<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: R80.40 unlock database in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-40-unlock-database/m-p/91816#M7036</link>
    <description>&lt;P&gt;Sounds like a bug and it's worth a TAC case.&lt;BR /&gt;One other thing I noticed: if you give both users the same UID (e.g. 0), then it "appears" to work correctly.&lt;BR /&gt;If they have different UIDs, then the behavior is as you describe.&lt;BR /&gt;Meanwhile "lock database override" should work as expected.&amp;nbsp;&lt;BR /&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7963"&gt;@Tal_Martsiano&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 17 Jul 2020 20:37:36 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2020-07-17T20:37:36Z</dc:date>
    <item>
      <title>R80.40 unlock database</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-40-unlock-database/m-p/91647#M7035</link>
      <description>&lt;P&gt;hello all&lt;/P&gt;&lt;P&gt;i have a small virtual R80.40 lab and i was trying to understand the Lock/Unlock feature&lt;/P&gt;&lt;P&gt;When i use the command lock database override i am able to transfer the lock from one admin to another admin between 2 ssh sessions.&lt;/P&gt;&lt;P&gt;According to &lt;A href="https://sc1.checkpoint.com/documents/R80.40/WebAdminGuides/EN/CP_R80.40_Gaia_AdminGuide/Content/Topics-GAG/Configuration-Locks.htm" target="_self"&gt;https://sc1.checkpoint.com/documents/R80.40/WebAdminGuides/EN/CP_R80.40_Gaia_AdminGuide/Content/Topics-GAG/Configuration-Locks.htm&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;same thing should be achieved with unlock database but it is not working for me. instead i see the message&lt;/P&gt;&lt;P&gt;"CLICMD0201 Config-lock is not owned by this clish session" when i run this command from the admin without the Lock. if i run it on the admin with Lock it is executed but still the Lock remains to the this same admin&lt;/P&gt;&lt;P&gt;What am i missing?&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jul 2020 17:50:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-40-unlock-database/m-p/91647#M7035</guid>
      <dc:creator>Christos_B</dc:creator>
      <dc:date>2020-07-15T17:50:33Z</dc:date>
    </item>
    <item>
      <title>Re: R80.40 unlock database</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-40-unlock-database/m-p/91816#M7036</link>
      <description>&lt;P&gt;Sounds like a bug and it's worth a TAC case.&lt;BR /&gt;One other thing I noticed: if you give both users the same UID (e.g. 0), then it "appears" to work correctly.&lt;BR /&gt;If they have different UIDs, then the behavior is as you describe.&lt;BR /&gt;Meanwhile "lock database override" should work as expected.&amp;nbsp;&lt;BR /&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7963"&gt;@Tal_Martsiano&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jul 2020 20:37:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-40-unlock-database/m-p/91816#M7036</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-07-17T20:37:36Z</dc:date>
    </item>
    <item>
      <title>Re: R80.40 unlock database</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-40-unlock-database/m-p/91841#M7037</link>
      <description>&lt;P&gt;first of all thank you very much for the help&lt;/P&gt;&lt;P&gt;now since you mentioned the uid i tried to revalidate these findings as first time i did not bother to change anything else than just the creation of a second admin.&lt;/P&gt;&lt;P&gt;so with different uids as i said to me it looks that only the lock database override works.&lt;/P&gt;&lt;P&gt;now i deleted the second admin and recreated it with uid=0 (in the show configuration output is with this line "add user chris uid 0 homedir /home/chris") and it looks to me that none of those two commands work now running from this second admin&lt;/P&gt;&lt;P&gt;fw1&amp;gt; show config-lock&lt;BR /&gt;Configuration locked by admin from 192.168.1.120, facility command line, 291 seconds to expiration&lt;BR /&gt;fw1&amp;gt; lock database override&lt;BR /&gt;fw1&amp;gt; show config-lock&lt;BR /&gt;Configuration locked by admin (300 seconds to expiration)&lt;BR /&gt;fw1&amp;gt; unlock database&lt;BR /&gt;fw1&amp;gt; show config-lock&lt;BR /&gt;Configuration locked by admin (300 seconds to expiration)&lt;/P&gt;</description>
      <pubDate>Sat, 18 Jul 2020 13:44:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-40-unlock-database/m-p/91841#M7037</guid>
      <dc:creator>Christos_B</dc:creator>
      <dc:date>2020-07-18T13:44:53Z</dc:date>
    </item>
    <item>
      <title>Re: R80.40 unlock database</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-40-unlock-database/m-p/91847#M7038</link>
      <description>&lt;P&gt;Believe it still works, I think it just displays the wrong name in this case.&lt;/P&gt;</description>
      <pubDate>Sat, 18 Jul 2020 15:30:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-40-unlock-database/m-p/91847#M7038</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-07-18T15:30:15Z</dc:date>
    </item>
    <item>
      <title>Re: R80.40 unlock database</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-40-unlock-database/m-p/91868#M7039</link>
      <description>&lt;P&gt;yeah you are right. i saw the name and i did not try to make a change on the cli. I see it works or at least as you said it appears to be working when uid = 0&lt;/P&gt;&lt;P&gt;Is this normal practice to make the uid=0 for different admin user? Is it something that we should keep in mind?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 19 Jul 2020 11:25:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-40-unlock-database/m-p/91868#M7039</guid>
      <dc:creator>Christos_B</dc:creator>
      <dc:date>2020-07-19T11:25:42Z</dc:date>
    </item>
    <item>
      <title>Re: R80.40 unlock database</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-40-unlock-database/m-p/91882#M7040</link>
      <description>&lt;P&gt;It depends.&lt;BR /&gt;There are certain functions (particularly in expert mode) that require admin users to be uid 0.&lt;BR /&gt;If you're sticking to clish, I don't believe it is strictly required.&lt;/P&gt;</description>
      <pubDate>Sun, 19 Jul 2020 17:33:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-40-unlock-database/m-p/91882#M7040</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-07-19T17:33:27Z</dc:date>
    </item>
    <item>
      <title>Re: R80.40 unlock database</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-40-unlock-database/m-p/91931#M7046</link>
      <description>&lt;P&gt;ok thank you very much for all the assistane&lt;/P&gt;&lt;P&gt;i believe the original question has been answered. I guess if you opened TAC case that CP will fix it&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;Chris&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jul 2020 13:21:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-40-unlock-database/m-p/91931#M7046</guid>
      <dc:creator>Christos_B</dc:creator>
      <dc:date>2020-07-20T13:21:55Z</dc:date>
    </item>
  </channel>
</rss>

