<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to create a TRUSTED ROOT CA? in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-create-a-TRUSTED-ROOT-CA/m-p/32794#M94591</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Has anyone created a “Trusted Root CA” (root-ca.crt) that is not recognized by the client computer? I followed the guide&amp;nbsp; for this poc to get the cert:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/66573_pastedImage_2.png" /&gt;&lt;/P&gt;&lt;P&gt;I did change the name (sblast.lab.local) but everything is the same ....when I import it:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://mail.google.com/mail/u/0/?ui=2&amp;amp;ik=25527368ab&amp;amp;view=fimg&amp;amp;th=1641f581389e982d&amp;amp;attid=0.1&amp;amp;disp=emb&amp;amp;attbid=ANGjdJ8KyxNjXJkuv_-4bWK40I3SyeQtvzeMpf10PqUKZ9oD43zlYQGEF1TTS2Gd_b6q5CxY-psiu6n94i3WDdvFyrgnOIwRTxARGbK-X3uN-eJENS3STjHK7y3Rnd0&amp;amp;sz=w972-h1272&amp;amp;ats=1529534230316&amp;amp;rm=1641f581389e982d&amp;amp;zw&amp;amp;atsh=1" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The docs states there should not be any issues and look like this:&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-2 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/66574_pastedImage_3.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas how to resolve it or find another means to get&amp;nbsp;a working&amp;nbsp;&lt;SPAN&gt;“Trusted Root CA"?&amp;nbsp; I also saw SK 113599 but decided to use this doc.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Ed&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 20 Jun 2018 23:46:33 GMT</pubDate>
    <dc:creator>Ed_Gonzalez</dc:creator>
    <dc:date>2018-06-20T23:46:33Z</dc:date>
    <item>
      <title>How to create a TRUSTED ROOT CA?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-create-a-TRUSTED-ROOT-CA/m-p/32794#M94591</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Has anyone created a “Trusted Root CA” (root-ca.crt) that is not recognized by the client computer? I followed the guide&amp;nbsp; for this poc to get the cert:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/66573_pastedImage_2.png" /&gt;&lt;/P&gt;&lt;P&gt;I did change the name (sblast.lab.local) but everything is the same ....when I import it:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://mail.google.com/mail/u/0/?ui=2&amp;amp;ik=25527368ab&amp;amp;view=fimg&amp;amp;th=1641f581389e982d&amp;amp;attid=0.1&amp;amp;disp=emb&amp;amp;attbid=ANGjdJ8KyxNjXJkuv_-4bWK40I3SyeQtvzeMpf10PqUKZ9oD43zlYQGEF1TTS2Gd_b6q5CxY-psiu6n94i3WDdvFyrgnOIwRTxARGbK-X3uN-eJENS3STjHK7y3Rnd0&amp;amp;sz=w972-h1272&amp;amp;ats=1529534230316&amp;amp;rm=1641f581389e982d&amp;amp;zw&amp;amp;atsh=1" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The docs states there should not be any issues and look like this:&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-2 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/66574_pastedImage_3.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas how to resolve it or find another means to get&amp;nbsp;a working&amp;nbsp;&lt;SPAN&gt;“Trusted Root CA"?&amp;nbsp; I also saw SK 113599 but decided to use this doc.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Ed&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Jun 2018 23:46:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-create-a-TRUSTED-ROOT-CA/m-p/32794#M94591</guid>
      <dc:creator>Ed_Gonzalez</dc:creator>
      <dc:date>2018-06-20T23:46:33Z</dc:date>
    </item>
    <item>
      <title>Re: How to create a TRUSTED ROOT CA?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-create-a-TRUSTED-ROOT-CA/m-p/32795#M94592</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Your screenshot for when you imported it doesn't show...it points to Gmail.&lt;/P&gt;&lt;P&gt;You might want to download it and reattach to the above message.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Jun 2018 03:50:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-create-a-TRUSTED-ROOT-CA/m-p/32795#M94592</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-06-21T03:50:58Z</dc:date>
    </item>
    <item>
      <title>Re: How to create a TRUSTED ROOT CA?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-create-a-TRUSTED-ROOT-CA/m-p/32796#M94593</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you are getting browser errors maybe the problem is with the end certificate, not the root CA certificate.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your certificate might be&amp;nbsp;missing a subject alternate name or the redirect URL doesn't match the CN or any alternate name.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What does the browser tell you about the error? Hit F12 &amp;gt; Security. It will tell you the exact reason for the error. Share with us.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Jun 2018 04:08:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-create-a-TRUSTED-ROOT-CA/m-p/32796#M94593</guid>
      <dc:creator>Pedro_Espindola</dc:creator>
      <dc:date>2018-06-21T04:08:10Z</dc:date>
    </item>
    <item>
      <title>Re: How to create a TRUSTED ROOT CA?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-create-a-TRUSTED-ROOT-CA/m-p/32797#M94594</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;IMG alt="Here is the image..." class="image-1 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/66591_unnamed.png" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Jun 2018 13:20:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-create-a-TRUSTED-ROOT-CA/m-p/32797#M94594</guid>
      <dc:creator>Ed_Gonzalez</dc:creator>
      <dc:date>2018-06-21T13:20:33Z</dc:date>
    </item>
    <item>
      <title>Re: How to create a TRUSTED ROOT CA?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-create-a-TRUSTED-ROOT-CA/m-p/32798#M94595</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Pedro. Thanks for the quick reply. That's exactly what I'm thinking and last night spend some time trying to review the steps in the command. It looks like it does read off it too... Here is the actual file (sba_openssl.cnf) that is initially setup. Once I run the commands and generate the cert it ask me for C, ST, O...etc. and I was entering diff info but tried to match them last night but no luck.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-1 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/66592_file.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'll look into the area you suggested and follow up.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Jun 2018 14:03:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-create-a-TRUSTED-ROOT-CA/m-p/32798#M94595</guid>
      <dc:creator>Ed_Gonzalez</dc:creator>
      <dc:date>2018-06-21T14:03:39Z</dc:date>
    </item>
    <item>
      <title>Re: How to create a TRUSTED ROOT CA?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-create-a-TRUSTED-ROOT-CA/m-p/32799#M94596</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here is the error.&lt;IMG alt="" class="image-1 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/66597_error.png" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Jun 2018 14:15:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-create-a-TRUSTED-ROOT-CA/m-p/32799#M94596</guid>
      <dc:creator>Ed_Gonzalez</dc:creator>
      <dc:date>2018-06-21T14:15:21Z</dc:date>
    </item>
    <item>
      <title>Re: How to create a TRUSTED ROOT CA?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-create-a-TRUSTED-ROOT-CA/m-p/32800#M94597</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;IMG alt="" class="image-1 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/66599_error_1.png" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Jun 2018 14:39:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-create-a-TRUSTED-ROOT-CA/m-p/32800#M94597</guid>
      <dc:creator>Ed_Gonzalez</dc:creator>
      <dc:date>2018-06-21T14:39:43Z</dc:date>
    </item>
    <item>
      <title>Re: How to create a TRUSTED ROOT CA?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-create-a-TRUSTED-ROOT-CA/m-p/32801#M94598</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;On the browser, hit F12 and go to the "Security" tab to see more details.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, open the certificate and check the certification path.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Jun 2018 14:43:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-create-a-TRUSTED-ROOT-CA/m-p/32801#M94598</guid>
      <dc:creator>Pedro_Espindola</dc:creator>
      <dc:date>2018-06-21T14:43:11Z</dc:date>
    </item>
    <item>
      <title>Re: How to create a TRUSTED ROOT CA?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-create-a-TRUSTED-ROOT-CA/m-p/32802#M94599</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/66604_pastedImage_1.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-2 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/66608_pastedImage_2.png" /&gt;&lt;/P&gt;&lt;P&gt;Here is more info.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Jun 2018 15:03:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-create-a-TRUSTED-ROOT-CA/m-p/32802#M94599</guid>
      <dc:creator>Ed_Gonzalez</dc:creator>
      <dc:date>2018-06-21T15:03:35Z</dc:date>
    </item>
    <item>
      <title>Re: How to create a TRUSTED ROOT CA?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-create-a-TRUSTED-ROOT-CA/m-p/32803#M94600</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/66610_pastedImage_2.png" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Jun 2018 15:10:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-create-a-TRUSTED-ROOT-CA/m-p/32803#M94600</guid>
      <dc:creator>Ed_Gonzalez</dc:creator>
      <dc:date>2018-06-21T15:10:29Z</dc:date>
    </item>
    <item>
      <title>Re: How to create a TRUSTED ROOT CA?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-create-a-TRUSTED-ROOT-CA/m-p/32804#M94601</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here are the exact steps and file.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-left: 0in;"&gt;&lt;SPAN style="color: #e35685; font-size: 14.0pt;"&gt;&lt;STRONG&gt;6.1 Create a CA certificate&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 0in;"&gt;&lt;SPAN style="font-size: 16.0pt; color: #e35685;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 0in;"&gt;&lt;SPAN style="color: black;"&gt;Login to the SB appliances via SSH and follow these steps: &lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 0in;"&gt;&lt;SPAN style="color: black;"&gt;(sba_openssl.cnf might be completely omitted if you use FQDN throughout all SBA config steps) &lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 0in;"&gt;&lt;SPAN style="color: black;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 0in;"&gt;&lt;SPAN style="color: black;"&gt;Ignore all warning outputs you get when running the cpopenssl commands &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 0in;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="margin-left: 0in;"&gt;1) Create /tmp/sba_openssl.cnf (change CN, DNS and IP according to your SB appliance settings) and insert this content:&lt;/P&gt;&lt;P style="margin-left: 0in;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="margin-left: .15in;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[ req ]&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;prompt = no default_bits = 4096&lt;/P&gt;&lt;P&gt;distinguished_name = req_distinguished_name&lt;/P&gt;&lt;P&gt;x509_extensions = req_ext&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[ req_distinguished_name ]&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;C=DE&lt;/P&gt;&lt;P&gt;ST=BY&lt;/P&gt;&lt;P&gt;O=CP&lt;/P&gt;&lt;P&gt;OU=SB&lt;/P&gt;&lt;P&gt;CN=&lt;EM&gt;sblast.lab.local &lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[ req_ext ]&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;subjectAltName = @alternate_names&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="margin-left: 0in;"&gt;[alternate_names]&lt;/P&gt;&lt;P style="margin-left: 0in;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="margin-left: 0in;"&gt;DNS.1=&lt;EM&gt;sblast.lab.local &lt;/EM&gt;&lt;/P&gt;&lt;P style="margin-left: 0in;"&gt;DNS.2=&lt;EM&gt;10.200.75.50&lt;/EM&gt;&lt;/P&gt;&lt;P style="margin-left: 0in;"&gt;&lt;EM&gt;&amp;nbsp;&lt;/EM&gt;IP.1=&lt;EM&gt;10.200.75.50&lt;/EM&gt;&lt;/P&gt;&lt;P style="margin-left: 0in; border: none; padding: 0in;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="margin-left: 0in;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="margin-left: 0in;"&gt;&lt;SPAN style="color: black;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 0in;"&gt;&lt;SPAN style="color: black;"&gt;2) Create CA private key &lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 0in;"&gt;&lt;SPAN style="color: black;"&gt;# cpopenssl genrsa -aes256 –out ca-root.key 2048 &lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 0in;"&gt;&lt;SPAN style="color: black;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 0in;"&gt;&lt;SPAN style="color: black;"&gt;3) Create CA certificate &lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 0in;"&gt;&lt;SPAN style="color: black;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 0in;"&gt;&lt;SPAN style="color: black;"&gt;# cpopenssl req -x509 -new -nodes -extensions v3_ca -key ca-root.key -days 1024 -out ca-root.crt -sha512 -config /var/opt/CPshrd-R77/conf/openssl.cnf &lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 0in;"&gt;&lt;SPAN style="color: black;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 0in;"&gt;&lt;SPAN style="color: black;"&gt;Be sure to set the common name to your domain only. &lt;/SPAN&gt;&lt;SPAN style="color: black;"&gt;Common Name (e.g. server FQDN or YOUR name) []: &lt;EM&gt;lab.local&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 0in;"&gt;&lt;SPAN style="color: black;"&gt;&lt;EM&gt;&amp;nbsp;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 0in; border: none; padding: 0in;"&gt;&lt;SPAN style="color: black;"&gt;&lt;EM&gt;&amp;nbsp;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 0in;"&gt;&lt;SPAN style="color: black; font-size: 14.0pt;"&gt;&lt;EM&gt;&amp;nbsp;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 0in;"&gt;&lt;SPAN style="color: #e35685; font-size: 14.0pt;"&gt;&lt;STRONG&gt;6.2 Create SandBlast UserCheck certificate&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 0in;"&gt;&lt;SPAN style="font-size: 16.0pt; color: #e35685;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 0in;"&gt;&lt;SPAN style="font-size: 10.0pt; color: black;"&gt;1) Create Server private key &lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 0in;"&gt;&lt;SPAN style="font-size: 10.0pt; color: black;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 0in;"&gt;&lt;SPAN style="color: black;"&gt;# cpopenssl genrsa -out sblast.local.key 4096 &lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 0in;"&gt;&lt;SPAN style="color: black;"&gt;2) Create certificate signing request &lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 0in;"&gt;&lt;SPAN style="color: black;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 0in;"&gt;&lt;SPAN style="color: black;"&gt;# cpopenssl req -new -key sblast.lab.local.key -sha512 -subj &lt;/SPAN&gt;&lt;SPAN style="color: red;"&gt;&lt;STRONG&gt;"/C=DE/ST=BY/O=CheckPoint/CN&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN style="color: black;"&gt;=sblast.lab.local" -config /tmp/sba_openssl.cnf -out sblast.lab.local.csr &lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 0in;"&gt;&lt;SPAN style="color: black;"&gt;3) Create server public certificate &lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 0in;"&gt;&lt;SPAN style="color: black;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 0in;"&gt;&lt;SPAN style="color: black;"&gt;# cpopenssl x509 -req -in sblast.lab.local.csr -CA ca-root.crt -CAkey ca-root.key -CAcreateserial -extensions req_ext -extfile /tmp/sba_openssl.cnf -out sblast.lab.local.crt -days 365 -sha512 &lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 0in;"&gt;&lt;SPAN style="color: black;"&gt;4) Convert server certificate to PKCS#12 &lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 0in;"&gt;&lt;SPAN style="color: black;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 0in;"&gt;&lt;SPAN style="color: black;"&gt;# cpopenssl pkcs12 -export -in sblast.lab.local.crt -inkey &amp;nbsp;sblast.lab.local.key -out sblast.lab.local.p12&amp;nbsp;-certfile ca-root.crt&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 0in;"&gt;&lt;/P&gt;&lt;P style="margin-left: 0in;"&gt;&lt;SPAN style="color: black;"&gt;==============================&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 0in;"&gt;&lt;/P&gt;&lt;P style="margin-left: 0in;"&gt;&lt;SPAN style="color: black;"&gt;NOTE: I think the problem might the "RED" font area.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 0in;"&gt;&lt;/P&gt;&lt;P style="margin-left: 0in;"&gt;&lt;SPAN style="color: black;"&gt;The two important files are "R7730TE.lab.local.p12" and ca-root.crt. It's the ca-root.crt that I'm installing on my labtop/client.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 0in;"&gt;&lt;/P&gt;&lt;P style="margin-left: 0in;"&gt;&lt;SPAN style="color: black;"&gt;&lt;IMG __jive_id="66611" class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/66611_pastedImage_1.png" /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Jun 2018 15:15:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-create-a-TRUSTED-ROOT-CA/m-p/32804#M94601</guid>
      <dc:creator>Ed_Gonzalez</dc:creator>
      <dc:date>2018-06-21T15:15:33Z</dc:date>
    </item>
    <item>
      <title>Re: How to create a TRUSTED ROOT CA?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-create-a-TRUSTED-ROOT-CA/m-p/32805#M94602</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Going to try something new... support just told me the following:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10.0pt;"&gt;Based on the information that is on the case it seems it looks like we are not combining the CA certificate with the server cert. The next step here will be to follow sk69660 which is originally intended for Mobile Access. The steps are the same&amp;nbsp; for UserCheck the only difference will be step 3, you will just have to import the certificate under the UserCheck tab.&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10.0pt;"&gt;I'll follow up on the results after lunch.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Jun 2018 15:32:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-create-a-TRUSTED-ROOT-CA/m-p/32805#M94602</guid>
      <dc:creator>Ed_Gonzalez</dc:creator>
      <dc:date>2018-06-21T15:32:38Z</dc:date>
    </item>
    <item>
      <title>Re: How to create a TRUSTED ROOT CA?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-create-a-TRUSTED-ROOT-CA/m-p/32806#M94603</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That is correct, the certificate is missing the root CA in the chain. There should be the lab.local certificate above the sblast.lab.local in the certification path.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In step 4, add the option&amp;nbsp;&lt;STRONG&gt;-certfile ca-root.crt&lt;/STRONG&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Jun 2018 19:28:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-create-a-TRUSTED-ROOT-CA/m-p/32806#M94603</guid>
      <dc:creator>Pedro_Espindola</dc:creator>
      <dc:date>2018-06-21T19:28:55Z</dc:date>
    </item>
    <item>
      <title>Re: How to create a TRUSTED ROOT CA?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-create-a-TRUSTED-ROOT-CA/m-p/32807#M94604</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey Pedro. Thanks your suggestion....it worked!&amp;nbsp; For some reason the work laptop was probably the main issue since it was not working there. But, once I tried the lab computer it worked great! Thanks! Ed&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Jun 2018 03:35:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-create-a-TRUSTED-ROOT-CA/m-p/32807#M94604</guid>
      <dc:creator>Ed_Gonzalez</dc:creator>
      <dc:date>2018-06-22T03:35:17Z</dc:date>
    </item>
    <item>
      <title>Re: How to create a TRUSTED ROOT CA?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-create-a-TRUSTED-ROOT-CA/m-p/32808#M94605</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Great to know, Ed!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please mark this question as answered if everything is working.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Jun 2018 14:24:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-create-a-TRUSTED-ROOT-CA/m-p/32808#M94605</guid>
      <dc:creator>Pedro_Espindola</dc:creator>
      <dc:date>2018-06-22T14:24:14Z</dc:date>
    </item>
    <item>
      <title>Re: How to create a TRUSTED ROOT CA?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-create-a-TRUSTED-ROOT-CA/m-p/32809#M94606</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;FYI I marked &lt;A href="https://community.checkpoint.com/migrated-users/46261"&gt;Ed Gonzalez&lt;/A&gt;‌'s answer correct and added your suggestion to step 4.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Jun 2018 18:36:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-create-a-TRUSTED-ROOT-CA/m-p/32809#M94606</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-06-22T18:36:58Z</dc:date>
    </item>
    <item>
      <title>Re: How to create a TRUSTED ROOT CA?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-create-a-TRUSTED-ROOT-CA/m-p/32810#M94607</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Great! Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Jun 2018 21:13:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-create-a-TRUSTED-ROOT-CA/m-p/32810#M94607</guid>
      <dc:creator>Pedro_Espindola</dc:creator>
      <dc:date>2018-06-22T21:13:44Z</dc:date>
    </item>
  </channel>
</rss>

