<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Machine Certificate in Endpoint</title>
    <link>https://community.checkpoint.com/t5/Endpoint/Machine-Certificate/m-p/210679#M8482</link>
    <description>&lt;P&gt;is that cert you used based on the trusted ca? because i believe it must be. Also, it cannot be empty fields in the certname, like *.trusted.company.crt for instance.&lt;/P&gt;&lt;P&gt;the * needs to be replaced with something, like machineid.trusted.company.crt, if i remember correct.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Br&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 08 Apr 2024 12:25:55 GMT</pubDate>
    <dc:creator>KM1895</dc:creator>
    <dc:date>2024-04-08T12:25:55Z</dc:date>
    <item>
      <title>Machine Certificate</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Machine-Certificate/m-p/208760#M8400</link>
      <description>&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Im currently assisting a customer with trying to set up machine certification on their windows mobile clients.&lt;/P&gt;&lt;P&gt;As far as i can tell, i think i have done the correct initial settings:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- added the trusted ca and subordinate ca to smartconsole&lt;/P&gt;&lt;P&gt;- made sure that they are set to use ldap account unit to retrieve crl&lt;/P&gt;&lt;P&gt;- set "send machine certificate" to mandatory, on the gateway object&lt;/P&gt;&lt;P&gt;- configured the basic remote access settings on the gateway&lt;/P&gt;&lt;P&gt;- int trac.defaults, i see that enable_machine_auth is set to true, but machine_tunnel_afer_logon is still set to false, which we intend to change&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What else am i missing, as i only get a "certificate is required" error message when trying to log on to the gateway.&lt;/P&gt;&lt;P&gt;I have only done this once before, and unfortunately, i cannot recall all the steps i did back then, so any input would be appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;mgmt server is 81.20, while gateway is 81.10.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Mar 2024 12:58:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Machine-Certificate/m-p/208760#M8400</guid>
      <dc:creator>KM1895</dc:creator>
      <dc:date>2024-03-14T12:58:17Z</dc:date>
    </item>
    <item>
      <title>Re: Machine Certificate</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Machine-Certificate/m-p/208767#M8401</link>
      <description>&lt;P&gt;This is what TAC sent us before, but I dont believe we ever followed it, as customer had more pressing issues to deal with.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_RemoteAccessVPN_AdminGuide/Topics-VPNRG/Machine-Certificate.htm?Highlight=Machine%20Auth" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_RemoteAccessVPN_AdminGuide/Topics-VPNRG/Machine-Certificate.htm?Highlight=Machine%20Auth&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Mar 2024 13:33:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Machine-Certificate/m-p/208767#M8401</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-03-14T13:33:51Z</dc:date>
    </item>
    <item>
      <title>Re: Machine Certificate</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Machine-Certificate/m-p/208770#M8402</link>
      <description>&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;thanks for the quick reply.&lt;/P&gt;&lt;P&gt;Have followed this one, and i think i have everything in place...just asked the customer to try again, but have a sneaky feeling something is still not right.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Mar 2024 13:52:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Machine-Certificate/m-p/208770#M8402</guid>
      <dc:creator>KM1895</dc:creator>
      <dc:date>2024-03-14T13:52:25Z</dc:date>
    </item>
    <item>
      <title>Re: Machine Certificate</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Machine-Certificate/m-p/208771#M8403</link>
      <description>&lt;P&gt;Can you send a screenshot of what they see?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 14 Mar 2024 13:54:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Machine-Certificate/m-p/208771#M8403</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-03-14T13:54:40Z</dc:date>
    </item>
    <item>
      <title>Re: Machine Certificate</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Machine-Certificate/m-p/210672#M8478</link>
      <description>&lt;P&gt;attaching the error they receive when trying to log on.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="error.png" style="width: 436px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/25191i21F6845597FAD4A0/image-size/large?v=v2&amp;amp;px=999" role="button" title="error.png" alt="error.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Apr 2024 11:59:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Machine-Certificate/m-p/210672#M8478</guid>
      <dc:creator>KM1895</dc:creator>
      <dc:date>2024-04-08T11:59:12Z</dc:date>
    </item>
    <item>
      <title>Re: Machine Certificate</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Machine-Certificate/m-p/210674#M8479</link>
      <description>&lt;P&gt;Thats it, thats EXACTLY what I get in the lab. I dont believe our client get that, but it never prompts them for cert auth to begin with.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 08 Apr 2024 12:17:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Machine-Certificate/m-p/210674#M8479</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-04-08T12:17:10Z</dc:date>
    </item>
    <item>
      <title>Re: Machine Certificate</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Machine-Certificate/m-p/210677#M8480</link>
      <description>&lt;P&gt;worst thing is, i have set this up once before, but wasnt much involved in the client setup.&lt;/P&gt;&lt;P&gt;So, i believe that things are correct set up on the Checkpoint side, but for some strange reason, the certificate, or at least not the correct, certificate is not presented.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have asked the customer for a verification of the certificates in the capi store, but here, im a bit on wobbly ground, as this is not something i work with on a daily basis.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Br&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Apr 2024 12:20:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Machine-Certificate/m-p/210677#M8480</guid>
      <dc:creator>KM1895</dc:creator>
      <dc:date>2024-04-08T12:20:40Z</dc:date>
    </item>
    <item>
      <title>Re: Machine Certificate</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Machine-Certificate/m-p/210678#M8481</link>
      <description>&lt;P&gt;Im sure someone will make me feel real dumb when they say what has to be done to make this work on windows side, but if I can get it work in the lab, happy to do it : - )&lt;/P&gt;
&lt;P&gt;I googled this so many times to see what Im missing, but not matter what I try, it simply does not work. I even tested with free p12 cert I found online, you set the cert as machine cert in mmc console, no joy.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 08 Apr 2024 12:23:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Machine-Certificate/m-p/210678#M8481</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-04-08T12:23:16Z</dc:date>
    </item>
    <item>
      <title>Re: Machine Certificate</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Machine-Certificate/m-p/210679#M8482</link>
      <description>&lt;P&gt;is that cert you used based on the trusted ca? because i believe it must be. Also, it cannot be empty fields in the certname, like *.trusted.company.crt for instance.&lt;/P&gt;&lt;P&gt;the * needs to be replaced with something, like machineid.trusted.company.crt, if i remember correct.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Br&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Apr 2024 12:25:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Machine-Certificate/m-p/210679#M8482</guid>
      <dc:creator>KM1895</dc:creator>
      <dc:date>2024-04-08T12:25:55Z</dc:date>
    </item>
    <item>
      <title>Re: Machine Certificate</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Machine-Certificate/m-p/210680#M8483</link>
      <description>&lt;P&gt;I did not do any of that, because its not trusted CA, plus, it asks for p12 certificate, so I generated one from mgmt ICA tool and also tried free one I found online, but its always exact same error you sent, no matter what cert store you place it in.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 08 Apr 2024 12:29:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Machine-Certificate/m-p/210680#M8483</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-04-08T12:29:57Z</dc:date>
    </item>
    <item>
      <title>Re: Machine Certificate</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Machine-Certificate/m-p/210682#M8484</link>
      <description>&lt;P&gt;i see.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;but as far as i can tell, this error is related to something on the client, rather than checkpoint. So for now, i feel focus my troubleshooting there.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Guess there is not much else to do in trac.defaults, other than setting the tunnel stuff to true.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Br&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Apr 2024 12:34:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Machine-Certificate/m-p/210682#M8484</guid>
      <dc:creator>KM1895</dc:creator>
      <dc:date>2024-04-08T12:34:37Z</dc:date>
    </item>
    <item>
      <title>Re: Machine Certificate</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Machine-Certificate/m-p/210686#M8485</link>
      <description>&lt;P&gt;I dont think so either, trac.defaults would not have much to do with cert itself, at least specially the machine one.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 08 Apr 2024 12:50:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Machine-Certificate/m-p/210686#M8485</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-04-08T12:50:17Z</dc:date>
    </item>
    <item>
      <title>Re: Machine Certificate</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Machine-Certificate/m-p/210689#M8486</link>
      <description>&lt;P&gt;Have you checked out&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk175111?" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk175111?&lt;/A&gt;&amp;nbsp;Had this issue when setting it up in my lab.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Apr 2024 13:00:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Machine-Certificate/m-p/210689#M8486</guid>
      <dc:creator>Albin</dc:creator>
      <dc:date>2024-04-08T13:00:01Z</dc:date>
    </item>
    <item>
      <title>Re: Machine Certificate</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Machine-Certificate/m-p/210691#M8487</link>
      <description>&lt;P&gt;Yup, did that on day 1, no joy.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 08 Apr 2024 13:04:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Machine-Certificate/m-p/210691#M8487</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-04-08T13:04:58Z</dc:date>
    </item>
  </channel>
</rss>

