<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Usercheck Block Page is Insecure/Private in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Usercheck-Block-Page-is-Insecure-Private/m-p/20213#M58542</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If the CA that signed that certificate isn't trusted by the browser, you'll still get the error.&lt;/P&gt;&lt;P&gt;That's the issue you need to fix &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;There's nothing wrong with using SHA256--no specific precautions are required that I am aware of.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 18 Aug 2018 14:58:29 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2018-08-18T14:58:29Z</dc:date>
    <item>
      <title>Usercheck Block Page is Insecure/Private</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Usercheck-Block-Page-is-Insecure-Private/m-p/20210#M58539</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;UL&gt;&lt;LI&gt;Application Control &amp;amp; URL filtering is enabled&lt;/LI&gt;&lt;LI&gt;HTTPS Inspection is also enabled. Outbound Certificate is deployed in the organization and No SSL error, thanks to that. Can see HTTPS outbound certificate on browsing Internet.&lt;/LI&gt;&lt;LI&gt;When trying to access a blocked &lt;STRONG&gt;http&lt;/STRONG&gt;://website_A, block page appears.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;When trying to access a blocked &lt;STRONG&gt;https&lt;/STRONG&gt;://website_A, Connection is insecure / private message appears and when selected to proceed Block page appears. Certificate on the block page is not same as HTTPS Outbound certificate. Extracted the certificate from browser and installed the same. Still at every other blocked &lt;STRONG&gt;https&lt;/STRONG&gt;://website_X , connection is not secure prompt is shown before proceeding manual to block page&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Customer is getting the Connection is not secure prompt before usercheck block page. Customer is quite cautious towards compliance and even the HTTPS Inspection Outbound certificate has been created with sha 256 algo.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As per customer HTTPS Usercheck Block page is not compliant as per there organization policy because it gives prompt for page being not secure&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;how to solve the same?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/69255_pastedImage_3.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.checkpoint.com/migrated-users/2075"&gt;Dameon Welch Abernathy&lt;/A&gt;‌ help here &lt;img id="smileysad" class="emoticon emoticon-smileysad" src="https://community.checkpoint.com/i/smilies/16x16_smiley-sad.png" alt="Smiley Sad" title="Smiley Sad" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 18 Aug 2018 12:10:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Usercheck-Block-Page-is-Insecure-Private/m-p/20210#M58539</guid>
      <dc:creator>Nikhil_Deshmukh</dc:creator>
      <dc:date>2018-08-18T12:10:16Z</dc:date>
    </item>
    <item>
      <title>Re: Usercheck Block Page is Insecure/Private</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Usercheck-Block-Page-is-Insecure-Private/m-p/20211#M58540</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You have to configure the certificate used for Usercheck.&lt;/P&gt;&lt;P&gt;See my comment here:&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" class="link-titled" href="https://community.checkpoint.com/thread/7984-usercheck-portal-certificate-problem-when-fws-ip-address-is-changed#comment-20551" title="https://community.checkpoint.com/thread/7984-usercheck-portal-certificate-problem-when-fws-ip-address-is-changed#comment-20551"&gt;https://community.checkpoint.com/thread/7984-usercheck-portal-certificate-problem-when-fws-ip-address-is-changed#comment…&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 18 Aug 2018 13:00:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Usercheck-Block-Page-is-Insecure-Private/m-p/20211#M58540</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-08-18T13:00:47Z</dc:date>
    </item>
    <item>
      <title>Re: Usercheck Block Page is Insecure/Private</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Usercheck-Block-Page-is-Insecure-Private/m-p/20212#M58541</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Agreed to the thread shared.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I also did generate the certificate through openssl, with DN name to match the IP address; as with cluster hostname it was giving me prompt that you'll face ssl error.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the end it still doesn't work with the imported certificate for usercheck.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My obervations:-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;When trying to access a blocked &lt;STRONG&gt;https&lt;/STRONG&gt;://website_A, Connection is insecure / private message appears and when selected to proceed Block page appears. Certificate is the one i created through open ssl and imported in Cluster&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Also at every other blocked &lt;STRONG&gt;https&lt;/STRONG&gt;://website_&lt;STRONG&gt;x&lt;/STRONG&gt;, connection is not secure appears before proceeding manual to block page&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried this before, will give it another shot.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also would you recommend using SHA256 certificates; and Cluster performance cautions i should take?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 18 Aug 2018 14:07:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Usercheck-Block-Page-is-Insecure-Private/m-p/20212#M58541</guid>
      <dc:creator>Nikhil_Deshmukh</dc:creator>
      <dc:date>2018-08-18T14:07:39Z</dc:date>
    </item>
    <item>
      <title>Re: Usercheck Block Page is Insecure/Private</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Usercheck-Block-Page-is-Insecure-Private/m-p/20213#M58542</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If the CA that signed that certificate isn't trusted by the browser, you'll still get the error.&lt;/P&gt;&lt;P&gt;That's the issue you need to fix &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;There's nothing wrong with using SHA256--no specific precautions are required that I am aware of.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 18 Aug 2018 14:58:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Usercheck-Block-Page-is-Insecure-Private/m-p/20213#M58542</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-08-18T14:58:29Z</dc:date>
    </item>
    <item>
      <title>Re: Usercheck Block Page is Insecure/Private</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Usercheck-Block-Page-is-Insecure-Private/m-p/20214#M58543</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm generating 2 certificate's through openssl (SHA256), one for HTTPS Inspection and other for Usercheck block page.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTTPS inspection works fine but the Usercheck Block page doesn't work as expected.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;As said earlier, My obervations:-&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="min-height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;When trying to access a blocked &lt;STRONG&gt;https&lt;/STRONG&gt;://website_A, Connection is insecure / private message appears and when selected to proceed Block page appears. Certificate shown on Block page is the one i created through open ssl for Usercheck Block Page&lt;/LI&gt;&lt;/UL&gt;&lt;P style="min-height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Then at every other blocked &lt;STRONG&gt;https&lt;/STRONG&gt;://website_&lt;STRONG&gt;x&lt;/STRONG&gt;, connection is not secure appears before proceeding manual to block page&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"&lt;EM&gt;If the CA that signed that certificate isn't trusted by the browser, you'll still get the error.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;That's the issue you need to fix "&lt;SPAN class="" style="height: 16px; width: 16px;"&gt;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have made both certificates CA as "&lt;SPAN class=""&gt;Trusted Root Certification Authorities". Still getting ssl error for Usercheck Block Page&amp;nbsp; &lt;IMG src="https://community.checkpoint.com/legacyfs/online/checkpoint/emoticons/confused.png" /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;I did all this before, will give it another shot.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 18 Aug 2018 17:40:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Usercheck-Block-Page-is-Insecure-Private/m-p/20214#M58543</guid>
      <dc:creator>Nikhil_Deshmukh</dc:creator>
      <dc:date>2018-08-18T17:40:04Z</dc:date>
    </item>
    <item>
      <title>Re: Usercheck Block Page is Insecure/Private</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Usercheck-Block-Page-is-Insecure-Private/m-p/20215#M58544</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;How did you generate the certificate for UserCheck with OpenSSL?&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;If you generated it as a self-signed certificate (which is what I suspect), then the browser must be configured to accept this self-signed certificate as valid. You follow the same steps you followed to get your organization to trust the HTTPS Inspection certificate. You can validate this on your own PC by clicking on the "Install Certificate" button as shown in your screenshot.&lt;/LI&gt;&lt;LI&gt;If you signed the certificate with a certificate authority the browser already trusts, then no configuration should be required.&lt;/LI&gt;&lt;/UL&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 18 Aug 2018 17:51:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Usercheck-Block-Page-is-Insecure-Private/m-p/20215#M58544</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-08-18T17:51:11Z</dc:date>
    </item>
    <item>
      <title>Re: Usercheck Block Page is Insecure/Private</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Usercheck-Block-Page-is-Insecure-Private/m-p/20216#M58545</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please check if the UserCheck URL is changed to https. By default, it is http:&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="69265" class="image-1 jive-image" height="296" src="https://community.checkpoint.com/legacyfs/online/checkpoint/69265_pastedImage_1.png" width="610" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Additionally, make sure that once the https is enabled, the Root CA issuing the certificate is added to your clients' Trusted Root CAs IN ADDITION to the actual certificate for that of the UserCheck portal.&lt;/P&gt;&lt;P&gt;Otherwise, validation of the Issuing CA's certificate will fail.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You may find this of interest or help:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-bottom: .0001pt;"&gt;…possible reason you are keep getting the “untrusted” messages in the browsers is due to your CheckPoint Management Server’s certificate not being included in the Trusted Root CAs.&lt;/P&gt;&lt;P style="margin-bottom: .0001pt;"&gt;&lt;/P&gt;&lt;P style="margin-bottom: .0001pt;"&gt;"This portal using an auto-generated&amp;nbsp; certificate. You can import your own certificate" is actually referring to the VPN cert.&lt;/P&gt;&lt;P style="margin-bottom: .0001pt;"&gt;&lt;/P&gt;&lt;P style="margin-bottom: .0001pt;"&gt;When browser sees the VPN cert, it is trying to verify who has issued it and if it can trust the issuer.&lt;/P&gt;&lt;P style="margin-bottom: .0001pt;"&gt;The VPN cert is issued not by the gateway, but by the Management Server.&lt;/P&gt;&lt;P style="margin-bottom: .0001pt;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="margin-bottom: .0001pt;"&gt;For you not to see warnings for UserCheck and VPN, three certificates must be installed in each computer’s Trusted Root CAs:&lt;/P&gt;&lt;OL style="margin-top: 0in;"&gt;&lt;LI style="margin-bottom: .0001pt;"&gt;SSL/HTTPS Inspection certificate&lt;/LI&gt;&lt;LI style="margin-bottom: .0001pt;"&gt;Cluster’s VPN certificate&lt;/LI&gt;&lt;LI style="margin-bottom: .0001pt;"&gt;Management Server’s Root CA certificate&lt;/LI&gt;&lt;/OL&gt;&lt;P style="margin-bottom: .0001pt;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="margin-bottom: .0001pt;"&gt;See the screenshots below:&lt;/P&gt;&lt;P style="margin-bottom: .0001pt;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="margin-bottom: .0001pt;"&gt;&amp;nbsp;&lt;/P&gt;&lt;OL style="margin-top: 0in;"&gt;&lt;LI style="margin-bottom: .0001pt;"&gt;Working VPN Cert:&lt;/LI&gt;&lt;/OL&gt;&lt;P style="margin-bottom: .0001pt;"&gt;&amp;nbsp;&lt;IMG __jive_id="69266" class="image-2 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/69266_pastedImage_2.png" /&gt;&lt;/P&gt;&lt;P style="margin-bottom: .0001pt;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="margin-bottom: .0001pt;"&gt;&amp;nbsp;2. Exporting VPN Cert using Chrome&lt;/P&gt;&lt;P style="margin-bottom: .0001pt;"&gt;&amp;nbsp;&lt;IMG __jive_id="69267" class="image-3 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/69267_pastedImage_3.png" /&gt;&lt;/P&gt;&lt;P style="margin-bottom: .0001pt;"&gt;&amp;nbsp;3., 4. &amp;nbsp;Exporting VPN Cert Using Chrome continues&lt;/P&gt;&lt;P style="margin-bottom: .0001pt;"&gt;&amp;nbsp;&lt;IMG __jive_id="69268" class="jive-image image-4" height="320" src="https://community.checkpoint.com/legacyfs/online/checkpoint/69268_pastedImage_4.png" width="332" /&gt;&amp;nbsp;&lt;IMG __jive_id="69269" class="image-5 jive-image" height="321" src="https://community.checkpoint.com/legacyfs/online/checkpoint/69269_pastedImage_5.png" width="333" /&gt;&lt;/P&gt;&lt;P style="margin-bottom: .0001pt;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="margin-bottom: .0001pt;"&gt;5. Saving VPN Cert&lt;/P&gt;&lt;P style="margin-bottom: .0001pt;"&gt;&amp;nbsp;&lt;IMG __jive_id="69270" class="image-6 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/69270_pastedImage_6.png" /&gt;&lt;/P&gt;&lt;P style="margin-bottom: .0001pt;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="margin-bottom: .0001pt;"&gt;6. Navigating up the Certification path (In “General” tab, we are still looking at the VPN Certificate, but in Certification Path, we are moving to the Root)&lt;/P&gt;&lt;P style="margin-bottom: .0001pt;"&gt;&amp;nbsp;&lt;IMG __jive_id="69271" class="image-7 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/69271_pastedImage_7.png" /&gt;&lt;/P&gt;&lt;P style="margin-bottom: .0001pt;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="margin-bottom: .0001pt;"&gt;7., 8. Root CA Certification export continues&lt;/P&gt;&lt;P style="margin-bottom: .0001pt;"&gt;&lt;IMG __jive_id="69272" class="jive-image image-8" height="442" src="https://community.checkpoint.com/legacyfs/online/checkpoint/69272_pastedImage_8.png" width="351" /&gt;&amp;nbsp;&lt;IMG __jive_id="69273" class="image-9 jive-image" height="441" src="https://community.checkpoint.com/legacyfs/online/checkpoint/69273_pastedImage_9.png" width="351" /&gt;&lt;/P&gt;&lt;P style="margin-bottom: .0001pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P style="margin-bottom: .0001pt;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="margin-bottom: .0001pt;"&gt;9., 10.&amp;nbsp; Root CA Certification export continues&lt;/P&gt;&lt;P style="margin-bottom: .0001pt;"&gt;&lt;IMG __jive_id="69274" class="jive-image image-10" height="341" src="https://community.checkpoint.com/legacyfs/online/checkpoint/69274_pastedImage_10.png" width="354" /&gt;&amp;nbsp;&lt;IMG __jive_id="69275" class="image-11 jive-image" height="342" src="https://community.checkpoint.com/legacyfs/online/checkpoint/69275_pastedImage_11.png" width="354" /&gt;&lt;/P&gt;&lt;P style="margin-bottom: .0001pt;"&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P style="margin-bottom: .0001pt;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="margin-bottom: .0001pt;"&gt;&amp;nbsp;11. Saving CheckPoint Management Root CA&lt;/P&gt;&lt;P style="margin-bottom: .0001pt;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="margin-bottom: .0001pt;"&gt;&amp;nbsp;&lt;IMG __jive_id="69276" class="image-12 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/69276_pastedImage_12.png" /&gt;&lt;/P&gt;&lt;P style="margin-bottom: .0001pt;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="margin-bottom: .0001pt;"&gt;&lt;/P&gt;&lt;P style="margin-bottom: .0001pt;"&gt;12. All three certificates must be present in Trusted Root CAs on every computer to avoid certificate warnings with UserCheck and VPN.&lt;/P&gt;&lt;P style="margin-bottom: .0001pt;"&gt;&amp;nbsp;&lt;IMG __jive_id="69277" class="image-13 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/69277_pastedImage_13.png" /&gt;&lt;/P&gt;&lt;P style="margin-bottom: .0001pt;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="margin-bottom: .0001pt;"&gt;Cheers,&lt;/P&gt;&lt;P style="margin-bottom: .0001pt;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="margin-bottom: .0001pt;"&gt;Vladimir&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 19 Aug 2018 13:23:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Usercheck-Block-Page-is-Insecure-Private/m-p/20216#M58545</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2018-08-19T13:23:21Z</dc:date>
    </item>
    <item>
      <title>Re: Usercheck Block Page is Insecure/Private</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Usercheck-Block-Page-is-Insecure-Private/m-p/20217#M58546</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks &lt;A href="https://community.checkpoint.com/migrated-users/48025"&gt;Vladimir Yakovlev&lt;/A&gt;‌ &amp;amp; &lt;A href="https://community.checkpoint.com/migrated-users/2075"&gt;Dameon Welch Abernathy&lt;/A&gt;‌.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Such detailed explanation, it becomes really helpful to everyone.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The certificate issued by the Management to the Gateway (Server Certificate) also contains IP address as a Alternate Subject Name.&lt;/P&gt;&lt;P&gt;I was able to drill down the issue with our Customer regarding this.&lt;/P&gt;&lt;P&gt;Customer changed the Gateway Cluster Object's IP address which changed the Platform &amp;amp; Usercheck Portal's Main URL.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Browser's opened Block Page on the new URL and the certificate didn't match the URL w.r.t. Alternate Subject Name.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hence the error ERR_CERT_COMMON_NAME_INVALID (Chrome)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We can renew the certificate and update other interface IP also (if required)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/69995_pastedImage_3.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-2 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/69996_pastedImage_4.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Once certificate was renewed and published to user's, No error prompt in browser's faced by user's.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Note:-&lt;/STRONG&gt; When creating a Certificate from Organizational Internal CA then also it important to mention the Subject Alternate Name.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sorry for such late reply &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Additional Reference :- &lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk121502" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk121502"&gt;UserCheck redirects to HTTPS even when UserCheck Portal is configured as HTTP&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Sep 2018 07:53:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Usercheck-Block-Page-is-Insecure-Private/m-p/20217#M58546</guid>
      <dc:creator>Nikhil_Deshmukh</dc:creator>
      <dc:date>2018-09-04T07:53:22Z</dc:date>
    </item>
    <item>
      <title>Re: Usercheck Block Page is Insecure/Private</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Usercheck-Block-Page-is-Insecure-Private/m-p/61426#M58547</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;I have the question, maybe you can help me&lt;/P&gt;&lt;P&gt;My client deploys the Captive Portal for PCs external to those of the organization in a wireless network, there is some way to download and install the certificate automatically when trying to connect to the captive portal?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Aug 2019 22:24:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Usercheck-Block-Page-is-Insecure-Private/m-p/61426#M58547</guid>
      <dc:creator>Sandra_Suarez</dc:creator>
      <dc:date>2019-08-28T22:24:40Z</dc:date>
    </item>
    <item>
      <title>Re: Usercheck Block Page is Insecure/Private</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Usercheck-Block-Page-is-Insecure-Private/m-p/61513#M58548</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I was able to do it, but i searched a bit before finding it&lt;/P&gt;&lt;P&gt;From Windows, certificate authority and generate a dedicated WebServer template.&lt;/P&gt;&lt;P&gt;-&amp;gt; That can be exportable with Private key&lt;/P&gt;&lt;P&gt;-&amp;gt; One that i can change the "Issued To"&lt;/P&gt;&lt;P&gt;-&amp;gt; I've then made a request via MMC -&amp;gt; Local Computer&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture0.PNG" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/2363iDD281FBED6476B79/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Capture0.PNG" alt="Capture0.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture1.PNG" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/2364i99BC73E933341DEC/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Capture1.PNG" alt="Capture1.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture2.PNG" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/2365i51AA3E480BA0C078/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Capture2.PNG" alt="Capture2.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And it works in a domain environment.&lt;/P&gt;&lt;P&gt;Everybody if is trusting the domain (which is normal by default in Windows domain as it was issued by the domain CA)&amp;nbsp; will work like a charm&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind regards,&lt;/P&gt;&lt;P&gt;David.D&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Thu, 29 Aug 2019 21:02:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Usercheck-Block-Page-is-Insecure-Private/m-p/61513#M58548</guid>
      <dc:creator>David_David</dc:creator>
      <dc:date>2019-08-29T21:02:40Z</dc:date>
    </item>
    <item>
      <title>Re: Usercheck Block Page is Insecure/Private</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Usercheck-Block-Page-is-Insecure-Private/m-p/147465#M58549</link>
      <description>&lt;P&gt;Speaking of late replies:)&lt;/P&gt;
&lt;P&gt;Just run into this thread with similar situation: UserCheck portal has different IP address from main portal. Thanks to your reply I was able to re-issue the cert with second IP in SAN to solve the issue.&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;Vladimir&lt;/P&gt;</description>
      <pubDate>Fri, 29 Apr 2022 13:09:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Usercheck-Block-Page-is-Insecure-Private/m-p/147465#M58549</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2022-04-29T13:09:25Z</dc:date>
    </item>
    <item>
      <title>Re: Usercheck Block Page is Insecure/Private</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Usercheck-Block-Page-is-Insecure-Private/m-p/147470#M58550</link>
      <description>&lt;P&gt;Few years later, but anyway, in case anyone is looking for solution:&lt;/P&gt;
&lt;P&gt;The short answer, if the users are external to your organization and the certificate is self-signed is a no.&lt;/P&gt;
&lt;P&gt;What you are asking is to install an unsanctioned by user untrusted CA.&lt;/P&gt;
&lt;P&gt;To make this work properly, generate CRL for publicly trusted CA, get the paid certificate and import it in Portal Access Settings for Browser-Based Authentication.&lt;/P&gt;
&lt;P&gt;Use this for references on how to create CSR:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;How to generate the Wildcard certificate (SAN) CSR for Multi-Portal sk170395&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk170395" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk170395&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Import_Portal_Cert.png" style="width: 769px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/16297iCE83A2BECBFD1DD1/image-size/large?v=v2&amp;amp;px=999" role="button" title="Import_Portal_Cert.png" alt="Import_Portal_Cert.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 29 Apr 2022 14:07:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Usercheck-Block-Page-is-Insecure-Private/m-p/147470#M58550</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2022-04-29T14:07:44Z</dc:date>
    </item>
  </channel>
</rss>

