<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: When renewing the https inspection cert, can I use a certificate from another management server? in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/When-renewing-the-https-inspection-cert-can-I-use-a-certificate/m-p/214210#M40885</link>
    <description>&lt;P&gt;The HTTPS Inspection certificate is a &lt;STRONG&gt;CA&lt;/STRONG&gt; certificate.&lt;BR /&gt;This is necessary as certificates are generated and signed&amp;nbsp;&lt;EM&gt;on the fly&lt;/EM&gt; based on where users are surfing to.&lt;BR /&gt;It is completely unrelated to the ICA of your existing management server; thus any one can be used provided clients can be configured to trust it.&lt;/P&gt;</description>
    <pubDate>Tue, 14 May 2024 17:09:44 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2024-05-14T17:09:44Z</dc:date>
    <item>
      <title>When renewing the https inspection cert, can I use a certificate from another management server?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/When-renewing-the-https-inspection-cert-can-I-use-a-certificate/m-p/214104#M40876</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The client's HTTPS Inspection Cert expires within 6 months.&lt;/P&gt;&lt;P&gt;So I plan to work on replacing the certificate soon.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But I have a problem.&lt;/P&gt;&lt;P&gt;As far as I know, if you press the certification renew button at checkpoint, the cert is automatically renewed.&lt;/P&gt;&lt;P&gt;As a result, there may be cases where the checkpoint gateway has 'new cert' and the client PC has 'old cert'.&lt;/P&gt;&lt;P&gt;the period for distributing certificates to clients after renewal is too short.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So I would like to distribute the certificate a week to a month in advance.&lt;/P&gt;&lt;P&gt;I would like to know if there is any problem if I proceed with the process below.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1.&amp;nbsp;Issue https inspection cert from another management server&lt;/P&gt;&lt;P&gt;2. Distributed to clients about a month ago&amp;nbsp;(GPO)&lt;/P&gt;&lt;P&gt;3.&amp;nbsp;Import a certificate distributed by another management server to the actual server.&lt;/P&gt;&lt;P&gt;4.&amp;nbsp;policy install an monitoring&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What I am most curious about here is whether it is okay to use a certificate issued by another management server.&lt;/P&gt;&lt;P&gt;I don't think there will be any technical problems, and when referring to the "best parctice", I didn't see any issues.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are there any problems that may arise when proceeding with step 4 above?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 May 2024 04:42:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/When-renewing-the-https-inspection-cert-can-I-use-a-certificate/m-p/214104#M40876</guid>
      <dc:creator>ChoiYunSoo</dc:creator>
      <dc:date>2024-05-14T04:42:56Z</dc:date>
    </item>
    <item>
      <title>Re: When renewing the https inspection cert, can I use a certificate from another management server?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/When-renewing-the-https-inspection-cert-can-I-use-a-certificate/m-p/214110#M40877</link>
      <description>&lt;P&gt;A Renewed certificate is different from a New cert - I think the existing certificate that is pushed out should still work after the cert is renewed, while you then get that renewed cert pushed out. I've not tested this though so if someone could confirm that would be great.&lt;/P&gt;</description>
      <pubDate>Tue, 14 May 2024 06:17:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/When-renewing-the-https-inspection-cert-can-I-use-a-certificate/m-p/214110#M40877</guid>
      <dc:creator>emmap</dc:creator>
      <dc:date>2024-05-14T06:17:15Z</dc:date>
    </item>
    <item>
      <title>Re: When renewing the https inspection cert, can I use a certificate from another management server?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/When-renewing-the-https-inspection-cert-can-I-use-a-certificate/m-p/214117#M40880</link>
      <description>&lt;P&gt;thank you for your reply&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I wrote this because I also needed the opinion of someone who had experienced it accurately.&lt;/P&gt;&lt;P&gt;The checkpoint guide document is not clearly expressed, so it is difficult to make an accurate judgment.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 May 2024 07:26:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/When-renewing-the-https-inspection-cert-can-I-use-a-certificate/m-p/214117#M40880</guid>
      <dc:creator>ChoiYunSoo</dc:creator>
      <dc:date>2024-05-14T07:26:15Z</dc:date>
    </item>
    <item>
      <title>Re: When renewing the https inspection cert, can I use a certificate from another management server?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/When-renewing-the-https-inspection-cert-can-I-use-a-certificate/m-p/214210#M40885</link>
      <description>&lt;P&gt;The HTTPS Inspection certificate is a &lt;STRONG&gt;CA&lt;/STRONG&gt; certificate.&lt;BR /&gt;This is necessary as certificates are generated and signed&amp;nbsp;&lt;EM&gt;on the fly&lt;/EM&gt; based on where users are surfing to.&lt;BR /&gt;It is completely unrelated to the ICA of your existing management server; thus any one can be used provided clients can be configured to trust it.&lt;/P&gt;</description>
      <pubDate>Tue, 14 May 2024 17:09:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/When-renewing-the-https-inspection-cert-can-I-use-a-certificate/m-p/214210#M40885</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-05-14T17:09:44Z</dc:date>
    </item>
  </channel>
</rss>

