<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Endpoint Security certificate based VPN prompting expiry in Endpoint</title>
    <link>https://community.checkpoint.com/t5/Endpoint/Endpoint-Security-certificate-based-VPN-prompting-expiry/m-p/154976#M5975</link>
    <description>&lt;P&gt;Thanks for getting back, I will test this out. Our endpoints should only have a single certificate so this should hopefully work to disable to prompts.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 14 Aug 2022 23:37:58 GMT</pubDate>
    <dc:creator>henryck</dc:creator>
    <dc:date>2022-08-14T23:37:58Z</dc:date>
    <item>
      <title>Endpoint Security certificate based VPN prompting expiry</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Endpoint-Security-certificate-based-VPN-prompting-expiry/m-p/154391#M5948</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;Our EPS agent is configured to use certificate based VPN to centrally managed R81.10 gateways. Internal ADCS/ADDS enrollment policies are configured to auto renew certificates, however our endpoints are currently prompting users with a dialogue to contact the sysadmin due to an expiring certificate.&lt;/P&gt;&lt;P&gt;Is anyone aware of how to turn this off in the registry, or disable the prompt from policy? Attachment of the error is attached.&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Wed, 03 Aug 2022 04:36:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Endpoint-Security-certificate-based-VPN-prompting-expiry/m-p/154391#M5948</guid>
      <dc:creator>henryck</dc:creator>
      <dc:date>2022-08-03T04:36:47Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint Security certificate based VPN prompting expiry</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Endpoint-Security-certificate-based-VPN-prompting-expiry/m-p/154450#M5957</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/37277"&gt;@henryck&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;This screen tells user that his personal certificate which is used for authentication will be expired soon.&lt;/P&gt;
&lt;P&gt;Could you please elaborate what "ADCS / ADDS" is?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Aug 2022 13:34:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Endpoint-Security-certificate-based-VPN-prompting-expiry/m-p/154450#M5957</guid>
      <dc:creator>AndreiR</dc:creator>
      <dc:date>2022-08-03T13:34:14Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint Security certificate based VPN prompting expiry</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Endpoint-Security-certificate-based-VPN-prompting-expiry/m-p/154480#M5958</link>
      <description>&lt;P&gt;Hi Andrei&lt;/P&gt;&lt;P&gt;I'd like to disable it as we do not want the users to know, as it generates tickets.&lt;/P&gt;&lt;P&gt;Active directory certificate services are used for PKI, its a windows environment.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Wed, 03 Aug 2022 22:34:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Endpoint-Security-certificate-based-VPN-prompting-expiry/m-p/154480#M5958</guid>
      <dc:creator>henryck</dc:creator>
      <dc:date>2022-08-03T22:34:43Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint Security certificate based VPN prompting expiry</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Endpoint-Security-certificate-based-VPN-prompting-expiry/m-p/154526#M5961</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/37277"&gt;@henryck&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;I'll check some details and get back to you soon.&lt;/P&gt;
&lt;P&gt;And let me know please which exact Endpoint product and version you use.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Aug 2022 14:05:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Endpoint-Security-certificate-based-VPN-prompting-expiry/m-p/154526#M5961</guid>
      <dc:creator>AndreiR</dc:creator>
      <dc:date>2022-08-04T14:05:32Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint Security certificate based VPN prompting expiry</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Endpoint-Security-certificate-based-VPN-prompting-expiry/m-p/154961#M5972</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/37277"&gt;@henryck&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;In short, if your users have only one personal certificate for authentication in VPN, you may set the "&lt;SPAN&gt;certificate_auto_renewal_threshold&lt;/SPAN&gt;" parameter to 0. Refer sk75221 and &lt;SPAN&gt;sk177463. But be aware of the risk that if for some reason certificate has expired (say, user didn't connect to domain controller for long time), user will not be able to connect to VPN.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;This trick might not work (we are still checking this) if some user have several personal certificates installed simultaneously&amp;nbsp;(with same Subject but different Serial Numbers).&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Aug 2022 07:44:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Endpoint-Security-certificate-based-VPN-prompting-expiry/m-p/154961#M5972</guid>
      <dc:creator>AndreiR</dc:creator>
      <dc:date>2022-08-15T07:44:38Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint Security certificate based VPN prompting expiry</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Endpoint-Security-certificate-based-VPN-prompting-expiry/m-p/154976#M5975</link>
      <description>&lt;P&gt;Thanks for getting back, I will test this out. Our endpoints should only have a single certificate so this should hopefully work to disable to prompts.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 14 Aug 2022 23:37:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Endpoint-Security-certificate-based-VPN-prompting-expiry/m-p/154976#M5975</guid>
      <dc:creator>henryck</dc:creator>
      <dc:date>2022-08-14T23:37:58Z</dc:date>
    </item>
  </channel>
</rss>

