<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: add server-certificates failed (API and mgmt_cli) in API / CLI Discussion</title>
    <link>https://community.checkpoint.com/t5/API-CLI-Discussion/add-server-certificates-failed-API-and-mgmt-cli/m-p/140567#M6591</link>
    <description>&lt;P&gt;I recall there was a problem with the API call and either the base64 cert or password was truncated. What JHF are you running? Must be at or above Take34. Best case here is to open a TAC ticket.&lt;/P&gt;</description>
    <pubDate>Fri, 04 Feb 2022 20:26:14 GMT</pubDate>
    <dc:creator>Art_Zalenekas</dc:creator>
    <dc:date>2022-02-04T20:26:14Z</dc:date>
    <item>
      <title>add server-certificates failed (API and mgmt_cli)</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/add-server-certificates-failed-API-and-mgmt-cli/m-p/140537#M6587</link>
      <description>&lt;P&gt;Hello&lt;BR /&gt;R81, API 1.7.1&lt;BR /&gt;add server-certificates&amp;nbsp; for HPPTS-Inspection failed when using API , mgmt_cli or Web Service.&lt;BR /&gt;It functions only manually using the dashboard.&lt;BR /&gt;( on console not possible because the certificate p12 in base64 is too big for the console)&lt;/P&gt;&lt;P&gt;I always receive "Failed to create HTTPS inbound certificate with error -1"&lt;/P&gt;&lt;P&gt;as basic command used ( also with other user mgmt_cli --user .... )&lt;BR /&gt;mgmt_cli -r true add server-certificate name "NameCertificate" base64-certificate "MIIQEAIB...5489characters....ggA" base64-password "password_format_base64" comments "TESTING CERTIFICATE IMPORT"&lt;/P&gt;&lt;P&gt;What I did for converting and testing the formatted base64 certificate&lt;BR /&gt;&amp;nbsp; converted to base64 using #base64 ...file.p12 &amp;gt; certificate_p12_formatbase64&lt;BR /&gt;&amp;nbsp; tested way back using "base64 -d " and "openssl pkcs12"&lt;BR /&gt;&lt;BR /&gt;What could be the issue ? do have someone else this issue ?&lt;BR /&gt;the --debug option do not give any further information&lt;/P&gt;&lt;P&gt;Thank you for your help&lt;BR /&gt;Jean-Michel&lt;/P&gt;&lt;P&gt;-----------------------------------------&lt;/P&gt;&lt;P&gt;#LOGIN&lt;BR /&gt;mgmt_cli --user "MYuser" -p *** login&lt;BR /&gt;&amp;nbsp; &amp;nbsp; uid: "9a4..MYuser..926"&lt;BR /&gt;&amp;nbsp; &amp;nbsp; sid: "W9ZG.MYuser.-RNw"&lt;BR /&gt;&amp;nbsp; &amp;nbsp; url: "&lt;A href="https://127.0.0.1:443/web_api" target="_blank" rel="noopener"&gt;https://127.0.0.1:443/web_api&lt;/A&gt;"&lt;BR /&gt;&amp;nbsp; &amp;nbsp; session-timeout: 600&lt;BR /&gt;&amp;nbsp; &amp;nbsp; last-login-was-at:&lt;BR /&gt;&amp;nbsp; &amp;nbsp; posix: 1643972043061&lt;BR /&gt;&amp;nbsp; &amp;nbsp; iso-8601: "2022-02-04T11:54+0100"&lt;BR /&gt;&amp;nbsp; &amp;nbsp; api-server-version: "1.7.1"&lt;BR /&gt;&amp;nbsp; &amp;nbsp; user-name: "MYuser"&lt;BR /&gt;&amp;nbsp; &amp;nbsp; user-uid: "f1c..MYuser..e4"&lt;/P&gt;&lt;P&gt;#ADD certificate&lt;BR /&gt;mgmt_cli --session-id W9Z..MYuser..-RNw add server-certificate name "CertificateXX base64-certificate "MIIQ....ggA" base64-password "Qi...K=" comments "TESTING CERTIFICATE IMPORT"&lt;BR /&gt;&amp;nbsp; &amp;nbsp; code: "err_server_certificate_operation_failed"&lt;BR /&gt;&amp;nbsp; &amp;nbsp; message: "Failed to create HTTPS inbound certificate with error '-1'"&lt;/P&gt;&lt;P&gt;#LOGOUT&lt;BR /&gt;mgmt_cli --session-id "W9Z..MYuser..-RNw" logout&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Feb 2022 16:12:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/add-server-certificates-failed-API-and-mgmt-cli/m-p/140537#M6587</guid>
      <dc:creator>pepj</dc:creator>
      <dc:date>2022-02-04T16:12:25Z</dc:date>
    </item>
    <item>
      <title>Re: add server-certificates failed (API and mgmt_cli)</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/add-server-certificates-failed-API-and-mgmt-cli/m-p/140555#M6589</link>
      <description>&lt;P&gt;I also had the problem and saw with tcpdump that fewer bytes were transferred than the length of the certificate. Unfortunately, this is only a guess, as you cannot see the real bytes in the https session. I would open a TAC Case.&lt;BR /&gt;&lt;BR /&gt;Does the same work on the CLI in expert mode?&lt;BR /&gt;&lt;BR /&gt;# mgmt_cli add server-certificate name "CertificateXX base64-certificate "MIIQ....ggA" base64-password "Qi...K=" comments "TESTING CERTIFICATE IMPORT" --format json&lt;/P&gt;</description>
      <pubDate>Fri, 04 Feb 2022 19:13:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/add-server-certificates-failed-API-and-mgmt-cli/m-p/140555#M6589</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2022-02-04T19:13:22Z</dc:date>
    </item>
    <item>
      <title>Re: add server-certificates failed (API and mgmt_cli)</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/add-server-certificates-failed-API-and-mgmt-cli/m-p/140567#M6591</link>
      <description>&lt;P&gt;I recall there was a problem with the API call and either the base64 cert or password was truncated. What JHF are you running? Must be at or above Take34. Best case here is to open a TAC ticket.&lt;/P&gt;</description>
      <pubDate>Fri, 04 Feb 2022 20:26:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/add-server-certificates-failed-API-and-mgmt-cli/m-p/140567#M6591</guid>
      <dc:creator>Art_Zalenekas</dc:creator>
      <dc:date>2022-02-04T20:26:14Z</dc:date>
    </item>
    <item>
      <title>Re: add server-certificates failed (API and mgmt_cli)</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/add-server-certificates-failed-API-and-mgmt-cli/m-p/140743#M6596</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;we have&amp;nbsp;HOTFIX_R81_JUMBO_HF_MAIN Take: 44&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; I tried with REST-API,&amp;nbsp; with curl, with shell mgmt_cli and show console.&amp;nbsp; &amp;nbsp;Alsways error =-1&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; ( the badest was with show console were the certificate cannot be inserted ... seems too big for the console.&amp;nbsp;&lt;/P&gt;&lt;P&gt;PS: I opened a case to my vendor&lt;/P&gt;&lt;P&gt;Thank you for your feedback&lt;/P&gt;&lt;P&gt;Jean-Michel&lt;/P&gt;</description>
      <pubDate>Mon, 07 Feb 2022 09:18:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/add-server-certificates-failed-API-and-mgmt-cli/m-p/140743#M6596</guid>
      <dc:creator>pepj</dc:creator>
      <dc:date>2022-02-07T09:18:52Z</dc:date>
    </item>
    <item>
      <title>Re: add server-certificates failed (API and mgmt_cli)</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/add-server-certificates-failed-API-and-mgmt-cli/m-p/141236#M6602</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;solved&amp;nbsp;&lt;/P&gt;&lt;P&gt;in our enviroment the session-name and session description are a must ( otherwise command aborted )&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;options "&lt;SPAN&gt;session-name" , "session-description"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;and have rights to publish certificate ( otherwise the changes stay in the session indefinitly or aborted )&lt;/P&gt;&lt;P&gt;Thank you for your help&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Feb 2022 08:41:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/add-server-certificates-failed-API-and-mgmt-cli/m-p/141236#M6602</guid>
      <dc:creator>pepj</dc:creator>
      <dc:date>2022-02-11T08:41:04Z</dc:date>
    </item>
    <item>
      <title>Re: add server-certificates failed (API and mgmt_cli)</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/add-server-certificates-failed-API-and-mgmt-cli/m-p/164958#M7344</link>
      <description>&lt;P&gt;Hi pepj, can you explain this a little further please?&lt;/P&gt;&lt;P&gt;I currently have the same problem and already specified a session name and description via "set session", still receiving the error.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Tue, 13 Dec 2022 07:58:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/add-server-certificates-failed-API-and-mgmt-cli/m-p/164958#M7344</guid>
      <dc:creator>JensBauernfeind</dc:creator>
      <dc:date>2022-12-13T07:58:17Z</dc:date>
    </item>
    <item>
      <title>Re: add server-certificates failed (API and mgmt_cli)</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/add-server-certificates-failed-API-and-mgmt-cli/m-p/165276#M7352</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I filled "&lt;/SPAN&gt;&lt;SPAN&gt;session-name" and "session-description" as defined by our security&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;and&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;created a special role only for only managing certificates and some needs:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;desactivated all out of:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;access control&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; - access control and objects settings: write&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; - application control and url filtering : checked&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;threat prevention&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;- permission setting: write&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;other:&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; - common objects write&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;- checkpoint point userdatabase default write&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;- https inspection : write&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;- client certificate : checked&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;monitor and logging&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;- https inspection log : checked&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;management&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;- management API : checked&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;endpoint&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;- allow executing pushing operation&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I hope this help&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Dec 2022 12:35:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/add-server-certificates-failed-API-and-mgmt-cli/m-p/165276#M7352</guid>
      <dc:creator>pepj</dc:creator>
      <dc:date>2022-12-15T12:35:56Z</dc:date>
    </item>
    <item>
      <title>Re: add server-certificates failed (API and mgmt_cli)</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/add-server-certificates-failed-API-and-mgmt-cli/m-p/249530#M9071</link>
      <description>&lt;P&gt;My problem was simpler.&lt;BR /&gt;The password was incorrect with the same error message "Failed to create HTTPS certificate with error '-1'"&lt;BR /&gt;&lt;BR /&gt;But I didn't notice it at first, it took me almost 2 hours to find it.&lt;BR /&gt;In the API docimentation the used password is: "bXlfcGFzc3dvcmQ="&lt;BR /&gt;$ echo bXlfcGFzc3dvcmQ= | base64 -d&lt;BR /&gt;my_password&lt;BR /&gt;$&lt;BR /&gt;$ echo "my_password" | base64&lt;BR /&gt;bXlfcGFzc3dvcmQK&lt;BR /&gt;$&lt;/P&gt;&lt;P&gt;$ echo bXlfcGFzc3dvcmQK | base64 -d&lt;BR /&gt;my_password&lt;/P&gt;&lt;P&gt;$&lt;BR /&gt;What happenning? After 2 hours I realized that there is an another &amp;lt;enter&amp;gt; after the password&lt;BR /&gt;$ echo bXlfcGFzc3dvcmQ= | base64 -d | hexdump -C&lt;BR /&gt;00000000 6d 79 5f 70 61 73 73 77 6f 72 64 |my_password|&lt;BR /&gt;0000000b&lt;BR /&gt;$&lt;BR /&gt;$ echo bXlfcGFzc3dvcmQK | base64 -d | hexdump -C&lt;BR /&gt;00000000 6d 79 5f 70 61 73 73 77 6f 72 64 0a |my_password.|&lt;BR /&gt;0000000c&lt;BR /&gt;$&lt;BR /&gt;There is a "0a" at the end.&lt;BR /&gt;So I had to remove the "0a"&lt;BR /&gt;$ echo -n "my_password" | base64&lt;BR /&gt;bXlfcGFzc3dvcmQ=&lt;BR /&gt;$&lt;BR /&gt;"bXlfcGFzc3dvcmQ="&amp;nbsp; same as in the documentation.&lt;BR /&gt;&lt;BR /&gt;This could’ve been it: 'Hey, dummy, wrong password!'&lt;span class="lia-unicode-emoji" title=":beaming_face_with_smiling_eyes:"&gt;😁&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;Br,&lt;BR /&gt;Zolo&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 29 May 2025 10:40:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/add-server-certificates-failed-API-and-mgmt-cli/m-p/249530#M9071</guid>
      <dc:creator>Zolo</dc:creator>
      <dc:date>2025-05-29T10:40:23Z</dc:date>
    </item>
  </channel>
</rss>

