<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ACME Support in Check Point products | SSL/TLS certificate lifespans reduced to 47 days by 2029 in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/ACME-Support-in-Check-Point-products-SSL-TLS-certificate/m-p/246584#M41202</link>
    <description>&lt;P&gt;Read about it yesterday, was having hard time believing it was true, but it definitely is.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Tue, 15 Apr 2025 23:12:27 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2025-04-15T23:12:27Z</dc:date>
    <item>
      <title>ACME Support in Check Point products | SSL/TLS certificate lifespans reduced to 47 days by 2029</title>
      <link>https://community.checkpoint.com/t5/General-Topics/ACME-Support-in-Check-Point-products-SSL-TLS-certificate/m-p/246469#M41179</link>
      <description>&lt;P&gt;Hello Checkmates!&lt;BR /&gt;&lt;BR /&gt;As you may have already heared the C&lt;SPAN&gt;A/Browser Forum has voted to significantly reduce&amp;nbsp;the lifespan of SSL/TLS certificates over the next 4 years, with a final lifespan of just 47 days starting in 2029.&lt;BR /&gt;&lt;BR /&gt;We are currently replacing our certificates via cpopenssl yearly by hand but this is no longer feasible when the lifespans willl be reduced every year now until 2029.&lt;BR /&gt;&lt;BR /&gt;Are there already out of the box solutions in the Check Point product suite for protocols like ACME to support auto renewal of certificates in Check Point products?&lt;BR /&gt;&lt;BR /&gt;Best regards&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Apr 2025 07:36:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/ACME-Support-in-Check-Point-products-SSL-TLS-certificate/m-p/246469#M41179</guid>
      <dc:creator>ProxyOps</dc:creator>
      <dc:date>2025-04-15T07:36:42Z</dc:date>
    </item>
    <item>
      <title>Re: ACME Support in Check Point products | SSL/TLS certificate lifespans reduced to 47 days by 2029</title>
      <link>https://community.checkpoint.com/t5/General-Topics/ACME-Support-in-Check-Point-products-SSL-TLS-certificate/m-p/246556#M41191</link>
      <description>&lt;P&gt;I know we have REST API support for changing certificates used for HTTPS Inspection as well as some of the certificates on the gateway itself in R82.&lt;BR /&gt;That's not ACME support, of course.&lt;BR /&gt;I recommend engaging with your local Check Point office with your precise requirements.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Apr 2025 16:40:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/ACME-Support-in-Check-Point-products-SSL-TLS-certificate/m-p/246556#M41191</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-04-15T16:40:35Z</dc:date>
    </item>
    <item>
      <title>Re: ACME Support in Check Point products | SSL/TLS certificate lifespans reduced to 47 days by 2029</title>
      <link>https://community.checkpoint.com/t5/General-Topics/ACME-Support-in-Check-Point-products-SSL-TLS-certificate/m-p/246563#M41195</link>
      <description>&lt;P&gt;Read about this today too, the changes will be phased as follows:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;March 15, 2026: Newly issued certificates, including their Domain Control Validation, aka DCV, will have to be renewed every 200 days.&lt;/LI&gt;
&lt;LI&gt;March 15, 2027: That lifespan will go down to 100 days.&lt;/LI&gt;
&lt;LI&gt;March 15, 2029: New SSL/TLS certificates will be limited to 47 days, and 10 days for DCVs.&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Tue, 15 Apr 2025 17:17:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/ACME-Support-in-Check-Point-products-SSL-TLS-certificate/m-p/246563#M41195</guid>
      <dc:creator>Alex-</dc:creator>
      <dc:date>2025-04-15T17:17:27Z</dc:date>
    </item>
    <item>
      <title>Re: ACME Support in Check Point products | SSL/TLS certificate lifespans reduced to 47 days by 2029</title>
      <link>https://community.checkpoint.com/t5/General-Topics/ACME-Support-in-Check-Point-products-SSL-TLS-certificate/m-p/246584#M41202</link>
      <description>&lt;P&gt;Read about it yesterday, was having hard time believing it was true, but it definitely is.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 15 Apr 2025 23:12:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/ACME-Support-in-Check-Point-products-SSL-TLS-certificate/m-p/246584#M41202</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-04-15T23:12:27Z</dc:date>
    </item>
    <item>
      <title>Re: ACME Support in Check Point products | SSL/TLS certificate lifespans reduced to 47 days by 2029</title>
      <link>https://community.checkpoint.com/t5/General-Topics/ACME-Support-in-Check-Point-products-SSL-TLS-certificate/m-p/246600#M41204</link>
      <description>&lt;P&gt;i second this. would be great to configure multiportal deamon to present ACME certificates and renew them automatically.&amp;nbsp; something completely different from https inspection&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Great would be&amp;nbsp; being able to have an option on several portals independent from each other. (perhaps per hostname, instead port) and in smartconsole / mgmt api - like saml-vpn, sslvpn, usercheck and so on.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Apr 2025 07:15:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/ACME-Support-in-Check-Point-products-SSL-TLS-certificate/m-p/246600#M41204</guid>
      <dc:creator>Nüüül</dc:creator>
      <dc:date>2025-04-16T07:15:40Z</dc:date>
    </item>
    <item>
      <title>Re: ACME Support in Check Point products | SSL/TLS certificate lifespans reduced to 47 days by 2029</title>
      <link>https://community.checkpoint.com/t5/General-Topics/ACME-Support-in-Check-Point-products-SSL-TLS-certificate/m-p/263756#M44545</link>
      <description>&lt;P&gt;i also have taken this to checkpoint support, and they said i should submit a RFE via checkpoint office...&lt;/P&gt;&lt;P&gt;...funny thing is that they don't seem to know there own product, because with R82 API you can already do all the needed certificate settings...&lt;/P&gt;&lt;P&gt;see&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/latest/APIs/index.html?#cli/set-simple-cluster~v2.0.1" target="_blank" rel="noopener"&gt;https://sc1.checkpoint.com/documents/latest/APIs/index.html?#cli/set-simple-cluster~v2.0.1&lt;/A&gt;&lt;/P&gt;&lt;P&gt;for example:&lt;/P&gt;&lt;PRE&gt;add via api:&lt;BR /&gt;mgmt_cli --root true set simple-cluster name "CLUSTER" vpn-settings.certificates.add.name "testcertdeleteme" vpn-settings.certificates.add.certificate-authority "HARICA_TLS_RSA_Root_CA_2021" vpn-settings.certificates.add.enrollment.enrollment-settings.distinguished-name "CN=commonname.com,O=Org,ST=Vienna,C=AT" vpn-settings.certificates.add.enrollment.enrollment-settings.alternate-names.1.name-type "fqdn" vpn-settings.certificates.add.enrollment.enrollment-settings.alternate-names.1.value "3.commonname.com" vpn-settings.certificates.add.enrollment.enrollment-settings.alternate-names.2.name-type "fqdn" vpn-settings.certificates.add.enrollment.enrollment-settings.alternate-names.2.value "firewall.commonname.com"&lt;/PRE&gt;&lt;PRE&gt;remove via api:&lt;BR /&gt;mgmt_cli --root true set simple-cluster name "CLUSTER" vpn-settings.certificates.remove "cername_exp20251113" ignore-warnings "true"&lt;/PRE&gt;&lt;P&gt;usercheck portal would be:&lt;/P&gt;&lt;P&gt;mgmt_cli --root true set simple-cluster name "CLUSTER" &lt;SPAN class=""&gt;usercheck-portal-settings.certificate-settings&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;so if you have the certificate via acme, you can import it via api, at least on R82&lt;/P&gt;</description>
      <pubDate>Thu, 27 Nov 2025 10:04:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/ACME-Support-in-Check-Point-products-SSL-TLS-certificate/m-p/263756#M44545</guid>
      <dc:creator>GHaider</dc:creator>
      <dc:date>2025-11-27T10:04:41Z</dc:date>
    </item>
    <item>
      <title>Re: ACME Support in Check Point products | SSL/TLS certificate lifespans reduced to 47 days by 2029</title>
      <link>https://community.checkpoint.com/t5/General-Topics/ACME-Support-in-Check-Point-products-SSL-TLS-certificate/m-p/267493#M45014</link>
      <description>&lt;P&gt;Thanks mate! will have a look at it shortly&lt;/P&gt;</description>
      <pubDate>Thu, 15 Jan 2026 15:31:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/ACME-Support-in-Check-Point-products-SSL-TLS-certificate/m-p/267493#M45014</guid>
      <dc:creator>Nüüül</dc:creator>
      <dc:date>2026-01-15T15:31:44Z</dc:date>
    </item>
    <item>
      <title>Re: ACME Support in Check Point products | SSL/TLS certificate lifespans reduced to 47 days by 2029</title>
      <link>https://community.checkpoint.com/t5/General-Topics/ACME-Support-in-Check-Point-products-SSL-TLS-certificate/m-p/274526#M45915</link>
      <description>&lt;P&gt;Any news from Check Point regarding the&amp;nbsp;damocles sword with certificate lifespans?&lt;BR /&gt;Our certificates from Web SmartConsole now need to be replaced every 7 months and I really hate the idea to do this manual reneweal process every 47 days in 2029.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Is there any strategy / recommendation from Check Point or is every check point customer on its own?&lt;/P&gt;</description>
      <pubDate>Tue, 31 Mar 2026 07:44:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/ACME-Support-in-Check-Point-products-SSL-TLS-certificate/m-p/274526#M45915</guid>
      <dc:creator>ProxyOps</dc:creator>
      <dc:date>2026-03-31T07:44:30Z</dc:date>
    </item>
    <item>
      <title>Re: ACME Support in Check Point products | SSL/TLS certificate lifespans reduced to 47 days by 2029</title>
      <link>https://community.checkpoint.com/t5/General-Topics/ACME-Support-in-Check-Point-products-SSL-TLS-certificate/m-p/274527#M45916</link>
      <description>&lt;P&gt;I think its important to note that this challenge is faced by all vendors, so it would logically make sense that all vendors need to update there systems to have a user friendly mechanism to auto renew certificates either via a public CA or Private CA.&lt;BR /&gt;From a Checkpoint prospective, there should be a solution that addresses this via SmartConsole and also at GAIA WEBUI level as it is feasible to have a device level certificate.&lt;BR /&gt;&lt;BR /&gt;I'm not sure why a RFE would be needed considering the industry level impact here.&lt;/P&gt;
&lt;P&gt;The question here also is if using certificates becomes impractical, then what are the alternatives to safeguard sites and identities.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 31 Mar 2026 08:22:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/ACME-Support-in-Check-Point-products-SSL-TLS-certificate/m-p/274527#M45916</guid>
      <dc:creator>genisis__</dc:creator>
      <dc:date>2026-03-31T08:22:00Z</dc:date>
    </item>
  </channel>
</rss>

