<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HTTPS certificate creation in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-certificate-creation/m-p/237982#M63425</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/23369"&gt;@Steve_Pearson&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you want to create manually a new cert for eg to your GW maybe you can follow this sk&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk30501" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk30501&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;After you create the user to access the ICA managament you will see this screen:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2025-01-08 14_27_48-.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/29132i0BBE414B4FD26519/image-size/medium?v=v2&amp;amp;px=400" role="button" title="2025-01-08 14_27_48-.png" alt="2025-01-08 14_27_48-.png" /&gt;&lt;/span&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Then you will be able to create a new cert as you want.&lt;/P&gt;
&lt;P&gt;Akos&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 08 Jan 2025 13:43:52 GMT</pubDate>
    <dc:creator>AkosBakos</dc:creator>
    <dc:date>2025-01-08T13:43:52Z</dc:date>
    <item>
      <title>HTTPS certificate creation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-certificate-creation/m-p/237976#M63422</link>
      <description>&lt;P&gt;I'm in the process of "rebuilding" a system, and one element that I need to re-enable is HTTPS inspection. This was working previously, but has been bypassed for the last several months (by a rule in the policy)&lt;/P&gt;&lt;P&gt;The existing certificate is 5 years old with a 10 year life, and at present is NOT installed on the users machines due to them being rebuilt (and group policy being reset too!), its also created on the management server using the company's name as the issuing authority (&lt;A href="http://www.mycompany,co,uk" target="_blank"&gt;www.mycompany,co,uk&lt;/A&gt;), but this is a local certificate and nothing to do with the actual real domain by that name. So the cert shows issued by and issued to, both as &lt;A href="http://www.mycompany.co.uk," target="_blank"&gt;www.mycompany.co.uk,&lt;/A&gt;&amp;nbsp;which is a little confusing for people.&lt;/P&gt;&lt;P&gt;So my thought is to generate a new certificate on the management server, using a more generic or obvious name with a full 10 years on it, then deploy this with via a GPO, however I can't see a way to do this.&lt;/P&gt;&lt;P&gt;I'm assuming that there is a way to do this but so far I've not found anything helpful (everything seems to discuss creating it when you turn on HTTPS inspection, but as it's already on this isn't an option), so I was wondering if anyone could advise me?&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jan 2025 12:55:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-certificate-creation/m-p/237976#M63422</guid>
      <dc:creator>Steve_Pearson</dc:creator>
      <dc:date>2025-01-08T12:55:44Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS certificate creation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-certificate-creation/m-p/237978#M63423</link>
      <description>&lt;P&gt;Hey Steve,&lt;/P&gt;
&lt;P&gt;I had that happen with customer once and TAC provided below sk to follow.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk92870" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk92870&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jan 2025 13:04:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-certificate-creation/m-p/237978#M63423</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-01-08T13:04:18Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS certificate creation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-certificate-creation/m-p/237980#M63424</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;If you want to renew the ICA, maybe this sk helps&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk158096" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk158096&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Or do you want to make an intermediate (issuer) Ca?&lt;/P&gt;
&lt;P&gt;Akos&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jan 2025 13:08:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-certificate-creation/m-p/237980#M63424</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2025-01-08T13:08:23Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS certificate creation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-certificate-creation/m-p/237982#M63425</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/23369"&gt;@Steve_Pearson&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you want to create manually a new cert for eg to your GW maybe you can follow this sk&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk30501" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk30501&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;After you create the user to access the ICA managament you will see this screen:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2025-01-08 14_27_48-.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/29132i0BBE414B4FD26519/image-size/medium?v=v2&amp;amp;px=400" role="button" title="2025-01-08 14_27_48-.png" alt="2025-01-08 14_27_48-.png" /&gt;&lt;/span&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Then you will be able to create a new cert as you want.&lt;/P&gt;
&lt;P&gt;Akos&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jan 2025 13:43:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-certificate-creation/m-p/237982#M63425</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2025-01-08T13:43:52Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS certificate creation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-certificate-creation/m-p/237989#M63426</link>
      <description>&lt;P&gt;Totally forgot about that, I see I had it set up in my lab as well, great tool!&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jan 2025 14:22:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-certificate-creation/m-p/237989#M63426</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-01-08T14:22:40Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS certificate creation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-certificate-creation/m-p/237994#M63427</link>
      <description>&lt;P&gt;Can be done via Smart Dashboard -&amp;gt;&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk108641" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk108641&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Or with cpopen ssl on CLI (Check points version of openSSL)&lt;/P&gt;
&lt;P&gt;Or any other system with openSSL.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Would do it via SmartDashboard, everything you need to do you can do over there.&lt;/P&gt;
&lt;P&gt;My customer did it also that way couple days ago and added to the client and works great.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If something is wrong about the certificate clients will get warning in browser.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jan 2025 14:46:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-certificate-creation/m-p/237994#M63427</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2025-01-08T14:46:13Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS certificate creation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-certificate-creation/m-p/238068#M63428</link>
      <description>&lt;P&gt;Hi Andy,&amp;nbsp;&lt;/P&gt;&lt;P&gt;This doesn't mention R81.20, but it does mention R81.10 so I figured that as long as I do a snapshot first it's definitely worth a try!&lt;/P&gt;&lt;P&gt;Worked like a dream, resetting the HTTPS as if it's never been enabled before, and allowed me to create a new certificate which was exactly what was required!&lt;/P&gt;&lt;P&gt;Perfect, thanks!&lt;/P&gt;&lt;P&gt;Steve&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jan 2025 09:29:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-certificate-creation/m-p/238068#M63428</guid>
      <dc:creator>Steve_Pearson</dc:creator>
      <dc:date>2025-01-09T09:29:07Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS certificate creation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-certificate-creation/m-p/238076#M63429</link>
      <description>&lt;P&gt;Great job! Glad we can help.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jan 2025 12:06:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-certificate-creation/m-p/238076#M63429</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-01-09T12:06:52Z</dc:date>
    </item>
  </channel>
</rss>

