<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to install a wildcard certificate without generating a CSR from each gateway in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-install-a-wildcard-certificate-without-generating-a-CSR/m-p/233826#M45273</link>
    <description>&lt;P&gt;Do you use a IP-address for the gateway? That's not possible. The wildcard just includes domains. There is not wildcard IP-address certificate. You have to use FQDN.&lt;/P&gt;</description>
    <pubDate>Tue, 26 Nov 2024 14:23:27 GMT</pubDate>
    <dc:creator>Daniel_</dc:creator>
    <dc:date>2024-11-26T14:23:27Z</dc:date>
    <item>
      <title>How to install a wildcard certificate without generating a CSR from each gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-install-a-wildcard-certificate-without-generating-a-CSR/m-p/233722#M45236</link>
      <description>&lt;P&gt;Hello.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm trying to use a 3rd party wildcard certificate for GAIA portal access to some of our firewalls.&amp;nbsp; A CP engineer and I installed wildcard.key file as server.key and the .crt file as server.crt but the IP was still resolving to the ISP domain name so it was giving a domain mismatch error.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I got that fixed and now the ip resolves to our domain but the website still shows an error and says that the domains do not match.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I got a new engineer who says we have to do a CSR for each gateway and cannot use the wildcard certificate.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is this the case or were we just not communicating?&lt;/P&gt;</description>
      <pubDate>Mon, 25 Nov 2024 22:07:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-install-a-wildcard-certificate-without-generating-a-CSR/m-p/233722#M45236</guid>
      <dc:creator>AaronPW</dc:creator>
      <dc:date>2024-11-25T22:07:03Z</dc:date>
    </item>
    <item>
      <title>Re: How to install a wildcard certificate without generating a CSR from each gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-install-a-wildcard-certificate-without-generating-a-CSR/m-p/233728#M45244</link>
      <description>&lt;P&gt;As far as I know, this is supported.&lt;BR /&gt;Are you accessing the Gaia WebUI by FQDN?&lt;/P&gt;</description>
      <pubDate>Mon, 25 Nov 2024 23:29:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-install-a-wildcard-certificate-without-generating-a-CSR/m-p/233728#M45244</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-11-25T23:29:54Z</dc:date>
    </item>
    <item>
      <title>Re: How to install a wildcard certificate without generating a CSR from each gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-install-a-wildcard-certificate-without-generating-a-CSR/m-p/233738#M45250</link>
      <description>&lt;P&gt;Im fairly positive you can use wildcard cert, had seen customers do it before.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 26 Nov 2024 03:13:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-install-a-wildcard-certificate-without-generating-a-CSR/m-p/233738#M45250</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-11-26T03:13:28Z</dc:date>
    </item>
    <item>
      <title>Re: How to install a wildcard certificate without generating a CSR from each gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-install-a-wildcard-certificate-without-generating-a-CSR/m-p/233826#M45273</link>
      <description>&lt;P&gt;Do you use a IP-address for the gateway? That's not possible. The wildcard just includes domains. There is not wildcard IP-address certificate. You have to use FQDN.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Nov 2024 14:23:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-install-a-wildcard-certificate-without-generating-a-CSR/m-p/233826#M45273</guid>
      <dc:creator>Daniel_</dc:creator>
      <dc:date>2024-11-26T14:23:27Z</dc:date>
    </item>
    <item>
      <title>Re: How to install a wildcard certificate without generating a CSR from each gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-install-a-wildcard-certificate-without-generating-a-CSR/m-p/236914#M45936</link>
      <description>&lt;P&gt;If you are wanting to change the GAIA portal certificate - you want to use the Platform Portal section of the Gateway Properties to change the certificate. Don't manually change the files at the CLI. I think it is possible to edit the files, then restart the service, but with the multiportal it is easier to do it this way. Just don't forget to install the policy after making the change.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;DIV id="tinyMceEditor_2fb678d92ea2c1CP_Chris_0" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV id="tinyMceEditor_2fb678d92ea2c1CP_Chris_1" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="portal cert.jpg" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/29016iFD05A5FC2EAF9364/image-size/large?v=v2&amp;amp;px=999" role="button" title="portal cert.jpg" alt="portal cert.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Thu, 26 Dec 2024 21:12:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-install-a-wildcard-certificate-without-generating-a-CSR/m-p/236914#M45936</guid>
      <dc:creator>CP_Chris</dc:creator>
      <dc:date>2024-12-26T21:12:26Z</dc:date>
    </item>
    <item>
      <title>Re: How to install a wildcard certificate without generating a CSR from each gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-install-a-wildcard-certificate-without-generating-a-CSR/m-p/244444#M47568</link>
      <description>&lt;P&gt;And when it's in a cluster you use the internal VIP for the FQDN.&amp;nbsp; However, since the VIP FQDN of a member is a different ip then the VIP you still get a warning.&amp;nbsp; Not to mention the standby member...&amp;nbsp; Also, there is no portal platform section on a manager.&amp;nbsp;&amp;nbsp; For the manager you must need to trust the CP ICA to your browsers trusted CAs store.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Mar 2025 15:57:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-install-a-wildcard-certificate-without-generating-a-CSR/m-p/244444#M47568</guid>
      <dc:creator>Daniel_Kavan</dc:creator>
      <dc:date>2025-03-21T15:57:30Z</dc:date>
    </item>
    <item>
      <title>Re: How to install a wildcard certificate without generating a CSR from each gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-install-a-wildcard-certificate-without-generating-a-CSR/m-p/245888#M47912</link>
      <description>&lt;P&gt;You can use the SAN to create multiple FQDN and IP address matches so a single cert works for the cluster. See&amp;nbsp;&lt;SPAN&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk170395" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk170395&lt;/A&gt;. Note it only shows DNS options for FQDN, but you can also use IP options for IP address in case you go to the portal via IP. Example:&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;subjectAltName = &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/28757"&gt;@VPN&lt;/a&gt;_names&lt;BR /&gt;[vpn_names]&lt;BR /&gt;DNS.1 = &lt;A href="http://www.abc.com" target="_blank"&gt;www.abc.com&lt;/A&gt;&lt;BR /&gt;DNS.2 = abc.com&lt;BR /&gt;DNS.3 = sub.abc.com&lt;BR /&gt;DNS.4 = sub2.abc.net&lt;BR /&gt;IP.1 = 172.25.105.136&lt;BR /&gt;IP.2 = 172.25.105.134&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Apr 2025 18:00:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-install-a-wildcard-certificate-without-generating-a-CSR/m-p/245888#M47912</guid>
      <dc:creator>CP_Chris</dc:creator>
      <dc:date>2025-04-07T18:00:33Z</dc:date>
    </item>
  </channel>
</rss>

