<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Identity Collector and Gateway certificates - which one? in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-and-Gateway-certificates-which-one/m-p/246365#M48004</link>
    <description>&lt;P&gt;yuo can control which certificate IDC uses.&lt;/P&gt;
&lt;P&gt;example: you can associate your Certificate signed by your CA to user check portal&lt;/P&gt;
&lt;P&gt;the user check portal will be associate to an ip ad an fqdn to make certificate working... so simply configure usercheck ip to IDC and your own certificate will be prompted to be trusted&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;that ip/fqdn/certificate association needs to be unique on FW to avoid overlapping with other portals&lt;/P&gt;
&lt;P&gt;i have environment with usercheck and captive portal associated to same ip, fqdn and certificate... from idc i configure IP of them&lt;/P&gt;</description>
    <pubDate>Mon, 14 Apr 2025 10:47:49 GMT</pubDate>
    <dc:creator>CheckPointerXL</dc:creator>
    <dc:date>2025-04-14T10:47:49Z</dc:date>
    <item>
      <title>Identity Collector and Gateway certificates - which one?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-and-Gateway-certificates-which-one/m-p/246278#M47994</link>
      <description>&lt;P&gt;A question to which I think I know the answer, but thought I'd see if anyone knows of an "official answer".&amp;nbsp; We use Identity Collectors in our various environments: production, lab, etc. In our lab. the certificate used by the Identity Collector to validate the gateway is the platform portal certificate, issued by our internal Windows CA. Our lab gateways also have an IPSec certificate, issued by our SMS.&lt;/P&gt;
&lt;P&gt;In our production environment, the certificate used by the Identity Collector to validate the gateway is the IPSec certificate, issued by our SMS. These gateways do not have a platform portal certificate.&lt;/P&gt;
&lt;P&gt;So my question is - where a gateway has a certificate for the platform portal and for IPSec VPN, does the Identity Collector default to the platform portal? Or is there a way to choose what it uses?&lt;/P&gt;
&lt;P&gt;Dave&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Apr 2025 19:33:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-and-Gateway-certificates-which-one/m-p/246278#M47994</guid>
      <dc:creator>David_C1</dc:creator>
      <dc:date>2025-04-11T19:33:52Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector and Gateway certificates - which one?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-and-Gateway-certificates-which-one/m-p/246365#M48004</link>
      <description>&lt;P&gt;yuo can control which certificate IDC uses.&lt;/P&gt;
&lt;P&gt;example: you can associate your Certificate signed by your CA to user check portal&lt;/P&gt;
&lt;P&gt;the user check portal will be associate to an ip ad an fqdn to make certificate working... so simply configure usercheck ip to IDC and your own certificate will be prompted to be trusted&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;that ip/fqdn/certificate association needs to be unique on FW to avoid overlapping with other portals&lt;/P&gt;
&lt;P&gt;i have environment with usercheck and captive portal associated to same ip, fqdn and certificate... from idc i configure IP of them&lt;/P&gt;</description>
      <pubDate>Mon, 14 Apr 2025 10:47:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-and-Gateway-certificates-which-one/m-p/246365#M48004</guid>
      <dc:creator>CheckPointerXL</dc:creator>
      <dc:date>2025-04-14T10:47:49Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector and Gateway certificates - which one?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-and-Gateway-certificates-which-one/m-p/246377#M48011</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/54489"&gt;@CheckPointerXL&lt;/a&gt;&amp;nbsp;explained it perfectly.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 14 Apr 2025 11:58:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-and-Gateway-certificates-which-one/m-p/246377#M48011</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-04-14T11:58:29Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector and Gateway certificates - which one?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-and-Gateway-certificates-which-one/m-p/246403#M48023</link>
      <description>&lt;P&gt;Thanks for this information. Your explanation makes sense, but it does not match my configuration. I have cert assigned to my captive portal (and same cert assigned to my platform portal) with an IP of 10.1.1.1. This cert has a number of Subject Alternate Names, both DNS entries and IP addresses. The IP address I used in the IDC configuration to establish connection with this cluster is neither 10.1.1.1 nor any of the SAN entries - it is a different interface on the firewall (the interface for the network that the IDC is on). When I look at the Certificate Info on the gateway config on the IDC, it&amp;nbsp;&lt;STRONG&gt;is&lt;/STRONG&gt; using the usercheck/platform portal cert, but again the IP address used to configure the gateway is not 10.1.1.1 nor any of the addresses listed as a Subject Alternate Name.&lt;/P&gt;
&lt;P&gt;Still a bit stumped.&lt;/P&gt;
&lt;P&gt;Dave&lt;/P&gt;</description>
      <pubDate>Mon, 14 Apr 2025 13:12:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-and-Gateway-certificates-which-one/m-p/246403#M48023</guid>
      <dc:creator>David_C1</dc:creator>
      <dc:date>2025-04-14T13:12:05Z</dc:date>
    </item>
  </channel>
</rss>

