<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SCEP with fixed password does not work (SMB cluster) in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SCEP-with-fixed-password-does-not-work-SMB-cluster/m-p/126072#M74974</link>
    <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I implemted a PoC enviroment at the customer, where I tested the issuing certificates from a 3rd party CA. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Windows server: 2012r2 as NDES server&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;CP SmartCenter: R80.40 JHF 118&lt;BR /&gt;SMB cluster R80.20 embedded Gaia&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We want to use cert based S2S VPN.&lt;BR /&gt;&lt;BR /&gt;Symptom: Requesting certificate for the SMB cluster with fix password does not work. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We got error message in NDES log: &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;ID 29: The password in the certificate request cannot be verified. It may have been used already. Obtain a new password to submit with this request. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Of course this password has never been used. We tried without password, and with one time passsword, both cases we got the certificate for the SMB cluster. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Until today I suppose that this is a windows side error.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Cisco FMC can cooperate with this CA/NDES without any problem. So this could be a CP side error&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Somebody experienced such kind of behaviour?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Akos&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 09 Aug 2021 15:28:24 GMT</pubDate>
    <dc:creator>AkosBakos</dc:creator>
    <dc:date>2021-08-09T15:28:24Z</dc:date>
    <item>
      <title>SCEP with fixed password does not work (SMB cluster)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SCEP-with-fixed-password-does-not-work-SMB-cluster/m-p/126072#M74974</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I implemted a PoC enviroment at the customer, where I tested the issuing certificates from a 3rd party CA. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Windows server: 2012r2 as NDES server&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;CP SmartCenter: R80.40 JHF 118&lt;BR /&gt;SMB cluster R80.20 embedded Gaia&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We want to use cert based S2S VPN.&lt;BR /&gt;&lt;BR /&gt;Symptom: Requesting certificate for the SMB cluster with fix password does not work. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We got error message in NDES log: &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;ID 29: The password in the certificate request cannot be verified. It may have been used already. Obtain a new password to submit with this request. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Of course this password has never been used. We tried without password, and with one time passsword, both cases we got the certificate for the SMB cluster. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Until today I suppose that this is a windows side error.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Cisco FMC can cooperate with this CA/NDES without any problem. So this could be a CP side error&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Somebody experienced such kind of behaviour?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Akos&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Aug 2021 15:28:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SCEP-with-fixed-password-does-not-work-SMB-cluster/m-p/126072#M74974</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2021-08-09T15:28:24Z</dc:date>
    </item>
    <item>
      <title>Re: SCEP with fixed password does not work (SMB cluster)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SCEP-with-fixed-password-does-not-work-SMB-cluster/m-p/126073#M74975</link>
      <description>&lt;P&gt;Can you show screenshots of the step-by-step process you’re following?&lt;BR /&gt;I don’t see exactly where any of this is occurring on the Check Point side.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Aug 2021 15:33:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SCEP-with-fixed-password-does-not-work-SMB-cluster/m-p/126073#M74975</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-08-09T15:33:05Z</dc:date>
    </item>
    <item>
      <title>Re: SCEP with fixed password does not work (SMB cluster)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SCEP-with-fixed-password-does-not-work-SMB-cluster/m-p/126198#M74976</link>
      <description>&lt;P&gt;I opened a TAC case.&lt;/P&gt;&lt;P&gt;I will update the community with the solution.&lt;/P&gt;&lt;P&gt;Akos&lt;/P&gt;</description>
      <pubDate>Tue, 10 Aug 2021 09:26:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SCEP-with-fixed-password-does-not-work-SMB-cluster/m-p/126198#M74976</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2021-08-10T09:26:37Z</dc:date>
    </item>
    <item>
      <title>Re: SCEP with fixed password does not work (SMB cluster)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SCEP-with-fixed-password-does-not-work-SMB-cluster/m-p/126570#M74977</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;We found the root cause of this issue.&lt;/P&gt;&lt;P&gt;The fix challenge password is 32 character long.&lt;/P&gt;&lt;P&gt;The OTP challenge password is 16 character long.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I copy and paste the 32 characters long password into the SmartConsole, the last two characters cut off&lt;/P&gt;&lt;P&gt;I tested with the latest SmartConsole.&lt;/P&gt;&lt;P&gt;As a workaround, we set 16 character long password, and now it works fine.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A&lt;/P&gt;</description>
      <pubDate>Wed, 11 Aug 2021 14:15:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SCEP-with-fixed-password-does-not-work-SMB-cluster/m-p/126570#M74977</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2021-08-11T14:15:03Z</dc:date>
    </item>
  </channel>
</rss>

