<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SIC certificate for OPSEC expired in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIC-certificate-for-OPSEC-expired/m-p/88894#M6839</link>
    <description>&lt;P&gt;Hello team,&lt;/P&gt;&lt;P&gt;We are managing a smart center running on GAIA R77.30 (yes the version is obsolate &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;). We have a customer OPSEC server connecting to our device and we found out that the SIC certificate expired, checked on the smart center and on the OPSEC servers log.&lt;/P&gt;&lt;P&gt;I am wondering if by resetting the SIC status on the smart center would also generate the new certificate? In this case I assume that resetting the SIC and setting a new PSK would solve the issue.&lt;/P&gt;&lt;P&gt;From what I read there is an option to generate a new certificate using the ICA Management tool. sk62873 sk39915&lt;/P&gt;&lt;P&gt;Here I am a bit lost how to generate the new certificate.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the documentation I found this related for the SIC certificate automatic renewal however I am not sure if it relates to third party devices.&lt;/P&gt;&lt;P class="tpbodytext"&gt;&lt;EM&gt;Automatic renewal of SIC certificates ensuring continuous SIC connectivity&lt;/EM&gt;&lt;/P&gt;&lt;P class="tpbodytext"&gt;SIC certificates are renewed automatically after 75% of the validity time of the certificate has passed. If, for example, the SIC certificate is valid for five years, 3.75 years after it was issued, a new certificate is created and downloaded automatically to the SIC entity. This automatic renewal ensures that the SIC connectivity of the gateway is continuous. The administrator can decide to revoke the old certificate automatically or after a set period of time. By default, the old certificate is revoked one week after the certificate renewal has taken place.&lt;/P&gt;&lt;P class="tpbodytext"&gt;&lt;A href="https://sc1.checkpoint.com/documents/R76/CP_R76_SecMan_WebAdmin/html_frameset.htm?topic=documents/R76/CP_R76_SecMan_WebAdmin/13118" target="_blank" rel="noopener"&gt;https://sc1.checkpoint.com/documents/R76/CP_R76_SecMan_WebAdmin/html_frameset.htm?topic=documents/R76/CP_R76_SecMan_WebAdmin/13118&lt;/A&gt;&lt;/P&gt;&lt;P class="tpbodytext"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="tpbodytext"&gt;Any thoughts are appreciated &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P class="tpbodytext"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="tpbodytext"&gt;Thanks a lot.&lt;/P&gt;&lt;P class="tpbodytext"&gt;Matt&lt;/P&gt;</description>
    <pubDate>Wed, 17 Jun 2020 11:04:45 GMT</pubDate>
    <dc:creator>matti</dc:creator>
    <dc:date>2020-06-17T11:04:45Z</dc:date>
    <item>
      <title>SIC certificate for OPSEC expired</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIC-certificate-for-OPSEC-expired/m-p/88894#M6839</link>
      <description>&lt;P&gt;Hello team,&lt;/P&gt;&lt;P&gt;We are managing a smart center running on GAIA R77.30 (yes the version is obsolate &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;). We have a customer OPSEC server connecting to our device and we found out that the SIC certificate expired, checked on the smart center and on the OPSEC servers log.&lt;/P&gt;&lt;P&gt;I am wondering if by resetting the SIC status on the smart center would also generate the new certificate? In this case I assume that resetting the SIC and setting a new PSK would solve the issue.&lt;/P&gt;&lt;P&gt;From what I read there is an option to generate a new certificate using the ICA Management tool. sk62873 sk39915&lt;/P&gt;&lt;P&gt;Here I am a bit lost how to generate the new certificate.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the documentation I found this related for the SIC certificate automatic renewal however I am not sure if it relates to third party devices.&lt;/P&gt;&lt;P class="tpbodytext"&gt;&lt;EM&gt;Automatic renewal of SIC certificates ensuring continuous SIC connectivity&lt;/EM&gt;&lt;/P&gt;&lt;P class="tpbodytext"&gt;SIC certificates are renewed automatically after 75% of the validity time of the certificate has passed. If, for example, the SIC certificate is valid for five years, 3.75 years after it was issued, a new certificate is created and downloaded automatically to the SIC entity. This automatic renewal ensures that the SIC connectivity of the gateway is continuous. The administrator can decide to revoke the old certificate automatically or after a set period of time. By default, the old certificate is revoked one week after the certificate renewal has taken place.&lt;/P&gt;&lt;P class="tpbodytext"&gt;&lt;A href="https://sc1.checkpoint.com/documents/R76/CP_R76_SecMan_WebAdmin/html_frameset.htm?topic=documents/R76/CP_R76_SecMan_WebAdmin/13118" target="_blank" rel="noopener"&gt;https://sc1.checkpoint.com/documents/R76/CP_R76_SecMan_WebAdmin/html_frameset.htm?topic=documents/R76/CP_R76_SecMan_WebAdmin/13118&lt;/A&gt;&lt;/P&gt;&lt;P class="tpbodytext"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="tpbodytext"&gt;Any thoughts are appreciated &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P class="tpbodytext"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="tpbodytext"&gt;Thanks a lot.&lt;/P&gt;&lt;P class="tpbodytext"&gt;Matt&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jun 2020 11:04:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIC-certificate-for-OPSEC-expired/m-p/88894#M6839</guid>
      <dc:creator>matti</dc:creator>
      <dc:date>2020-06-17T11:04:45Z</dc:date>
    </item>
    <item>
      <title>Re: SIC certificate for OPSEC expired</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIC-certificate-for-OPSEC-expired/m-p/221577#M42429</link>
      <description>&lt;P&gt;Hi Matt,&lt;/P&gt;&lt;P&gt;I was looking at R81.10 and found the same information but wanted to know how long my certs have left?&lt;/P&gt;&lt;P&gt;Did you get the answer you were looking for?&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Shabib&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jul 2024 14:17:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIC-certificate-for-OPSEC-expired/m-p/221577#M42429</guid>
      <dc:creator>shabib</dc:creator>
      <dc:date>2024-07-22T14:17:41Z</dc:date>
    </item>
  </channel>
</rss>

