<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Notify when certificate expired in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Notify-when-certificate-expired/m-p/92238#M8900</link>
    <description>&lt;P&gt;There is an interesting topic on CheckMates with a lot of valuable information about this:&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/General-Topics/Third-Parties-Certificate-details/m-p/76911" target="_self"&gt;&lt;SPAN class="lia-link-navigation child-thread lia-link-disabled"&gt;Third Parties Certificate details&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 23 Jul 2020 09:26:40 GMT</pubDate>
    <dc:creator>G_W_Albrecht</dc:creator>
    <dc:date>2020-07-23T09:26:40Z</dc:date>
    <item>
      <title>Notify when certificate expired</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Notify-when-certificate-expired/m-p/92189#M8897</link>
      <description>&lt;P&gt;&lt;SPAN class="tlid-translation translation"&gt;&lt;SPAN class=""&gt;Yesterday I had an incident with my IPSEC tunnels with branches (they are established by certificate) because the virtual firewall certificate expired.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="tlid-translation translation"&gt;&lt;SPAN class=""&gt;Attached the image of the Gw, had to renew the certificate to restore the service&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="tlid-translation translation"&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;The question is:&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;The Firewall can send a notification warning that a certificate is about to expire?,&amp;nbsp;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="tlid-translation translation"&gt;&lt;SPAN class=""&gt;&lt;STRONG&gt; ¿What configuration is required for the Firewall could send the notification?&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="tlid-translation translation"&gt;&lt;SPAN class=""&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_2.png" style="width: 396px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/7350i879B8C0BCD42A18B/image-dimensions/396x309?v=v2" width="396" height="309" role="button" title="Screenshot_2.png" alt="Screenshot_2.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="tlid-translation translation"&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;thanks for your help&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jul 2020 18:46:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Notify-when-certificate-expired/m-p/92189#M8897</guid>
      <dc:creator>raquinog</dc:creator>
      <dc:date>2020-07-22T18:46:22Z</dc:date>
    </item>
    <item>
      <title>Re: Notify when certificate expired</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Notify-when-certificate-expired/m-p/92232#M8898</link>
      <description>&lt;P&gt;Acording to SK102092, gateway does not alert about certificates expiration without installing a Security policy&lt;/P&gt;&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk102092" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk102092&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jul 2020 08:39:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Notify-when-certificate-expired/m-p/92232#M8898</guid>
      <dc:creator>MarioB_1</dc:creator>
      <dc:date>2020-07-23T08:39:32Z</dc:date>
    </item>
    <item>
      <title>Re: Notify when certificate expired</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Notify-when-certificate-expired/m-p/92236#M8899</link>
      <description>&lt;P&gt;...and&amp;nbsp; &lt;A href="http://supportcontent.checkpoint.com/solutions?id=sk31539" target="_blank" rel="noopener"&gt;sk31539&lt;/A&gt;&amp;nbsp;tells us that&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The Security Management server generates a report, per Security Gateway, warning about those certificates that will expire within 60 days time from the current date. &lt;/SPAN&gt;&lt;STRONG&gt;This functionality is always enabled and the&amp;nbsp;60 days is a fixed warning period.&lt;/STRONG&gt; &lt;/P&gt;
&lt;P&gt;...&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Certificate expiration warning messages are not recorded in any log by the Security Management server.&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;Warnings are generated and presented anew with each Policy installation.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;You could check on CLI using&amp;nbsp;&lt;SPAN&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk104400&amp;amp;partition=Basic&amp;amp;product=IPSec" target="_self"&gt;sk104400&lt;/A&gt;:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;# cpca_client lscert -stat Valid -kind IKE&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Operation succeeded. rc=0.&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;1 certs found.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Subject = CN=cpmodule VPN Certificate,O=Example_Management_Server.checkpoint.com.d2hitj&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Status = Valid Kind = IKE Serial = 91912 DP = 1&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Not_Before: Wed Jan 14 14:19:02 2015 Not_After: Tue Jan 14 14:19:02 2020&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jul 2020 09:11:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Notify-when-certificate-expired/m-p/92236#M8899</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2020-07-23T09:11:41Z</dc:date>
    </item>
    <item>
      <title>Re: Notify when certificate expired</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Notify-when-certificate-expired/m-p/92238#M8900</link>
      <description>&lt;P&gt;There is an interesting topic on CheckMates with a lot of valuable information about this:&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/General-Topics/Third-Parties-Certificate-details/m-p/76911" target="_self"&gt;&lt;SPAN class="lia-link-navigation child-thread lia-link-disabled"&gt;Third Parties Certificate details&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jul 2020 09:26:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Notify-when-certificate-expired/m-p/92238#M8900</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2020-07-23T09:26:40Z</dc:date>
    </item>
    <item>
      <title>Re: Notify when certificate expired</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Notify-when-certificate-expired/m-p/112119#M15548</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/35389"&gt;@raquinog&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;A customer of us had the same problem, no indication when instaling the policy about the expired certificate.&lt;BR /&gt;The feature should be always activated but it seems that it is not working.&lt;/P&gt;&lt;P&gt;Nobody knows why, so we will open a case for it.&lt;/P&gt;&lt;P&gt;Thanks,&lt;BR /&gt;Peter&lt;/P&gt;</description>
      <pubDate>Mon, 01 Mar 2021 15:23:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Notify-when-certificate-expired/m-p/112119#M15548</guid>
      <dc:creator>Peter_Baumann</dc:creator>
      <dc:date>2021-03-01T15:23:06Z</dc:date>
    </item>
    <item>
      <title>Re: Notify when certificate expired</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Notify-when-certificate-expired/m-p/124855#M18023</link>
      <description>&lt;P&gt;Just had the same issue.&amp;nbsp; We're you able to figure out why the feature doesn't work?&lt;/P&gt;</description>
      <pubDate>Sun, 25 Jul 2021 23:58:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Notify-when-certificate-expired/m-p/124855#M18023</guid>
      <dc:creator>Anthony_Vita</dc:creator>
      <dc:date>2021-07-25T23:58:31Z</dc:date>
    </item>
    <item>
      <title>Re: Notify when certificate expired</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Notify-when-certificate-expired/m-p/124879#M18032</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/14004"&gt;@Anthony_Vita&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;We opened a case and there was a lot of troubleshooting involved. Unfortunately it leads not to a solution and was closed by check point/customer.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Jul 2021 07:15:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Notify-when-certificate-expired/m-p/124879#M18032</guid>
      <dc:creator>Peter_Baumann</dc:creator>
      <dc:date>2021-07-26T07:15:14Z</dc:date>
    </item>
    <item>
      <title>Re: Notify when certificate expired</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Notify-when-certificate-expired/m-p/127386#M18490</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/35389"&gt;@raquinog&lt;/a&gt;&amp;nbsp;,&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/11229"&gt;@Peter_Baumann&lt;/a&gt;&amp;nbsp;,&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/14004"&gt;@Anthony_Vita&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Nowadays the firewall is sending notification&amp;nbsp;that a certificate is about to expire in two places&lt;BR /&gt;1. 'info' status as part of policy installation:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="info_in_policy_install.jpg" style="width: 735px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/13389iDDB66A9889D0B6D0/image-size/large?v=v2&amp;amp;px=999" role="button" title="info_in_policy_install.jpg" alt="info_in_policy_install.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;2. In VPN log:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vpn_logs.jpg" style="width: 609px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/13390i3CD5171A9F05BC74/image-size/large?v=v2&amp;amp;px=999" role="button" title="vpn_logs.jpg" alt="vpn_logs.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;As &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21294"&gt;@G_W_Albrecht&lt;/a&gt;&amp;nbsp; mentioned, You can also monitor VPN certificates of all Virtual systems / Security gateways from Security Management via single CLI command:&lt;/P&gt;
&lt;P&gt;cpca_client search "VPN certificate"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We are about to Improve the alert during Policy installation – to Changing from ‘info’ to ‘warning‘&lt;/P&gt;
&lt;P&gt;The improvement will be released in R81.20 and also be ported to all R8X.XX JHFs&lt;/P&gt;
&lt;P&gt;We are looking for other ways to alert about VPN certificate expiry, such as red “X” for the Gateway object when the VPN certificate is expired / Yellow Warning sign when the certificate is about to expire soon (e.g 60 days or less)&lt;/P&gt;
&lt;P&gt;Thanks,&lt;BR /&gt;Matan&lt;/P&gt;</description>
      <pubDate>Thu, 19 Aug 2021 06:38:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Notify-when-certificate-expired/m-p/127386#M18490</guid>
      <dc:creator>matangi</dc:creator>
      <dc:date>2021-08-19T06:38:03Z</dc:date>
    </item>
    <item>
      <title>Re: Notify when certificate expired</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Notify-when-certificate-expired/m-p/156909#M27171</link>
      <description>&lt;P&gt;&lt;FONT color="#666699"&gt;I made this simple script for crontab. It may be usefull for you&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;&lt;EM&gt;&lt;FONT color="#666699"&gt;#!/bin/sh&lt;/FONT&gt;&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;&lt;FONT color="#666699"&gt;source /etc/profile.d/CP.sh&lt;/FONT&gt;&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;&lt;EM&gt;&lt;FONT color="#666699"&gt;CERTIFICATE=`cpca_client lscert -stat Valid -dn &amp;lt;SubString&amp;gt;`&lt;/FONT&gt;&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;&lt;EM&gt;&lt;FONT color="#666699"&gt;#get string with expiration date from certificate info&lt;/FONT&gt;&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;&lt;FONT color="#666699"&gt;CERT_INFO=`cpca_client lscert -stat Valid -dn &amp;lt;SubString&amp;gt; | grep Not_After`&lt;/FONT&gt;&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;&lt;EM&gt;&lt;FONT color="#666699"&gt;#make list with expiration date, month and year&lt;/FONT&gt;&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;&lt;FONT color="#666699"&gt;EXPIRED=$(python -c "lst='$CERT_INFO'.split('Not_After:'); print(lst[1].split())")&lt;/FONT&gt;&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;&lt;EM&gt;&lt;FONT color="#666699"&gt;#get expiration day&lt;/FONT&gt;&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;&lt;FONT color="#666699"&gt;EXPIRED_DATE=$( python -c "print($EXPIRED[2])" )&lt;/FONT&gt;&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;&lt;FONT color="#666699"&gt;#get expiration month&lt;/FONT&gt;&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;&lt;FONT color="#666699"&gt;EXPIRED_MONTH=$( python -c "print($EXPIRED[1])" )&lt;/FONT&gt;&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;&lt;FONT color="#666699"&gt;#get expiration year&lt;/FONT&gt;&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;&lt;FONT color="#666699"&gt;EXPIRED_YEAR=$( python -c "print($EXPIRED[-1])" )&lt;/FONT&gt;&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;&lt;EM&gt;&lt;FONT color="#666699"&gt;DIFF=$(python -c "from datetime import (date, datetime); print date(2023, datetime.strptime('$EXPIRED_MONTH','%b').month, 11).toordinal() - date.today().toordinal()")&lt;/FONT&gt;&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;&lt;EM&gt;&lt;FONT color="#666699"&gt;if [ $DIFF -lt 30 ];&lt;/FONT&gt;&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;&lt;FONT color="#666699"&gt;then&lt;/FONT&gt;&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;&lt;FONT color="#666699"&gt;echo -e "Subject: CheckPoint VPN certificate expiration\r\n\r\nVPN certificate will be expired in $DIFF days.\r\n\n\n $CERTIFICATE.\r\n " | sendmail --domain=&amp;lt;domain name&amp;gt; -f &amp;lt;from_email&amp;gt; -v &amp;lt;to_email&amp;gt; --host=&amp;lt;smtp_server&amp;gt;&lt;/FONT&gt;&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;&lt;FONT color="#666699"&gt;fi&lt;/FONT&gt;&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Sep 2022 11:02:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Notify-when-certificate-expired/m-p/156909#M27171</guid>
      <dc:creator>Igor_Demchenko</dc:creator>
      <dc:date>2022-09-09T11:02:38Z</dc:date>
    </item>
    <item>
      <title>Re: Notify when certificate expired</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Notify-when-certificate-expired/m-p/205824#M38844</link>
      <description>&lt;P&gt;Sorry to resurrect such an old post but we are running R81.10 mgmt/gateway, which I see in the screenshots, and I'm not seeing any of these expiring cert messages in my logs on the key installs. We should have some recently because we had a VPN cert expire this weekend which went un-noticed. I'd like to incorporate these logs into an alerting mechanism in our SIEM.&lt;/P&gt;&lt;P&gt;Do you know when this became available or did this get pushed to R81.20?&lt;/P&gt;</description>
      <pubDate>Tue, 13 Feb 2024 00:01:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Notify-when-certificate-expired/m-p/205824#M38844</guid>
      <dc:creator>Heath</dc:creator>
      <dc:date>2024-02-13T00:01:34Z</dc:date>
    </item>
    <item>
      <title>Re: Notify when certificate expired</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Notify-when-certificate-expired/m-p/205844#M38857</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7758"&gt;@Heath&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;Sorry for the inconvenient.&amp;nbsp;&lt;BR /&gt;By checking the code, it seems that the log exist at least since R80.30.&lt;BR /&gt;In case you can't find it, you may open a ticket to Check Point support.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Feb 2024 07:43:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Notify-when-certificate-expired/m-p/205844#M38857</guid>
      <dc:creator>matangi</dc:creator>
      <dc:date>2024-02-13T07:43:02Z</dc:date>
    </item>
  </channel>
</rss>

