<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Problem with ssl certificate - Quantum spark 1590 in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-ssl-certificate-Quantum-spark-1590/m-p/222247#M42566</link>
    <description>&lt;P&gt;You can replace step 4 with fw_configload which does a full policy recompile.&lt;/P&gt;</description>
    <pubDate>Tue, 30 Jul 2024 14:16:18 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2024-07-30T14:16:18Z</dc:date>
    <item>
      <title>Problem with ssl certificate - Quantum spark 1590</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-ssl-certificate-Quantum-spark-1590/m-p/215040#M41080</link>
      <description>&lt;P&gt;Good evening, everyone,&lt;/P&gt;&lt;P&gt;I hope someone can help me in this issue :&lt;/P&gt;&lt;P&gt;A few weeks ago we updated the ssl certificate for both the gateway portal and the VPN client.&lt;/P&gt;&lt;P&gt;Currently the portal is exposed on port 4434 while 443 is used for VPN RA.&lt;/P&gt;&lt;P&gt;When I access the portal on port 4434 the certificate is displayed correctly and the expiration date is correct .&lt;/P&gt;&lt;P&gt;However, if I check on port 443 it tells me that the certificate has expired, showing me the date of the last certificate.&lt;/P&gt;&lt;P&gt;We cleared all the cache and there is no trace of the old certificate.&lt;/P&gt;&lt;P&gt;We have opened a case at TAC and it tells us that all the operations were done correctly.&lt;/P&gt;&lt;P&gt;However on any site that checks on the certificate (ssl shopper or Qualys) it tells us that the certificate has expired.&lt;/P&gt;&lt;P&gt;It is the quantum spark 1590 series.&lt;/P&gt;&lt;P&gt;Has anyone ever encountered such an issue ?&lt;/P&gt;&lt;P&gt;Has the gateway already been rebooted/updated and any other tests with TAC&lt;/P&gt;&lt;P&gt;Thank you all.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 May 2024 18:55:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-ssl-certificate-Quantum-spark-1590/m-p/215040#M41080</guid>
      <dc:creator>aMatthew</dc:creator>
      <dc:date>2024-05-22T18:55:45Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with ssl certificate - Quantum spark 1590</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-ssl-certificate-Quantum-spark-1590/m-p/215042#M41081</link>
      <description>&lt;P&gt;I don't think it is possible as listed in:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk110533" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk110533&lt;/A&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;The Quantum Spark Appliance always presents its internal VPN certificate when it tries to establish a connection between the client endpoint and the site. The client host does not have this certificate installed.&lt;/LI&gt;
&lt;LI&gt;The VPN site certificate changed.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3&gt;Solution&lt;/H3&gt;
&lt;P&gt;This is expected behavior.&lt;BR /&gt;&lt;BR /&gt;Locally Managed Quantum Spark (SMB) appliances do not support internal certificate administration. These appliances always present their own VPN certificate, even if there are other certificates installed on the appliances.&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;Note -&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;You can verify the internal certificate in the appliance WebUI:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Device&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&amp;gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Certificates (Internal Certificate)&lt;/STRONG&gt;. This page shows two certificates: Internal CA Certificate and Internal VPN Certificate.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;They speak of local managed gateways, what about this gateway?&lt;/P&gt;</description>
      <pubDate>Wed, 22 May 2024 19:18:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-ssl-certificate-Quantum-spark-1590/m-p/215042#M41081</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-05-22T19:18:43Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with ssl certificate - Quantum spark 1590</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-ssl-certificate-Quantum-spark-1590/m-p/215043#M41082</link>
      <description>&lt;P&gt;Hi lesley,&lt;/P&gt;&lt;P&gt;I don't know if I explained myself well , I try to clarify:&lt;/P&gt;&lt;P&gt;Until a few weeks ago we had a third-party certificate that worked for both the web portal (port 4434) and the RA VPN (port 443) .&lt;BR /&gt;When we renewed the certificate if we connect to example.com:4434 the expiration date is correct. If we connect to &lt;A href="https://example.com" target="_blank"&gt;https://example.com&lt;/A&gt; it keeps giving us the old expiration date.&lt;/P&gt;</description>
      <pubDate>Wed, 22 May 2024 19:28:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-ssl-certificate-Quantum-spark-1590/m-p/215043#M41082</guid>
      <dc:creator>aMatthew</dc:creator>
      <dc:date>2024-05-22T19:28:37Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with ssl certificate - Quantum spark 1590</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-ssl-certificate-Quantum-spark-1590/m-p/215045#M41083</link>
      <description>&lt;P&gt;So it is central or local management what steps or guide you have followed?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 May 2024 19:39:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-ssl-certificate-Quantum-spark-1590/m-p/215045#M41083</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-05-22T19:39:26Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with ssl certificate - Quantum spark 1590</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-ssl-certificate-Quantum-spark-1590/m-p/222027#M42554</link>
      <description>&lt;P&gt;I have seen this multiple time with renewal of third party certificates and was just about to open a ticket on this.&amp;nbsp; The main portal on 4434 uses the new certificate successfully, but the SSL portal still used the old (expired) certificate.&amp;nbsp; The only work around I have found is to undo the certificate, turn off the SSL, reboot the box, then re-install the new certificate and turn ssl portal back on.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I believe that this is a problem where the ssl portal is storing this certificate elsewhere and it is not being updated when the ssl certificate is updated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Given the amount of time that we have all been using SSL certificates, you would think that these cert renewals would be straight forward by now and update correctly.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jul 2024 16:29:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-ssl-certificate-Quantum-spark-1590/m-p/222027#M42554</guid>
      <dc:creator>Ted_Serreyn</dc:creator>
      <dc:date>2024-07-26T16:29:57Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with ssl certificate - Quantum spark 1590</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-ssl-certificate-Quantum-spark-1590/m-p/222038#M42555</link>
      <description>&lt;P&gt;Just to clarify, you mean the SNX portal, correct?&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jul 2024 18:51:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-ssl-certificate-Quantum-spark-1590/m-p/222038#M42555</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-07-26T18:51:03Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with ssl certificate - Quantum spark 1590</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-ssl-certificate-Quantum-spark-1590/m-p/222039#M42556</link>
      <description>&lt;P&gt;Hi Ted ,&lt;/P&gt;&lt;P&gt;thanks for the comment.&lt;/P&gt;&lt;P&gt;the problem was solved by the TAC after a long analysis.&lt;/P&gt;&lt;P&gt;We deleted some files and references of the old certificate via CLI. In these days I will try to publish the solution .&lt;/P&gt;&lt;P&gt;thank you all for your time .&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jul 2024 18:58:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-ssl-certificate-Quantum-spark-1590/m-p/222039#M42556</guid>
      <dc:creator>aMatthew</dc:creator>
      <dc:date>2024-07-26T18:58:01Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with ssl certificate - Quantum spark 1590</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-ssl-certificate-Quantum-spark-1590/m-p/222040#M42557</link>
      <description>&lt;P&gt;Hi PhoneBoy,&lt;/P&gt;&lt;P&gt;thanks for the comment.&lt;/P&gt;&lt;P&gt;the problem was solved by the TAC after a long analysis.&lt;/P&gt;&lt;P&gt;We deleted some files and references of the old certificate via CLI. In these days I will try to publish the solution .&lt;/P&gt;&lt;P&gt;thank you all for your time .&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jul 2024 18:56:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-ssl-certificate-Quantum-spark-1590/m-p/222040#M42557</guid>
      <dc:creator>aMatthew</dc:creator>
      <dc:date>2024-07-26T18:56:50Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with ssl certificate - Quantum spark 1590</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-ssl-certificate-Quantum-spark-1590/m-p/222160#M42561</link>
      <description>&lt;P&gt;technically yes, but not how it is displayed or labeled on a 1500 series box running R81.10.10 or later.&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2024-07-29 164022.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/27026i93FAACD58D3F7601/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2024-07-29 164022.png" alt="Screenshot 2024-07-29 164022.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jul 2024 21:42:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-ssl-certificate-Quantum-spark-1590/m-p/222160#M42561</guid>
      <dc:creator>Ted_Serreyn</dc:creator>
      <dc:date>2024-07-29T21:42:21Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with ssl certificate - Quantum spark 1590</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-ssl-certificate-Quantum-spark-1590/m-p/222163#M42562</link>
      <description>&lt;P&gt;Would be “SSL VPN” in that screenshot.&lt;BR /&gt;Had the SNX Portal on my mind for a different thread &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jul 2024 23:22:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-ssl-certificate-Quantum-spark-1590/m-p/222163#M42562</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-07-29T23:22:27Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with ssl certificate - Quantum spark 1590</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-ssl-certificate-Quantum-spark-1590/m-p/222198#M42563</link>
      <description>&lt;P&gt;hi ted,&lt;/P&gt;&lt;P&gt;as already discussed the problem is related to DB corruption.&lt;/P&gt;&lt;P&gt;Although the new certificate is loaded, doing an ssl check still detects the old expiration date.&lt;/P&gt;&lt;P&gt;I solved it this way:&lt;/P&gt;&lt;P&gt;1. Delete $FWDIR/conf/fwauth.NDB.&lt;BR /&gt;2. Run 'sfwd_restart'&lt;BR /&gt;3. Run 'vpn_configload;fw reconf_sfwd'&lt;BR /&gt;4. Add a new local user (it might be a temporary user, just to apply the change),&lt;BR /&gt;5. Optional : re-add the 3rd party certificate.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jul 2024 08:12:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-ssl-certificate-Quantum-spark-1590/m-p/222198#M42563</guid>
      <dc:creator>aMatthew</dc:creator>
      <dc:date>2024-07-30T08:12:59Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with ssl certificate - Quantum spark 1590</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-ssl-certificate-Quantum-spark-1590/m-p/222247#M42566</link>
      <description>&lt;P&gt;You can replace step 4 with fw_configload which does a full policy recompile.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jul 2024 14:16:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-ssl-certificate-Quantum-spark-1590/m-p/222247#M42566</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-07-30T14:16:18Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with ssl certificate - Quantum spark 1590</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-ssl-certificate-Quantum-spark-1590/m-p/269284#M53291</link>
      <description>&lt;P&gt;I'm not sure this classes as the same issue, but I've uploaded some external certificates (device and cluster) to spark devices I have in order to replace the default device cert presented for administration over port 4434.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In the WEBUI its applied. I raised a TAC case, and was a little surprised what they told me, I need to also install the certificate on the client! (I hoping this is just a communication issue).&lt;BR /&gt;&lt;BR /&gt;We are not running any VPNs on these device, and the objective is for the valid certificate to be presented to the client when we attempt to access the WEBUI.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Jan 2026 20:26:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-ssl-certificate-Quantum-spark-1590/m-p/269284#M53291</guid>
      <dc:creator>genisis__</dc:creator>
      <dc:date>2026-01-30T20:26:10Z</dc:date>
    </item>
  </channel>
</rss>

