<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: The Internal Certificate Authority (ICA) certificate will expire in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/The-Internal-Certificate-Authority-ICA-certificate-will-expire/m-p/191950#M32158</link>
    <description>&lt;P&gt;But the question is, if ICA is automatically renewed, what about VPN certificates and VPN users? Will their connection be affected after ICA auto-renew? Because I can still see the old VPN certificate in the gateway properties.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 07 Sep 2023 18:48:34 GMT</pubDate>
    <dc:creator>starmen2000</dc:creator>
    <dc:date>2023-09-07T18:48:34Z</dc:date>
    <item>
      <title>The Internal Certificate Authority (ICA) certificate will expire</title>
      <link>https://community.checkpoint.com/t5/General-Topics/The-Internal-Certificate-Authority-ICA-certificate-will-expire/m-p/180606#M30150</link>
      <description>&lt;P&gt;Hi All we received this alert since a couple of days that the ICA cert of the SMS will expire in one year. We are using R81.10 at the moment.&lt;/P&gt;&lt;P&gt;Warning (The Internal Certificate Authority (ICA) certificate will expire on May 5 10:02:29 2024 GMT . To renew it, follow &amp;lt;a href = "&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk158096" target="_blank" rel="noopener"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk158096&lt;/A&gt;"&amp;gt;sk158096&amp;lt;/a&amp;gt;)&lt;/P&gt;&lt;P&gt;So there seems to be a procedure to renew this cert but I am very curious on what would be the impact on the Identity awareness agent.&lt;/P&gt;&lt;P&gt;&lt;EM&gt;"The end user is still able to connect from the VPN client and/or Identity Agents by clicking “Trust and continue” / “Trust” respectively.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;To avoid these warning messages in the first place, we recommend that you publish the renewed fingerprint centrally to all your VPN clients / Identity Agents right after the renewal of the Internal CA certificate.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Unfortunately, the new fingerprint is generated only when the Internal CA certificate is renewed.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Note - There is no way to push the new fingerprint before the renewal of the Internal CA certificate"&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;I believe the IA agents are using a different certificate which is installed on the gateway so how does that relate to the ICA cert of the SMS?&lt;/P&gt;&lt;P&gt;We obviously dont want to&amp;nbsp; impact any end user especially the IA agent needs to be connected all the time, could anyone please leave your comments on this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 May 2023 09:09:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/The-Internal-Certificate-Authority-ICA-certificate-will-expire/m-p/180606#M30150</guid>
      <dc:creator>dehaasm</dc:creator>
      <dc:date>2023-05-11T09:09:23Z</dc:date>
    </item>
    <item>
      <title>Re: The Internal Certificate Authority (ICA) certificate will expire</title>
      <link>https://community.checkpoint.com/t5/General-Topics/The-Internal-Certificate-Authority-ICA-certificate-will-expire/m-p/180665#M30164</link>
      <description>&lt;P&gt;Different certificate, but it's signed by the same CA (the Internal CA).&lt;BR /&gt;Having said that, no previously issued certificates will be invalidated.&lt;/P&gt;
&lt;P&gt;Not sure how this works with the Identity Agents, unfortunately.&lt;/P&gt;</description>
      <pubDate>Thu, 11 May 2023 19:25:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/The-Internal-Certificate-Authority-ICA-certificate-will-expire/m-p/180665#M30164</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-05-11T19:25:23Z</dc:date>
    </item>
    <item>
      <title>Re: The Internal Certificate Authority (ICA) certificate will expire</title>
      <link>https://community.checkpoint.com/t5/General-Topics/The-Internal-Certificate-Authority-ICA-certificate-will-expire/m-p/180733#M30179</link>
      <description>&lt;P&gt;I understand but we need to prevent impacting the IA agents installed on the laptops (new fingerprint popup), should I open a TAC case to investigate?&lt;/P&gt;</description>
      <pubDate>Fri, 12 May 2023 12:14:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/The-Internal-Certificate-Authority-ICA-certificate-will-expire/m-p/180733#M30179</guid>
      <dc:creator>dehaasm</dc:creator>
      <dc:date>2023-05-12T12:14:40Z</dc:date>
    </item>
    <item>
      <title>Re: The Internal Certificate Authority (ICA) certificate will expire</title>
      <link>https://community.checkpoint.com/t5/General-Topics/The-Internal-Certificate-Authority-ICA-certificate-will-expire/m-p/180767#M30190</link>
      <description>&lt;P&gt;I would recommend a TAC case on this, yes.&lt;/P&gt;</description>
      <pubDate>Fri, 12 May 2023 18:29:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/The-Internal-Certificate-Authority-ICA-certificate-will-expire/m-p/180767#M30190</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-05-12T18:29:32Z</dc:date>
    </item>
    <item>
      <title>Re: The Internal Certificate Authority (ICA) certificate will expire</title>
      <link>https://community.checkpoint.com/t5/General-Topics/The-Internal-Certificate-Authority-ICA-certificate-will-expire/m-p/181678#M30278</link>
      <description>&lt;P&gt;&lt;STRONG&gt;NEW&lt;/STRONG&gt;&lt;SPAN&gt;: Previously, the Internal CA certificate required manual renewal process. Now it will be automatically renewed one year before its expiration date.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;take 95&amp;nbsp;PRJ-44576,&lt;BR /&gt;PMTR-90463&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;this fixed it automatically&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 22 May 2023 21:15:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/The-Internal-Certificate-Authority-ICA-certificate-will-expire/m-p/181678#M30278</guid>
      <dc:creator>dehaasm</dc:creator>
      <dc:date>2023-05-22T21:15:21Z</dc:date>
    </item>
    <item>
      <title>Re: The Internal Certificate Authority (ICA) certificate will expire</title>
      <link>https://community.checkpoint.com/t5/General-Topics/The-Internal-Certificate-Authority-ICA-certificate-will-expire/m-p/191950#M32158</link>
      <description>&lt;P&gt;But the question is, if ICA is automatically renewed, what about VPN certificates and VPN users? Will their connection be affected after ICA auto-renew? Because I can still see the old VPN certificate in the gateway properties.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Sep 2023 18:48:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/The-Internal-Certificate-Authority-ICA-certificate-will-expire/m-p/191950#M32158</guid>
      <dc:creator>starmen2000</dc:creator>
      <dc:date>2023-09-07T18:48:34Z</dc:date>
    </item>
    <item>
      <title>Re: The Internal Certificate Authority (ICA) certificate will expire</title>
      <link>https://community.checkpoint.com/t5/General-Topics/The-Internal-Certificate-Authority-ICA-certificate-will-expire/m-p/191967#M32160</link>
      <description>&lt;P&gt;No, it should not.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Sep 2023 20:46:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/The-Internal-Certificate-Authority-ICA-certificate-will-expire/m-p/191967#M32160</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-09-07T20:46:45Z</dc:date>
    </item>
    <item>
      <title>Re: The Internal Certificate Authority (ICA) certificate will expire</title>
      <link>https://community.checkpoint.com/t5/General-Topics/The-Internal-Certificate-Authority-ICA-certificate-will-expire/m-p/191989#M32163</link>
      <description>&lt;P&gt;No impact for VPN users. However, VPN users connecting to the gateway where ICA was renewed, will be asked to confirm new fingerprint once ICA is renewed.&lt;/P&gt;</description>
      <pubDate>Fri, 08 Sep 2023 05:40:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/The-Internal-Certificate-Authority-ICA-certificate-will-expire/m-p/191989#M32163</guid>
      <dc:creator>JozkoMrkvicka</dc:creator>
      <dc:date>2023-09-08T05:40:20Z</dc:date>
    </item>
    <item>
      <title>Re: The Internal Certificate Authority (ICA) certificate will expire</title>
      <link>https://community.checkpoint.com/t5/General-Topics/The-Internal-Certificate-Authority-ICA-certificate-will-expire/m-p/192001#M32165</link>
      <description>&lt;P&gt;What about the Site to Site VPNs, theirs autentication works over Certificate from the same SMS? After ICA changed, what are the best practise steps to make sure the tunnels are working properly?&lt;/P&gt;</description>
      <pubDate>Fri, 08 Sep 2023 08:06:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/The-Internal-Certificate-Authority-ICA-certificate-will-expire/m-p/192001#M32165</guid>
      <dc:creator>starmen2000</dc:creator>
      <dc:date>2023-09-08T08:06:28Z</dc:date>
    </item>
    <item>
      <title>Re: The Internal Certificate Authority (ICA) certificate will expire</title>
      <link>https://community.checkpoint.com/t5/General-Topics/The-Internal-Certificate-Authority-ICA-certificate-will-expire/m-p/192011#M32166</link>
      <description>&lt;P&gt;it is automatically renewed since take 95 take a look at release notes we did it and had no impact with identity awareness nor IPsec VPNs although we don't use VPN remote access on the Check Point&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;NEW&lt;/SPAN&gt;: Previously, the Internal CA certificate required manual renewal process. Now it will be automatically renewed one year before its expiration date.&lt;/P&gt;</description>
      <pubDate>Fri, 08 Sep 2023 08:44:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/The-Internal-Certificate-Authority-ICA-certificate-will-expire/m-p/192011#M32166</guid>
      <dc:creator>dehaasm</dc:creator>
      <dc:date>2023-09-08T08:44:36Z</dc:date>
    </item>
    <item>
      <title>Re: The Internal Certificate Authority (ICA) certificate will expire</title>
      <link>https://community.checkpoint.com/t5/General-Topics/The-Internal-Certificate-Authority-ICA-certificate-will-expire/m-p/192067#M32175</link>
      <description>&lt;P&gt;do nothing &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; there is nothing to be worried about S2S VPNs once ICA is renewed. Nothing to do in this area.&lt;/P&gt;</description>
      <pubDate>Fri, 08 Sep 2023 18:29:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/The-Internal-Certificate-Authority-ICA-certificate-will-expire/m-p/192067#M32175</guid>
      <dc:creator>JozkoMrkvicka</dc:creator>
      <dc:date>2023-09-08T18:29:41Z</dc:date>
    </item>
    <item>
      <title>Re: The Internal Certificate Authority (ICA) certificate will expire</title>
      <link>https://community.checkpoint.com/t5/General-Topics/The-Internal-Certificate-Authority-ICA-certificate-will-expire/m-p/192068#M32176</link>
      <description>&lt;P&gt;As&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1702"&gt;@JozkoMrkvicka&lt;/a&gt;&amp;nbsp;said, no need to worry &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Sep 2023 18:31:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/The-Internal-Certificate-Authority-ICA-certificate-will-expire/m-p/192068#M32176</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-09-08T18:31:46Z</dc:date>
    </item>
  </channel>
</rss>

