<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Import CA certificate and use it for Multifactor Authentication. in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Import-CA-certificate-and-use-it-for-Multifactor-Authentication/m-p/119053#M22167</link>
    <description>&lt;P&gt;Ah ok sorry, I was confused with the usual multifactor authentication profile method, but I am seeing that this is a new feature and most of things are enabled by default. Thank you very much.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 21 May 2021 12:07:05 GMT</pubDate>
    <dc:creator>Debon27</dc:creator>
    <dc:date>2021-05-21T12:07:05Z</dc:date>
    <item>
      <title>Import CA certificate and use it for Multifactor Authentication.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Import-CA-certificate-and-use-it-for-Multifactor-Authentication/m-p/119032#M22159</link>
      <description>&lt;P&gt;Hi, I am wondering if possible to import our AD internal CA certificate in our Check Point devices, to use it for multifactor authentication for Remote Access VPN users. I have done this on Cisco ASA and FortiGates but not sure if possible in Check Point. I know that I could add a NPS server and send RADIUS requests from the Gateways to the NPS, but I do not want this scenario. I just need that the Gateways trust our internal CA, and check the users' username/password + certificate and allow connection if the users' certificates belong to the chain of trust. I do NOT want that the Gateways relegate the certificate authentication to an external machine. Thank you very much.&lt;/P&gt;</description>
      <pubDate>Fri, 21 May 2021 09:46:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Import-CA-certificate-and-use-it-for-Multifactor-Authentication/m-p/119032#M22159</guid>
      <dc:creator>Debon27</dc:creator>
      <dc:date>2021-05-21T09:46:05Z</dc:date>
    </item>
    <item>
      <title>Re: Import CA certificate and use it for Multifactor Authentication.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Import-CA-certificate-and-use-it-for-Multifactor-Authentication/m-p/119038#M22160</link>
      <description>&lt;P&gt;User certificate or device certificate? If latter, look into&amp;nbsp;&lt;SPAN&gt;sk121173.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 May 2021 10:15:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Import-CA-certificate-and-use-it-for-Multifactor-Authentication/m-p/119038#M22160</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2021-05-21T10:15:36Z</dc:date>
    </item>
    <item>
      <title>Re: Import CA certificate and use it for Multifactor Authentication.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Import-CA-certificate-and-use-it-for-Multifactor-Authentication/m-p/119049#M22163</link>
      <description>&lt;P&gt;After adding the CA certificate and checking that machine authentication feature is enabled, I supose that I also have to create a new profile for VPN Clients, setting username/password + certificate as usual, right? Just for confirmation, the requered steps are the following ones:&lt;/P&gt;&lt;P&gt;1- Check that machine authentication is enabled.&lt;/P&gt;&lt;P&gt;2- Import our Internal CA certificate in the SMS&lt;/P&gt;&lt;P&gt;3- Create a new Multifactor Profile for certificate as first factor, and user/pass as second factor (user and pass will be authenticated by LDAP server).&lt;/P&gt;&lt;P&gt;4- Install policy.&lt;/P&gt;&lt;P&gt;5- Create a new profile in the Check Point End Point Security client, selecting the new Profile.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After that, the client should sent certificate+user/pass to the Gateway, and te Gateway will perform the certificate authentication, while the LDAP server will continue in charge of user/pass authentication, right? Thank you very much for the help!&lt;/P&gt;</description>
      <pubDate>Fri, 21 May 2021 11:54:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Import-CA-certificate-and-use-it-for-Multifactor-Authentication/m-p/119049#M22163</guid>
      <dc:creator>Debon27</dc:creator>
      <dc:date>2021-05-21T11:54:00Z</dc:date>
    </item>
    <item>
      <title>Re: Import CA certificate and use it for Multifactor Authentication.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Import-CA-certificate-and-use-it-for-Multifactor-Authentication/m-p/119051#M22165</link>
      <description>&lt;P&gt;I suggest you read the mentioned SK, and follow the guidance. In addition, download&amp;nbsp;&lt;A href="http://downloads.checkpoint.com/dc/download.htm?ID=60345" target="_blank" rel="noopener"&gt;Remote Access Clients for Windows 32/64-bit E80.72 and higher Administration Guide&lt;/A&gt;&amp;nbsp;and look it though, especially starting from page 64&lt;/P&gt;</description>
      <pubDate>Fri, 21 May 2021 11:58:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Import-CA-certificate-and-use-it-for-Multifactor-Authentication/m-p/119051#M22165</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2021-05-21T11:58:06Z</dc:date>
    </item>
    <item>
      <title>Re: Import CA certificate and use it for Multifactor Authentication.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Import-CA-certificate-and-use-it-for-Multifactor-Authentication/m-p/119053#M22167</link>
      <description>&lt;P&gt;Ah ok sorry, I was confused with the usual multifactor authentication profile method, but I am seeing that this is a new feature and most of things are enabled by default. Thank you very much.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 May 2021 12:07:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Import-CA-certificate-and-use-it-for-Multifactor-Authentication/m-p/119053#M22167</guid>
      <dc:creator>Debon27</dc:creator>
      <dc:date>2021-05-21T12:07:05Z</dc:date>
    </item>
  </channel>
</rss>

