<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Access Role was not working with expired self-signed certificate. Identity Collector problem. in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Access-Role-was-not-working-with-expired-self-signed-certificate/m-p/179624#M68586</link>
    <description>&lt;P&gt;R81.10 JHF Take 79.&lt;BR /&gt;Identity Collector version - R81.040.0000&lt;/P&gt;&lt;P&gt;I have things currently working after renewing the IPSec VPN self-signed certificate, but I am wondering if I have things setup "right"?&amp;nbsp;The reason I started looking into this was my Access Role was not working. Check Point Identity Collector is installed on two servers. Under the Identity Collector app &amp;gt; Gateways tab it was Disconnected on both. (screenshot taken after fix)&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="IdC" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/20709i5E7D6FED123EB07C/image-size/large?v=v2&amp;amp;px=999" role="button" title="idc.png" alt="IdC" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;IdC&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;It referenced SK113021 under the Test button -&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk113021" target="_blank"&gt;Identity Collector fails to connect / add / edit a Security Gateway (checkpoint.com)&lt;/A&gt;.&amp;nbsp;I went to our cluster IP via a browser after reading that SK and other forum posts. Forum posts led me to read this as well - &lt;A href="https://support.checkpoint.com/results/sk/sk170112" target="_blank"&gt;Identity Collector fails to connect to a Security Gateway due to MultiPortal certificate (checkpoint.com).&lt;/A&gt;&lt;BR /&gt;After learning certs could be an issue, I went to my cluster IP via a browser and found out the self-signed certificate expired last month.&lt;BR /&gt;&lt;BR /&gt;To fix that, I had to re-enable the IPSec VPN blade (I disabled the blade since we aren't using this VPN method) and renewed the certificate and installed the policy. After those steps I was able to hit Test and it Connected fine on the IdC app.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;My questions are: - Does this setup sound correct?&amp;nbsp;&lt;BR /&gt;Can the self-signed certificate go longer than 1 year to avoid having to renew manually each year?&lt;BR /&gt;&lt;BR /&gt;Seems like one drawback of using IDC vs AD Query..&lt;/P&gt;&lt;P&gt;Thanks for reading!&lt;/P&gt;</description>
    <pubDate>Mon, 01 May 2023 22:59:42 GMT</pubDate>
    <dc:creator>r1der</dc:creator>
    <dc:date>2023-05-01T22:59:42Z</dc:date>
    <item>
      <title>Access Role was not working with expired self-signed certificate. Identity Collector problem.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Access-Role-was-not-working-with-expired-self-signed-certificate/m-p/179624#M68586</link>
      <description>&lt;P&gt;R81.10 JHF Take 79.&lt;BR /&gt;Identity Collector version - R81.040.0000&lt;/P&gt;&lt;P&gt;I have things currently working after renewing the IPSec VPN self-signed certificate, but I am wondering if I have things setup "right"?&amp;nbsp;The reason I started looking into this was my Access Role was not working. Check Point Identity Collector is installed on two servers. Under the Identity Collector app &amp;gt; Gateways tab it was Disconnected on both. (screenshot taken after fix)&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="IdC" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/20709i5E7D6FED123EB07C/image-size/large?v=v2&amp;amp;px=999" role="button" title="idc.png" alt="IdC" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;IdC&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;It referenced SK113021 under the Test button -&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk113021" target="_blank"&gt;Identity Collector fails to connect / add / edit a Security Gateway (checkpoint.com)&lt;/A&gt;.&amp;nbsp;I went to our cluster IP via a browser after reading that SK and other forum posts. Forum posts led me to read this as well - &lt;A href="https://support.checkpoint.com/results/sk/sk170112" target="_blank"&gt;Identity Collector fails to connect to a Security Gateway due to MultiPortal certificate (checkpoint.com).&lt;/A&gt;&lt;BR /&gt;After learning certs could be an issue, I went to my cluster IP via a browser and found out the self-signed certificate expired last month.&lt;BR /&gt;&lt;BR /&gt;To fix that, I had to re-enable the IPSec VPN blade (I disabled the blade since we aren't using this VPN method) and renewed the certificate and installed the policy. After those steps I was able to hit Test and it Connected fine on the IdC app.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;My questions are: - Does this setup sound correct?&amp;nbsp;&lt;BR /&gt;Can the self-signed certificate go longer than 1 year to avoid having to renew manually each year?&lt;BR /&gt;&lt;BR /&gt;Seems like one drawback of using IDC vs AD Query..&lt;/P&gt;&lt;P&gt;Thanks for reading!&lt;/P&gt;</description>
      <pubDate>Mon, 01 May 2023 22:59:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Access-Role-was-not-working-with-expired-self-signed-certificate/m-p/179624#M68586</guid>
      <dc:creator>r1der</dc:creator>
      <dc:date>2023-05-01T22:59:42Z</dc:date>
    </item>
    <item>
      <title>Re: Access Role was not working with expired self-signed certificate. Identity Collector problem.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Access-Role-was-not-working-with-expired-self-signed-certificate/m-p/179625#M68587</link>
      <description>&lt;P&gt;CP changed cert validity to 1 year I believe back in 2021, used to be 5 years for longest time. I know someone in R&amp;amp;D told me they made that decision, as it is actually industry standars. Btw, you can have VPN blade off and still use IDC, I did that in lab few times.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 01 May 2023 23:09:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Access-Role-was-not-working-with-expired-self-signed-certificate/m-p/179625#M68587</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-05-01T23:09:39Z</dc:date>
    </item>
    <item>
      <title>Re: Access Role was not working with expired self-signed certificate. Identity Collector problem.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Access-Role-was-not-working-with-expired-self-signed-certificate/m-p/179626#M68588</link>
      <description>&lt;P&gt;Yeah, I have to renew web certs every year and I guess now this.&lt;/P&gt;&lt;P&gt;Thanks, I figured as much since it was off beforehand till the cert self-signed cert expired.&lt;BR /&gt;I would turn it back off but I guess I'll leave it on to have the certificate renew button visible, so it's not hidden.&lt;/P&gt;</description>
      <pubDate>Mon, 01 May 2023 23:17:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Access-Role-was-not-working-with-expired-self-signed-certificate/m-p/179626#M68588</guid>
      <dc:creator>r1der</dc:creator>
      <dc:date>2023-05-01T23:17:35Z</dc:date>
    </item>
    <item>
      <title>Re: Access Role was not working with expired self-signed certificate. Identity Collector problem.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Access-Role-was-not-working-with-expired-self-signed-certificate/m-p/179627#M68589</link>
      <description>&lt;P&gt;They improved this significantly in R81.20, as it gives warning way before its supposed to expire. I believe its at least 6 months, so gives plenty of time to take care of it.&lt;/P&gt;</description>
      <pubDate>Mon, 01 May 2023 23:50:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Access-Role-was-not-working-with-expired-self-signed-certificate/m-p/179627#M68589</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-05-01T23:50:13Z</dc:date>
    </item>
    <item>
      <title>Re: Access Role was not working with expired self-signed certificate. Identity Collector problem.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Access-Role-was-not-working-with-expired-self-signed-certificate/m-p/179629#M68590</link>
      <description>&lt;P&gt;For awareness:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk176527" target="_blank"&gt;IKE certificate validity period has changed from 5 years to 1 year by default (checkpoint.com)&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 02 May 2023 01:11:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Access-Role-was-not-working-with-expired-self-signed-certificate/m-p/179629#M68590</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-05-02T01:11:49Z</dc:date>
    </item>
    <item>
      <title>Re: Access Role was not working with expired self-signed certificate. Identity Collector problem.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Access-Role-was-not-working-with-expired-self-signed-certificate/m-p/179631#M68591</link>
      <description>&lt;P&gt;I remember seeing that sk before Chris, but will try extend validity in the lab tomorrow and see if it works.&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 02 May 2023 02:07:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Access-Role-was-not-working-with-expired-self-signed-certificate/m-p/179631#M68591</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-05-02T02:07:15Z</dc:date>
    </item>
    <item>
      <title>Re: Access Role was not working with expired self-signed certificate. Identity Collector problem.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Access-Role-was-not-working-with-expired-self-signed-certificate/m-p/179720#M68592</link>
      <description>&lt;P&gt;Just tried it, worked like a charm. Thanks&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/3630"&gt;@Chris_Atkinson&lt;/a&gt;&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":thumbs_up:"&gt;👍&lt;/span&gt;&lt;span class="lia-unicode-emoji" title=":thumbs_up:"&gt;👍&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/20732i23E3264B74234267/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Tue, 02 May 2023 15:34:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Access-Role-was-not-working-with-expired-self-signed-certificate/m-p/179720#M68592</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-05-02T15:34:23Z</dc:date>
    </item>
    <item>
      <title>Re: Access Role was not working with expired self-signed certificate. Identity Collector problem.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Access-Role-was-not-working-with-expired-self-signed-certificate/m-p/180098#M68593</link>
      <description>&lt;P&gt;Perfect, thanks! I was able to increase the expiration by 3 years.&lt;/P&gt;</description>
      <pubDate>Fri, 05 May 2023 22:02:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Access-Role-was-not-working-with-expired-self-signed-certificate/m-p/180098#M68593</guid>
      <dc:creator>r1der</dc:creator>
      <dc:date>2023-05-05T22:02:04Z</dc:date>
    </item>
    <item>
      <title>Re: Access Role was not working with expired self-signed certificate. Identity Collector problem.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Access-Role-was-not-working-with-expired-self-signed-certificate/m-p/181517#M68594</link>
      <description>&lt;P&gt;I'm still trying to understand this. Do you need the VPN certificate though? It seemed like when it expired IDC stopped working.&lt;BR /&gt;I think I'll test Removing the cert from the repository perhaps and see if IDC complains... but not today&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":beaming_face_with_smiling_eyes:"&gt;😁&lt;/span&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Edit: I think the answer is to delete the certificate, after reading this again. Since it is not in use:&lt;BR /&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk113021" target="_blank"&gt;Identity Collector fails to connect / add / edit a Security Gateway (checkpoint.com)&lt;/A&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;If you can not "view" the certificate, &lt;STRONG&gt;it needs to be deleted and re-imported or permanently deleted once you have verified its not in use.&amp;nbsp;&lt;/STRONG&gt;&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Fri, 19 May 2023 22:35:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Access-Role-was-not-working-with-expired-self-signed-certificate/m-p/181517#M68594</guid>
      <dc:creator>r1der</dc:creator>
      <dc:date>2023-05-19T22:35:30Z</dc:date>
    </item>
  </channel>
</rss>

