store</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Machine-cert-authentication-and-local-computer-certificate-store/m-p/211629#M40134</link>
      <description>&lt;P&gt;Ok lol&lt;/P&gt;
&lt;P&gt;In that case, I would open TAC ticket and see what gives.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 17 Apr 2024 15:15:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Machine-cert-authentication-and-local-computer-certificate-store/m-p/211629#M40134</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-04-17T15:15:18Z</dc:date>
    </item>
    <item>
      <title>Re: Machine cert authentication and local computer certificate store</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Machine-cert-authentication-and-local-computer-certificate-store/m-p/211636#M40137</link>
      <description>&lt;P&gt;Machine certificates are used only when a user is not logged in (i.e. Windows login screen).&lt;BR /&gt;This is mentioned in the documentation I linked previously.&lt;/P&gt;
&lt;P&gt;As such, this is operating as expected.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Apr 2024 15:45:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Machine-cert-authentication-and-local-computer-certificate-store/m-p/211636#M40137</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-04-17T15:45:45Z</dc:date>
    </item>
    <item>
      <title>Re: Machine cert authentication and local computer certificate store</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Machine-cert-authentication-and-local-computer-certificate-store/m-p/211637#M40138</link>
      <description>&lt;P&gt;And I am now even more confused&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":grinning_squinting_face:"&gt;😆&lt;/span&gt; Or I just can't read properly. This is what I'm seeing in that doc.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;"&lt;SPAN class="Menu_Options"&gt;Machine-only authentication&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;- Authenticate with a machine certificate only. This mode is &lt;STRONG&gt;available before and after the user logs in&lt;/STRONG&gt; to Windows"&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Apr 2024 15:55:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Machine-cert-authentication-and-local-computer-certificate-store/m-p/211637#M40138</guid>
      <dc:creator>flachance</dc:creator>
      <dc:date>2024-04-17T15:55:18Z</dc:date>
    </item>
    <item>
      <title>Re: Machine cert authentication and local computer certificate store</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Machine-cert-authentication-and-local-computer-certificate-store/m-p/211648#M40140</link>
      <description>&lt;P&gt;Clearly I misread the docs &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;However, you may need to adjust some settings here:&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/RemoteAccessClients_forWindows_AdminGuide/Content/Topics-RA-VPN-for-Win/Configuring-Machine-Authentication-on-Client.htm?tocpath=Configuring%20Client%20Features%7CMachine%20Authentication%7C_____3" target="_blank"&gt;https://sc1.checkpoint.com/documents/RemoteAccessClients_forWindows_AdminGuide/Content/Topics-RA-VPN-for-Win/Configuring-Machine-Authentication-on-Client.htm?tocpath=Configuring%20Client%20Features%7CMachine%20Authentication%7C_____3&lt;/A&gt;&lt;BR /&gt;Specifically setting&amp;nbsp;&lt;SPAN&gt;machine_tunnel_after_logon to true.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Otherwise, you may want to get the TAC involved: &lt;A href="https://help.checkpoint.com" target="_blank"&gt;https://help.checkpoint.com&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Apr 2024 17:34:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Machine-cert-authentication-and-local-computer-certificate-store/m-p/211648#M40140</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-04-17T17:34:07Z</dc:date>
    </item>
  </channel>
</rss>

