<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Corrupted Internal CA? in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Corrupted-Internal-CA/m-p/19440#M93242</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;After a lot of reading, it seems the only option for me is to follow&amp;nbsp;sk108966.&lt;/P&gt;&lt;P&gt;My Default VPN cert is showing as expired 4 years ago, (cpca_client lscert -kind IKE) and I am not able to renew it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can anyone give me some real life experience of what resetting the SIC will actually do? Will the firewalls stop passing traffic as soon as I hit that command on the management server? We have firewalls in a cluster can I do this as a hit less procedure?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 17 Aug 2018 05:50:20 GMT</pubDate>
    <dc:creator>Ryan_Ryan</dc:creator>
    <dc:date>2018-08-17T05:50:20Z</dc:date>
    <item>
      <title>Corrupted Internal CA?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Corrupted-Internal-CA/m-p/19433#M93235</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello, when I run this command on SmartManager "fwm printcert -ca internal_ca I get no response back, I believe its to do with the Internal CA missing or something similar.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Its causing issues when trying to enable VPN blade on all our gateways, when trying to generate a cert I get a message back "Failed to get the CA server's certificate"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas how i can confirm this is the issue and how to fix it?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Aug 2018 07:06:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Corrupted-Internal-CA/m-p/19433#M93235</guid>
      <dc:creator>Ryan_Ryan</dc:creator>
      <dc:date>2018-08-15T07:06:26Z</dc:date>
    </item>
    <item>
      <title>Re: Corrupted Internal CA?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Corrupted-Internal-CA/m-p/19434#M93236</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Check out this SK for more options:&amp;nbsp;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk62873&amp;amp;partition=General&amp;amp;product=Security" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk62873&amp;amp;partition=General&amp;amp;product=Security"&gt;How to determine an SIC Certificate&amp;amp;apos;s expiration date&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Alternatively enable the webui for ICA and check that way.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Good luck&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Peter !!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Aug 2018 07:44:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Corrupted-Internal-CA/m-p/19434#M93236</guid>
      <dc:creator>Peter_Sandkuijl</dc:creator>
      <dc:date>2018-08-15T07:44:18Z</dc:date>
    </item>
    <item>
      <title>Re: Corrupted Internal CA?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Corrupted-Internal-CA/m-p/19435#M93237</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Before anything else, please run the following on your management server:&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier, monospace;"&gt;cpwd_admin list&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;and make sure your cpd process is up and running&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Aug 2018 13:11:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Corrupted-Internal-CA/m-p/19435#M93237</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2018-08-15T13:11:00Z</dc:date>
    </item>
    <item>
      <title>Re: Corrupted Internal CA?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Corrupted-Internal-CA/m-p/19436#M93238</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Interesting, I am not seeing it:&lt;/P&gt;&lt;P&gt;CPVIEWD&lt;BR /&gt;CPD&lt;BR /&gt;FWD&lt;BR /&gt;FWM&lt;BR /&gt;STPR&lt;BR /&gt;SVR&lt;BR /&gt;CPSEAD&lt;BR /&gt;CPWMD&lt;BR /&gt;CPHTTPD&lt;BR /&gt;SMARTLOG_SERVER&lt;BR /&gt;DASERVICE&lt;BR /&gt;CPSM&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just did a cpstart and its still not showing either.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Aug 2018 00:51:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Corrupted-Internal-CA/m-p/19436#M93238</guid>
      <dc:creator>Ryan_Ryan</dc:creator>
      <dc:date>2018-08-16T00:51:53Z</dc:date>
    </item>
    <item>
      <title>Re: Corrupted Internal CA?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Corrupted-Internal-CA/m-p/19437#M93239</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry, a typo, should be cpd. Are you still experiencing the issue after cpstop | cpstart?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Aug 2018 06:44:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Corrupted-Internal-CA/m-p/19437#M93239</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2018-08-16T06:44:06Z</dc:date>
    </item>
    <item>
      <title>Re: Corrupted Internal CA?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Corrupted-Internal-CA/m-p/19438#M93240</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No change after stop start, still same error, anything to do with the internal CA seems to fail, also installed latest hotfix to see if it would help but no difference.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I run this command:&lt;/P&gt;&lt;P&gt;cpca_client lscert -kind SIC | grep -A 2 "CN=cp_mgmt,"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is a cert that expires in 2021,&amp;nbsp;the o= matches the name of the manager. So so far this all seems ok..&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Aug 2018 00:50:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Corrupted-Internal-CA/m-p/19438#M93240</guid>
      <dc:creator>Ryan_Ryan</dc:creator>
      <dc:date>2018-08-17T00:50:43Z</dc:date>
    </item>
    <item>
      <title>Re: Corrupted Internal CA?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Corrupted-Internal-CA/m-p/19439#M93241</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please open a support request with TAC, thank you&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Aug 2018 05:48:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Corrupted-Internal-CA/m-p/19439#M93241</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2018-08-17T05:48:41Z</dc:date>
    </item>
    <item>
      <title>Re: Corrupted Internal CA?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Corrupted-Internal-CA/m-p/19440#M93242</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;After a lot of reading, it seems the only option for me is to follow&amp;nbsp;sk108966.&lt;/P&gt;&lt;P&gt;My Default VPN cert is showing as expired 4 years ago, (cpca_client lscert -kind IKE) and I am not able to renew it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can anyone give me some real life experience of what resetting the SIC will actually do? Will the firewalls stop passing traffic as soon as I hit that command on the management server? We have firewalls in a cluster can I do this as a hit less procedure?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Aug 2018 05:50:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Corrupted-Internal-CA/m-p/19440#M93242</guid>
      <dc:creator>Ryan_Ryan</dc:creator>
      <dc:date>2018-08-17T05:50:20Z</dc:date>
    </item>
    <item>
      <title>Re: Corrupted Internal CA?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Corrupted-Internal-CA/m-p/19441#M93243</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Once more, please open a support request. TAC engineer will help you in fixing the issue. The issue may not be related to certificate specifically. It need proper troubleshooting and action plan for resolution.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Following the standard support procedures is the best and fastest way.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Aug 2018 05:55:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Corrupted-Internal-CA/m-p/19441#M93243</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2018-08-17T05:55:42Z</dc:date>
    </item>
    <item>
      <title>Re: Corrupted Internal CA?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Corrupted-Internal-CA/m-p/19442#M93244</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;IKE is a different certificate from SIC. Resetting SIC will not resolve IKE certificate issues. Please follow Valeri's recommendation and let support have a look. This does not look anything like a configuration error.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BR&lt;BR /&gt;&lt;BR /&gt;Peter !!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Aug 2018 07:17:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Corrupted-Internal-CA/m-p/19442#M93244</guid>
      <dc:creator>Peter_Sandkuijl</dc:creator>
      <dc:date>2018-08-17T07:17:00Z</dc:date>
    </item>
    <item>
      <title>Re: Corrupted Internal CA?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Corrupted-Internal-CA/m-p/19443#M93245</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello TAC have confirmed to reset the SIC on the manager to fix the issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am still not entirely sure what is the impact of doing this, doing it to a cluster can I avoid any outage?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 19 Aug 2018 23:05:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Corrupted-Internal-CA/m-p/19443#M93245</guid>
      <dc:creator>Ryan_Ryan</dc:creator>
      <dc:date>2018-08-19T23:05:48Z</dc:date>
    </item>
    <item>
      <title>Re: Corrupted Internal CA?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Corrupted-Internal-CA/m-p/19444#M93246</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you are doing correctly and gradually, impact should be minimal. Ask support to assist you if any doubt.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Aug 2018 06:03:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Corrupted-Internal-CA/m-p/19444#M93246</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2018-08-20T06:03:43Z</dc:date>
    </item>
  </channel>
</rss>

