<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Importing certificates in Check Point gateways for authentication in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Importing-certificates-in-Check-Point-gateways-for/m-p/70365#M14245</link>
    <description>&lt;P&gt;Hi Mates&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I need a hand.&lt;/P&gt;&lt;P&gt;We are currently migrating one of our services (skype for business) from TMG to Check Point. I am using a logical server in order to balance the traffic to our internal servers (3 servers) where the 7 DNS records that serves this application.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The problem that we are facing is with mobile devices, currently with TMG when a mobile device tries to connects, TMG presents them our certificate issued by Digicert, and everything works fine.&lt;/P&gt;&lt;P&gt;Now that we are migrating to Check Point, we are facing an issue with the certificate. With Check Point, when a mobile device tries to connect, it is presented with self-signed certificate on the internal servers, and the comunication does not work.&lt;/P&gt;&lt;P&gt;We requested the certificate that is being used by TMG, and it is a .pfx file.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there any way we can achieve what is being done by TMG.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are using R80.20.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 13 Dec 2019 08:13:17 GMT</pubDate>
    <dc:creator>Di_Junior</dc:creator>
    <dc:date>2019-12-13T08:13:17Z</dc:date>
    <item>
      <title>Importing certificates in Check Point gateways for authentication</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Importing-certificates-in-Check-Point-gateways-for/m-p/70365#M14245</link>
      <description>&lt;P&gt;Hi Mates&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I need a hand.&lt;/P&gt;&lt;P&gt;We are currently migrating one of our services (skype for business) from TMG to Check Point. I am using a logical server in order to balance the traffic to our internal servers (3 servers) where the 7 DNS records that serves this application.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The problem that we are facing is with mobile devices, currently with TMG when a mobile device tries to connects, TMG presents them our certificate issued by Digicert, and everything works fine.&lt;/P&gt;&lt;P&gt;Now that we are migrating to Check Point, we are facing an issue with the certificate. With Check Point, when a mobile device tries to connect, it is presented with self-signed certificate on the internal servers, and the comunication does not work.&lt;/P&gt;&lt;P&gt;We requested the certificate that is being used by TMG, and it is a .pfx file.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there any way we can achieve what is being done by TMG.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are using R80.20.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Dec 2019 08:13:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Importing-certificates-in-Check-Point-gateways-for/m-p/70365#M14245</guid>
      <dc:creator>Di_Junior</dc:creator>
      <dc:date>2019-12-13T08:13:17Z</dc:date>
    </item>
    <item>
      <title>Re: Importing certificates in Check Point gateways for authentication</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Importing-certificates-in-Check-Point-gateways-for/m-p/70424#M14268</link>
      <description>Logical Server objects don't have any specific support for HTTPS.&lt;BR /&gt;That said, you might be able to combine this with inbound HTTPS Inspection where you can configure it to present the Digicert certificate.&lt;BR /&gt;The gateway will need to be configured to trust the CA (or self-signed cert) for the Internal servers.</description>
      <pubDate>Fri, 13 Dec 2019 16:53:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Importing-certificates-in-Check-Point-gateways-for/m-p/70424#M14268</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-12-13T16:53:33Z</dc:date>
    </item>
    <item>
      <title>Re: Importing certificates in Check Point gateways for authentication</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Importing-certificates-in-Check-Point-gateways-for/m-p/70502#M14284</link>
      <description>Hi PhoneBoy&lt;BR /&gt;&lt;BR /&gt;Thanks for the feedback.&lt;BR /&gt;&lt;BR /&gt;"That said, you might be able to combine this with inbound HTTPS Inspection where you can configure it to present the Digicert certificate."&lt;BR /&gt;&lt;BR /&gt;The Digicert certificate is in pfx format, I tried to import it in https inspections but it seems that this pfx is not supported. How can solve this issue?&lt;BR /&gt;&lt;BR /&gt;Thanks in advance&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Sun, 15 Dec 2019 06:44:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Importing-certificates-in-Check-Point-gateways-for/m-p/70502#M14284</guid>
      <dc:creator>Di_Junior</dc:creator>
      <dc:date>2019-12-15T06:44:07Z</dc:date>
    </item>
    <item>
      <title>Re: Importing certificates in Check Point gateways for authentication</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Importing-certificates-in-Check-Point-gateways-for/m-p/70523#M14287</link>
      <description>You just need to convert the certificate using OpenSSL or some other tool.&lt;BR /&gt;A couple suggestions here: &lt;A href="https://stackoverflow.com/questions/6819079/convert-pfx-format-to-p12" target="_blank"&gt;https://stackoverflow.com/questions/6819079/convert-pfx-format-to-p12&lt;/A&gt;</description>
      <pubDate>Mon, 16 Dec 2019 02:04:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Importing-certificates-in-Check-Point-gateways-for/m-p/70523#M14287</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-12-16T02:04:13Z</dc:date>
    </item>
    <item>
      <title>Re: Importing certificates in Check Point gateways for authentication</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Importing-certificates-in-Check-Point-gateways-for/m-p/70614#M14303</link>
      <description>Hi PhoneBoy&lt;BR /&gt;&lt;BR /&gt;I have successfully convertes the certificate into p12.&lt;BR /&gt;&lt;BR /&gt;How do I now present the certificates to clientes when they are trying to connect?&lt;BR /&gt;&lt;BR /&gt;How do I make the gateway to trust this certificate?&lt;BR /&gt;&lt;BR /&gt;You help is much appreciated.&lt;BR /&gt;&lt;BR /&gt;Thanks in advance</description>
      <pubDate>Mon, 16 Dec 2019 22:55:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Importing-certificates-in-Check-Point-gateways-for/m-p/70614#M14303</guid>
      <dc:creator>Di_Junior</dc:creator>
      <dc:date>2019-12-16T22:55:24Z</dc:date>
    </item>
    <item>
      <title>Re: Importing certificates in Check Point gateways for authentication</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Importing-certificates-in-Check-Point-gateways-for/m-p/70615#M14304</link>
      <description>You configure Inbound HTTPS Inspection as described in the documentation: &lt;A href="https://sc1.checkpoint.com/documents/R80.30/WebAdminGuides/EN/CP_R80.30_NextGenSecurityGateway_Guide/html_frameset.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R80.30/WebAdminGuides/EN/CP_R80.30_NextGenSecurityGateway_Guide/html_frameset.htm&lt;/A&gt;&lt;BR /&gt;The certificate you have to configure the gateway to "trust" in this case is the internal CA (or self-signed) certificate(s) the gateway will see when it opens the HTTPS connection to the internal hosts.&lt;BR /&gt;This process should also be described in the documentation referenced above.&lt;BR /&gt;&lt;BR /&gt;Like I originally said, this might work.&lt;BR /&gt;I don't know for sure it will.</description>
      <pubDate>Mon, 16 Dec 2019 23:47:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Importing-certificates-in-Check-Point-gateways-for/m-p/70615#M14304</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-12-16T23:47:40Z</dc:date>
    </item>
    <item>
      <title>Re: Importing certificates in Check Point gateways for authentication</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Importing-certificates-in-Check-Point-gateways-for/m-p/71842#M14561</link>
      <description>Hi &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&lt;BR /&gt;&lt;BR /&gt;Thanks for your help.&lt;BR /&gt;I tried that, and it did not work. I am still getting the self-signed certificate instead of the Digicert certificate.&lt;BR /&gt;I have opened a TAC case and still waiting on their feedback.&lt;BR /&gt;&lt;BR /&gt;Meanwhile, Has anyone ever implemented skype for business over a Check Point firewall and got it working? how was it implemented? because this is the only service preventing us from migrating all our services to Check Point.&lt;BR /&gt;&lt;BR /&gt;Thanks in advance</description>
      <pubDate>Wed, 08 Jan 2020 10:41:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Importing-certificates-in-Check-Point-gateways-for/m-p/71842#M14561</guid>
      <dc:creator>Di_Junior</dc:creator>
      <dc:date>2020-01-08T10:41:29Z</dc:date>
    </item>
    <item>
      <title>Re: Importing certificates in Check Point gateways for authentication</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Importing-certificates-in-Check-Point-gateways-for/m-p/71891#M14572</link>
      <description>You should start a separate thread about Skype for Business derailing the configuration and specific issues you’re running into.&lt;BR /&gt;I do know you probably need to bypass HTTPS Inspection for those servers.</description>
      <pubDate>Wed, 08 Jan 2020 23:26:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Importing-certificates-in-Check-Point-gateways-for/m-p/71891#M14572</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-01-08T23:26:58Z</dc:date>
    </item>
    <item>
      <title>Re: Importing certificates in Check Point gateways for authentication</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Importing-certificates-in-Check-Point-gateways-for/m-p/71934#M14582</link>
      <description>Hi &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&lt;BR /&gt;&lt;BR /&gt;Thanks. I will open another thread.&lt;BR /&gt;Regards</description>
      <pubDate>Thu, 09 Jan 2020 12:56:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Importing-certificates-in-Check-Point-gateways-for/m-p/71934#M14582</guid>
      <dc:creator>Di_Junior</dc:creator>
      <dc:date>2020-01-09T12:56:16Z</dc:date>
    </item>
  </channel>
</rss>

