<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Harmony Endpoint on-prem and strong authentication with computers not joined to a domain? in Endpoint</title>
    <link>https://community.checkpoint.com/t5/Endpoint/Harmony-Endpoint-on-prem-and-strong-authentication-with/m-p/238169#M9934</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;we are deploying Harmony on-prem in an environment with mostly windows servers and clients joined to a windows AD-domain. We have enabled Strong Authentication as recommended and it works fine.&amp;nbsp;&lt;/P&gt;&lt;P&gt;But we also have some windows and linux servers not joined to the domain that we want to protect. Is this supported somehow?&amp;nbsp;&lt;/P&gt;&lt;P&gt;On a linux server in the cpla.log I get following error:&lt;/P&gt;&lt;P&gt;libsba - ERROR - [cpda] realm is empty&lt;/P&gt;&lt;P&gt;libsba - ERROR - [cpda] Failed to get auth header. GetAuthheader error&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On a windows server in the cpda.log I get:&lt;/P&gt;&lt;P&gt;[error] Kerberos authentication failed - Unknown error. [CclientAuth::getAuthHeader]&lt;/P&gt;&lt;P&gt;[error] Failed to get auth header. GetAuthheader error: 70001 [CHTTPCall_curl::sendReq_internal]&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Endpoint Management: R81.20&lt;/P&gt;&lt;P&gt;Windows Endpoint version: E88.32&lt;/P&gt;&lt;P&gt;Linux Endpoint version: 1.20.7&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best Regards // Jonas&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 10 Jan 2025 14:08:07 GMT</pubDate>
    <dc:creator>Jonas_O</dc:creator>
    <dc:date>2025-01-10T14:08:07Z</dc:date>
    <item>
      <title>Harmony Endpoint on-prem and strong authentication with computers not joined to a domain?</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Harmony-Endpoint-on-prem-and-strong-authentication-with/m-p/238169#M9934</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;we are deploying Harmony on-prem in an environment with mostly windows servers and clients joined to a windows AD-domain. We have enabled Strong Authentication as recommended and it works fine.&amp;nbsp;&lt;/P&gt;&lt;P&gt;But we also have some windows and linux servers not joined to the domain that we want to protect. Is this supported somehow?&amp;nbsp;&lt;/P&gt;&lt;P&gt;On a linux server in the cpla.log I get following error:&lt;/P&gt;&lt;P&gt;libsba - ERROR - [cpda] realm is empty&lt;/P&gt;&lt;P&gt;libsba - ERROR - [cpda] Failed to get auth header. GetAuthheader error&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On a windows server in the cpda.log I get:&lt;/P&gt;&lt;P&gt;[error] Kerberos authentication failed - Unknown error. [CclientAuth::getAuthHeader]&lt;/P&gt;&lt;P&gt;[error] Failed to get auth header. GetAuthheader error: 70001 [CHTTPCall_curl::sendReq_internal]&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Endpoint Management: R81.20&lt;/P&gt;&lt;P&gt;Windows Endpoint version: E88.32&lt;/P&gt;&lt;P&gt;Linux Endpoint version: 1.20.7&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best Regards // Jonas&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jan 2025 14:08:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Harmony-Endpoint-on-prem-and-strong-authentication-with/m-p/238169#M9934</guid>
      <dc:creator>Jonas_O</dc:creator>
      <dc:date>2025-01-10T14:08:07Z</dc:date>
    </item>
    <item>
      <title>Harmony Endpoint on-prem and strong authentication with computers not joined to a domain?</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Harmony-Endpoint-on-prem-and-strong-authentication-with/m-p/238200#M9941</link>
      <description>&lt;P&gt;&lt;STRONG&gt;This answer is provided by &lt;A href="https://www.checkpoint.com/ai/copilot/" target="_blank"&gt;Infinity AI Copilot&lt;/A&gt; and should be confirmed by reviewing official documentation in &lt;A href="https://support.checkpoint.com" target="blank"&gt;Support Center&lt;/A&gt;.&lt;/STRONG&gt;&lt;/P&gt; &lt;P&gt;Deploying Harmony Endpoint with Strong Authentication for servers not joined to a domain is not supported. Strong Authentication relies on Active Directory and Kerberos, which require the machines to be part of the domain. &lt;/P&gt; &lt;P&gt;For your non-domain Windows and Linux servers, you will need to disable Strong Authentication. Here are the steps you can take:&lt;/P&gt; &lt;OL&gt; &lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;Disable Strong Authentication&lt;/STRONG&gt;: &lt;/P&gt; &lt;UL&gt; &lt;LI&gt;In the Web Console or SmartEndpoint, clear the "work in authenticated mode" checkbox for the non-domain machines.&lt;/LI&gt; &lt;/UL&gt; &lt;/LI&gt; &lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;Review Logs&lt;/STRONG&gt;: &lt;/P&gt; &lt;UL&gt; &lt;LI&gt;For Linux, ensure the keytab file is correctly set up in &lt;CODE&gt;/var/lib/checkpoint/cpmgmt/auth.keytab&lt;/CODE&gt;.&lt;/LI&gt; &lt;LI&gt;For Windows, verify the service name and ensure there are no typing errors in the Check Point Endpoint Security Management Server.&lt;/LI&gt; &lt;/UL&gt; &lt;/LI&gt; &lt;/OL&gt; &lt;P&gt;If you need further assistance, consider reaching out to &lt;A href="https://www.checkpoint.com/about-us/contact-us/" target="_blank"&gt;Check Point Support&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jan 2025 17:15:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Harmony-Endpoint-on-prem-and-strong-authentication-with/m-p/238200#M9941</guid>
      <dc:creator>CheckMatesAI</dc:creator>
      <dc:date>2025-01-10T17:15:51Z</dc:date>
    </item>
    <item>
      <title>Re: Harmony Endpoint on-prem and strong authentication with computers not joined to a domain?</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Harmony-Endpoint-on-prem-and-strong-authentication-with/m-p/238206#M9942</link>
      <description>&lt;P&gt;Are you trying to auth by machine or user? Local admin or infinity portal?&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jan 2025 18:16:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Harmony-Endpoint-on-prem-and-strong-authentication-with/m-p/238206#M9942</guid>
      <dc:creator>Chillyjim</dc:creator>
      <dc:date>2025-01-10T18:16:02Z</dc:date>
    </item>
  </channel>
</rss>

