<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Certificate-based VPN with elliptical curve certificate in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Certificate-based-VPN-with-elliptical-curve-certificate/m-p/94609#M18702</link>
    <description>&lt;P&gt;Did you consult&amp;nbsp;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk27054&amp;amp;partition=Basic&amp;amp;product=IPSec" target="_blank"&gt;sk27054: Defining Advanced Diffie-Hellman Groups for IKE in Site-to-Site VPN&lt;/A&gt;&amp;nbsp;yet?&lt;/P&gt;</description>
    <pubDate>Wed, 19 Aug 2020 12:55:14 GMT</pubDate>
    <dc:creator>G_W_Albrecht</dc:creator>
    <dc:date>2020-08-19T12:55:14Z</dc:date>
    <item>
      <title>Certificate-based VPN with elliptical curve certificate</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Certificate-based-VPN-with-elliptical-curve-certificate/m-p/94588#M18699</link>
      <description>&lt;P&gt;&lt;SPAN&gt;I have two site-to-site VPNs between a single R80.20 security gateway and a remote Palo Alto device.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;I control the Check Point gateway but the Palo Alto remote peer(s) belongs to a third party organisation.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;One VPN is for a Production environment and other is for a Test environment.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;The VPNs terminate on two different IPv4 addresses at the remote site and may be on a single device or on two separate devices. I do not know exactly how the remote end appliance is configured.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;The IPsec VPNs are currently secured using shared secrets but the peer organisation want to move to certificate-based authentication using elliptical curve 256-bit certificates (&lt;/SPAN&gt;ECDSA-256 with SHA256 on P-256 curve)&lt;/P&gt;&lt;P&gt;I need to generate a suitable CSR from my security gateway so that the remote organisation can use it to generate a certificate that can be imported into my security gateway but the CSR I generated using cpopenssl commands at the gateway cli produced an RSA 256-bit one rather than an EC 256-bit one.&lt;/P&gt;&lt;P&gt;In R80.20 is it possible to generate elliptical curve 256-bit CSRs so that the remote organisation can generate a certificate which I can then import into my security gateway?&lt;/P&gt;</description>
      <pubDate>Wed, 19 Aug 2020 09:47:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Certificate-based-VPN-with-elliptical-curve-certificate/m-p/94588#M18699</guid>
      <dc:creator>SteveW</dc:creator>
      <dc:date>2020-08-19T09:47:36Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate-based VPN with elliptical curve certificate</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Certificate-based-VPN-with-elliptical-curve-certificate/m-p/94609#M18702</link>
      <description>&lt;P&gt;Did you consult&amp;nbsp;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk27054&amp;amp;partition=Basic&amp;amp;product=IPSec" target="_blank"&gt;sk27054: Defining Advanced Diffie-Hellman Groups for IKE in Site-to-Site VPN&lt;/A&gt;&amp;nbsp;yet?&lt;/P&gt;</description>
      <pubDate>Wed, 19 Aug 2020 12:55:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Certificate-based-VPN-with-elliptical-curve-certificate/m-p/94609#M18702</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2020-08-19T12:55:14Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate-based VPN with elliptical curve certificate</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Certificate-based-VPN-with-elliptical-curve-certificate/m-p/94632#M18704</link>
      <description>&lt;P&gt;I'm using DH group 19 which is enabled by default in R80.20 so the sk article doesn't apply in this scenario.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Aug 2020 15:38:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Certificate-based-VPN-with-elliptical-curve-certificate/m-p/94632#M18704</guid>
      <dc:creator>SteveW</dc:creator>
      <dc:date>2020-08-19T15:38:52Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate-based VPN with elliptical curve certificate</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Certificate-based-VPN-with-elliptical-curve-certificate/m-p/94710#M18715</link>
      <description>&lt;P&gt;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk149253&amp;amp;partition=Basic&amp;amp;product=IPSec" target="_blank"&gt;sk149253: How to generate and install a third-party IPSec Certificate&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk44961&amp;amp;partition=Advanced&amp;amp;product=Security" target="_blank"&gt;sk44961: Generating a 2048-bit &lt;STRONG&gt;CSR&lt;/STRONG&gt; for Security Gateway&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk95064&amp;amp;partition=Advanced&amp;amp;product=Multi-Domain" target="_blank"&gt;sk95064: How to create a self-signed certificate for the Gaia WebUI&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk69660&amp;amp;partition=Advanced&amp;amp;product=Mobile" target="_blank"&gt;sk69660: How to generate Server Certificate Signing Request (&lt;STRONG&gt;CSR&lt;/STRONG&gt;) and import the new 3rd Party certificate to Mobile Access Blade&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Aug 2020 08:13:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Certificate-based-VPN-with-elliptical-curve-certificate/m-p/94710#M18715</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2020-08-20T08:13:02Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate-based VPN with elliptical curve certificate</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Certificate-based-VPN-with-elliptical-curve-certificate/m-p/95292#M18785</link>
      <description>&lt;P&gt;&lt;STRONG&gt;sk149253: How to generate and install a third-party IPSec Certificate&lt;/STRONG&gt; appears to be the correct approach but it means asking the third-party to send me their root certificate and any intermediate certificates (or the root certificate from their firewall/VPN device) so that I can install them on my Check Point security gateway then generate a CSR to send back to them for signing.&lt;/P&gt;&lt;P&gt;The third-party will probably refuse my request which I could completely understand and I wouldn't want to hand out my root certificate to a partner company either! But I'll give it a go.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Aug 2020 15:57:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Certificate-based-VPN-with-elliptical-curve-certificate/m-p/95292#M18785</guid>
      <dc:creator>SteveW</dc:creator>
      <dc:date>2020-08-26T15:57:56Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate-based VPN with elliptical curve certificate</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Certificate-based-VPN-with-elliptical-curve-certificate/m-p/96364#M18981</link>
      <description>&lt;P&gt;The Site to Site VPN Administration Guides for both R80.20 and R80.30, in the Public Key Infrastructure section, state:&lt;/P&gt;&lt;P&gt;"A Security Gateway taking part in VPN tunnel establishment &lt;STRONG&gt;must have an RSA key pair&lt;/STRONG&gt; and a certificate issued by a trusted CA."&lt;/P&gt;&lt;P&gt;I would take that to mean using an elliptical curve key pair is not a possibility. Given that EC is now preferred over RSA by many organisations it's a shortcoming in Check Point's features.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Sep 2020 14:54:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Certificate-based-VPN-with-elliptical-curve-certificate/m-p/96364#M18981</guid>
      <dc:creator>SteveW</dc:creator>
      <dc:date>2020-09-09T14:54:51Z</dc:date>
    </item>
  </channel>
</rss>

