<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Management API Login with certificates in API / CLI Discussion</title>
    <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Management-API-Login-with-certificates/m-p/27417#M1601</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Robert for confirmation. Will there be a update in mgmt_cli tool to include this functionality of login with certificates? Its important to have this functionality as it prevents putting password in scripts. is there any other solution of remotely updating network objects without having login credentials in clear text in any scripts or batch files?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 06 Feb 2018 09:59:15 GMT</pubDate>
    <dc:creator>RAJESH_TRIPATHI</dc:creator>
    <dc:date>2018-02-06T09:59:15Z</dc:date>
    <item>
      <title>Management API Login with certificates</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Management-API-Login-with-certificates/m-p/27410#M1594</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am new to Mgmt_cli and APIs. I want to login into mgmt server with cli tool and add new IP host objects into existing group to blacklist public IP which is threat source. I can do this very well with below commands&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ex:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;C:\CP&amp;gt;mgmt_cli add host name 120.20.20.20 ip-address 120.20.20.20 -u admin -p Cp@123 -m 10.x.y.z&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;C:\CP&amp;gt;mgmt_cli set group name "blacklist" members.add "120.20.20.20" -u admin -p Cp@123 -m 10.x.y.z&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But I dont want to store the info of userame and password in the script and instead want to have a user created who can login with personal certificate and i can store that certificate in a volume which cant be read by anyone else...is this possible?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Feb 2018 12:28:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/Management-API-Login-with-certificates/m-p/27410#M1594</guid>
      <dc:creator>RAJESH_TRIPATHI</dc:creator>
      <dc:date>2018-02-02T12:28:57Z</dc:date>
    </item>
    <item>
      <title>Re: Management API Login with certificates</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Management-API-Login-with-certificates/m-p/27411#M1595</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Further I tried this but getting error as below&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;C:\CP&amp;gt;mgmt_cli login -c C:\CP\resourceadmin.p12 -p secret&lt;BR /&gt;Peer certificate host: 127.0.0.1, port: 19009 cannot be authenticated&lt;BR /&gt;C:\CP&amp;gt;mgmt_cli login -c C:\CP\resourceadmin.p12 -p secret -m 10.1.1.1&lt;BR /&gt;First connection to the server 10.1.1.1 port 19009&lt;/P&gt;&lt;P&gt;To verify server identity, compare the following fingerprint with the one displayed by the server configuration tool (cpconfig).&lt;/P&gt;&lt;P&gt;SHA1 Fingerprint=D9:73:57:B9:3C:23:4D:ED:88:19:1B:56:A2:1D:4E:AE:45:24:72:6D&lt;BR /&gt;English Fingerprint=SENT HOOT TORN DUMB POT WALL GAGE ONLY SAID WAR RUSS BETH&lt;/P&gt;&lt;P&gt;Do you accept the fingerprint? (y/n) [y] ? y&lt;BR /&gt;Error: Unable to login with client certificate. mgmt_cli_login tool was not found on this system.&lt;/P&gt;&lt;P&gt;C:\CP&amp;gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Feb 2018 14:32:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/Management-API-Login-with-certificates/m-p/27411#M1595</guid>
      <dc:creator>RAJESH_TRIPATHI</dc:creator>
      <dc:date>2018-02-02T14:32:41Z</dc:date>
    </item>
    <item>
      <title>Re: Management API Login with certificates</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Management-API-Login-with-certificates/m-p/27412#M1596</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Please refer to the following link and look at the login command examples using certificates -&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/latest/APIs/index.html#mgmt_cli~v1.1"&gt;https://sc1.checkpoint.com/documents/latest/APIs/index.html#mgmt_cli~v1.1&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Robert.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Feb 2018 15:43:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/Management-API-Login-with-certificates/m-p/27412#M1596</guid>
      <dc:creator>Robert_Decker</dc:creator>
      <dc:date>2018-02-02T15:43:03Z</dc:date>
    </item>
    <item>
      <title>Re: Management API Login with certificates</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Management-API-Login-with-certificates/m-p/27413#M1597</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This hasnt helped &lt;img id="smileysad" class="emoticon emoticon-smileysad" src="https://community.checkpoint.com/i/smilies/16x16_smiley-sad.png" alt="Smiley Sad" title="Smiley Sad" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried the diff combinations but no joy... I can login with userid and passwd but not certificate only&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;C:\CP&amp;gt;mgmt_cli login -u resourcemgr -p iLoveCp123&amp;nbsp;-m 10.x.y.z&lt;BR /&gt;uid: "5064e6fc-530c-4df9-9152-3b28fedb938e"&lt;BR /&gt;sid: "vFSeU29BfSqc10-GImSKTwxXm5VypNSJO7CNNa6ECDM"&lt;BR /&gt;&lt;SPAN&gt;url: "&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://10.11.115.233:443/web_api" rel="nofollow"&gt;https://10.x.y.z:443/web_api&lt;/A&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;BR /&gt;session-timeout: 600&lt;BR /&gt;last-login-was-at:&lt;BR /&gt; posix: 1517587802133&lt;BR /&gt; iso-8601: "2018-02-02T16:10+0000"&lt;BR /&gt;api-server-version: "1.1"&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;C:\CP&amp;gt;mgmt_cli login -c C:\CP\resourcemgr.p12 -p 1234 -m 10.x.y.z&lt;BR /&gt;Error: Unable to login with client certificate. mgmt_cli_login tool was not found on this system.&lt;/P&gt;&lt;P&gt;C:\CP&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you share a working example?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Feb 2018 16:12:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/Management-API-Login-with-certificates/m-p/27413#M1597</guid>
      <dc:creator>RAJESH_TRIPATHI</dc:creator>
      <dc:date>2018-02-02T16:12:42Z</dc:date>
    </item>
    <item>
      <title>Re: Management API Login with certificates</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Management-API-Login-with-certificates/m-p/27414#M1598</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;The error is about a missing "&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;mgmt_cli_login" utility.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;This utility is required in order to login with a certificate.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;Please verify that it is in your working directory.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;Are you running on Windows machine?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;Robert.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Feb 2018 19:01:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/Management-API-Login-with-certificates/m-p/27414#M1598</guid>
      <dc:creator>Robert_Decker</dc:creator>
      <dc:date>2018-02-02T19:01:07Z</dc:date>
    </item>
    <item>
      <title>Re: Management API Login with certificates</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Management-API-Login-with-certificates/m-p/27415#M1599</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes I am running from windows machine where I have copied the mgmt_cli tool.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;where can I find mgmt_cli_login tool? Documentation is not very clear on this tool, infact there is no mention of this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I want to run this tool from remote machine as part of automation&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Rajesh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 05 Feb 2018 12:44:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/Management-API-Login-with-certificates/m-p/27415#M1599</guid>
      <dc:creator>RAJESH_TRIPATHI</dc:creator>
      <dc:date>2018-02-05T12:44:47Z</dc:date>
    </item>
    <item>
      <title>Re: Management API Login with certificates</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Management-API-Login-with-certificates/m-p/27416#M1600</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Rajesh,&lt;/P&gt;&lt;P&gt;It is not possible to run "login" API command with a certificate on Windows machine.&lt;/P&gt;&lt;P&gt;The&amp;nbsp;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;"&lt;/SPAN&gt;&lt;SPAN style="color: #333333; background-color: #ffffff; border: 0px;"&gt;mgmt_cli_login" utility is available only on R80 Management Server machine.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff; border: 0px;"&gt;We will update the documentation to note this fact.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff; border: 0px;"&gt;Robert.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Feb 2018 08:57:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/Management-API-Login-with-certificates/m-p/27416#M1600</guid>
      <dc:creator>Robert_Decker</dc:creator>
      <dc:date>2018-02-06T08:57:14Z</dc:date>
    </item>
    <item>
      <title>Re: Management API Login with certificates</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Management-API-Login-with-certificates/m-p/27417#M1601</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Robert for confirmation. Will there be a update in mgmt_cli tool to include this functionality of login with certificates? Its important to have this functionality as it prevents putting password in scripts. is there any other solution of remotely updating network objects without having login credentials in clear text in any scripts or batch files?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Feb 2018 09:59:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/Management-API-Login-with-certificates/m-p/27417#M1601</guid>
      <dc:creator>RAJESH_TRIPATHI</dc:creator>
      <dc:date>2018-02-06T09:59:15Z</dc:date>
    </item>
    <item>
      <title>Re: Management API Login with certificates</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Management-API-Login-with-certificates/m-p/27418#M1602</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can use environment variables to store the credentials:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE class="j-table jiveBorder" style="border: 1px solid #c6c6c6;" width="100%"&gt;&lt;THEAD&gt;&lt;TR style="background-color: #efefef;"&gt;&lt;TH&gt;Parameter name&lt;/TH&gt;&lt;TH&gt;Short name&lt;/TH&gt;&lt;TH&gt;Environment variable&lt;/TH&gt;&lt;/TR&gt;&lt;/THEAD&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;User name&lt;/TD&gt;&lt;TD&gt;-u&lt;/TD&gt;&lt;TD&gt;MGMT_CLI_USER&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Password&lt;/TD&gt;&lt;TD&gt;-p&lt;/TD&gt;&lt;TD&gt;MGMT_CLI_PASSWORD&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Domain&lt;/TD&gt;&lt;TD&gt;-d&lt;/TD&gt;&lt;TD&gt;MGMT_CLI_DOMAIN&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Management server address&lt;/TD&gt;&lt;TD&gt;-m&lt;/TD&gt;&lt;TD&gt;MGMT_CLI_MANAGEMENT&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;First, add the environment variables. On linux machine use -&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;export MGMT_CLI_USER=me&lt;BR /&gt;export MGMT_CLI_PASSWORD=secret&lt;BR /&gt;export MGMT_CLI_MANAGEMENT=1.1.1.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and call the command -&amp;nbsp;&lt;/P&gt;&lt;P&gt;mgmt_cli login&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Robert.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Feb 2018 10:16:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/Management-API-Login-with-certificates/m-p/27418#M1602</guid>
      <dc:creator>Robert_Decker</dc:creator>
      <dc:date>2018-02-06T10:16:33Z</dc:date>
    </item>
    <item>
      <title>Re: Management API Login with certificates</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Management-API-Login-with-certificates/m-p/27419#M1603</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Am afraid but this is not good as the password is still in clear text in env variable and can be visible to anyone, this wont meet security policies of the company &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Feb 2018 10:28:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/Management-API-Login-with-certificates/m-p/27419#M1603</guid>
      <dc:creator>RAJESH_TRIPATHI</dc:creator>
      <dc:date>2018-02-06T10:28:20Z</dc:date>
    </item>
    <item>
      <title>Re: Management API Login with certificates</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Management-API-Login-with-certificates/m-p/27420#M1604</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;if you are writing a script to automate your tasks, you can save the password obscured, and then un-obscure in script just before calling the login command.&lt;/P&gt;&lt;P&gt;Robert.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Feb 2018 10:31:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/Management-API-Login-with-certificates/m-p/27420#M1604</guid>
      <dc:creator>Robert_Decker</dc:creator>
      <dc:date>2018-02-06T10:31:47Z</dc:date>
    </item>
  </channel>
</rss>

