<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SBOM / SPDX support for Checkpoint products in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/SBOM-SPDX-support-for-Checkpoint-products/m-p/280605#M46643</link>
    <description>&lt;P&gt;If I understand it correctly the european Cyber Resilance Act will need SBOM for any digital product in december 2027. I think that checkpoint is aware of this and will provide such lists in 2027.&lt;/P&gt;</description>
    <pubDate>Fri, 31 Jul 2026 09:41:01 GMT</pubDate>
    <dc:creator>Jan_Kleinhans</dc:creator>
    <dc:date>2026-07-31T09:41:01Z</dc:date>
    <item>
      <title>SBOM / SPDX support for Checkpoint products</title>
      <link>https://community.checkpoint.com/t5/General-Topics/SBOM-SPDX-support-for-Checkpoint-products/m-p/280446#M46632</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;i am in the process of planing for a SBOM project. SBOM is about securing the supply chain for software products.&lt;/P&gt;&lt;P&gt;Details see here:&amp;nbsp;&lt;A href="https://www.cisa.gov/resources-tools/resources/2026-minimum-elements-software-bill-materials-sbom" target="_blank"&gt;https://www.cisa.gov/resources-tools/resources/2026-minimum-elements-software-bill-materials-sbom&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Part of this is to get a list of all vendor supplied files with their checksums, to be able to do periodic (automatic) audits, identifiy patch needs, etc. That includes my Checkpoint firewalls.&lt;/P&gt;&lt;P&gt;This software/files/checksum info is typically in SPDX format (see &lt;A href="https://spdx.dev" target="_blank"&gt;https://spdx.dev/&lt;/A&gt;). This info is not just needed, but has to come via the software supply chain, and has to be electronically signed by the vendor, e.g. Checkpoint.&lt;/P&gt;&lt;P&gt;Typical RPM packages (e.g. from RHEL) satisfy this requirement: the files are listed/there, with their checksum, the whole package is signed.&lt;/P&gt;&lt;P&gt;However Checkpoint products seem to use unsigned RPMs! And possibly some stuff outside of RPM, directly via the installer?&lt;/P&gt;&lt;P&gt;Questions:&lt;/P&gt;&lt;P&gt;Does Checkpoint have some other method of supporting SBOM/SPDX?&lt;/P&gt;&lt;P&gt;If so, how?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Why are the Checkpoint supplied RPMs not protected via a signature?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best Regards&lt;/P&gt;&lt;P&gt;Matthias&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On a normal RHEL, signatures are present:&lt;/P&gt;&lt;P&gt;# rpm -q --qf '%{NAME}-%{VERSION} %{SIGPGP:pgpsig} %{SIGGPG:pgpsig} \n' util-linux&lt;BR /&gt;util-linux-2.37.4 RSA/SHA256, Mo 06 Apr 2026 10:32:33 CEST, Key ID d36cb86cb86b3716 (none)&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;On Checkpoint servers signatures are missing:&lt;/P&gt;&lt;P&gt;# rpm -q --qf '%{NAME}-%{VERSION} %{SIGPGP:pgpsig} %{SIGGPG:pgpsig} \n' util-linux&lt;BR /&gt;util-linux-2.23.2 (not a blob) (not a blob)&lt;/P&gt;&lt;P&gt;# rpm -q --qf '%{NAME}-%{VERSION} %{SIGPGP:pgpsig} %{SIGGPG:pgpsig} \n' CPinfo&lt;BR /&gt;CPinfo-10 (not a blob) (not a blob)&lt;/P&gt;&lt;P&gt;# rpm -q -info CPinfo&lt;BR /&gt;Name : CPinfo Relocations: (not relocatable)&lt;BR /&gt;Version : 10 Vendor: Check Point Software Ltd.&lt;BR /&gt;Release : 00 Build Date: Sun Apr 21 10:28:50 2024&lt;BR /&gt;Install Date: Wed Oct 16 10:47:57 2024 Build Host: Lnx50BccCmp7.checkpoint.com&lt;BR /&gt;Group : Networking/Admin Source RPM: CPinfo-10-00.src.rpm&lt;BR /&gt;Size : 14934372 License: This Software is licensed to you from the Check Point Software Ltd.&lt;BR /&gt;&lt;STRONG&gt;Signature : (none)&lt;/STRONG&gt;&lt;BR /&gt;Packager : Check Point Software Ltd.&lt;BR /&gt;URL : &lt;A href="http://www.checkpoint.com" target="_blank"&gt;http://www.checkpoint.com&lt;/A&gt;&lt;BR /&gt;Summary : Check Point CPinfo&lt;BR /&gt;Description :&lt;BR /&gt;Check Point CPinfo for Linux.&lt;/P&gt;&lt;P&gt;# rpm -q -info CPsuite&lt;BR /&gt;Name : CPsuite Relocations: (not relocatable)&lt;BR /&gt;Version : R81.20 Vendor: Check Point Software Technologies Ltd.&lt;BR /&gt;Release : 00 Build Date: Wed Nov 16 12:27:02 2022&lt;BR /&gt;Install Date: Wed Apr 19 11:07:05 2023 Build Host: Lnx50BccCmp3.checkpoint.com&lt;BR /&gt;Group : Networking/Admin Source RPM: CPsuite-R81.20-00.src.rpm&lt;BR /&gt;Size : 1969463695 License: This Software is licensed to you from Check Point Software Technologies Ltd.&lt;BR /&gt;&lt;STRONG&gt;Signature : (none)&lt;/STRONG&gt;&lt;BR /&gt;Packager : Check Point Software Technologies Ltd.&lt;BR /&gt;URL : &lt;A href="http://www.checkpoint.com" target="_blank"&gt;http://www.checkpoint.com&lt;/A&gt;&lt;BR /&gt;Summary : Check Point R81.20.&lt;BR /&gt;Description :&lt;BR /&gt;Check Point Firewall-1(TM) and VPN-1(TM) for Linux.&lt;BR /&gt;The leading FireWall and VPN software for your Linux servers and embedded systems&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jul 2026 08:19:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/SBOM-SPDX-support-for-Checkpoint-products/m-p/280446#M46632</guid>
      <dc:creator>Matthias42</dc:creator>
      <dc:date>2026-07-30T08:19:53Z</dc:date>
    </item>
    <item>
      <title>Re: SBOM / SPDX support for Checkpoint products</title>
      <link>https://community.checkpoint.com/t5/General-Topics/SBOM-SPDX-support-for-Checkpoint-products/m-p/280515#M46636</link>
      <description>&lt;P&gt;This is probably an &lt;A href="https://usercenter.checkpoint.com/ucapps/rfe/" target="_blank"&gt;RFE&lt;/A&gt;&amp;nbsp;and you should work with your local Check Point office to promote it.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jul 2026 13:41:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/SBOM-SPDX-support-for-Checkpoint-products/m-p/280515#M46636</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2026-07-30T13:41:25Z</dc:date>
    </item>
    <item>
      <title>Re: SBOM / SPDX support for Checkpoint products</title>
      <link>https://community.checkpoint.com/t5/General-Topics/SBOM-SPDX-support-for-Checkpoint-products/m-p/280603#M46642</link>
      <description>&lt;P&gt;I filled out the RFE form. Lets see what happens.&lt;/P&gt;&lt;P&gt;The local Checkpoint office is kind of a dead end. I've dealt with them before. They are interested in one thing only: Provisions. They ask themself: how much extra provisions do i get, if an existing customer is happy about a new feature? zero?-&amp;gt;plonk-&amp;gt;end of story.&lt;/P&gt;&lt;P&gt;My guess is, lots of customers will want this. So i will just wait until somebody else does this fight.&lt;/P&gt;</description>
      <pubDate>Fri, 31 Jul 2026 06:32:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/SBOM-SPDX-support-for-Checkpoint-products/m-p/280603#M46642</guid>
      <dc:creator>Matthias42</dc:creator>
      <dc:date>2026-07-31T06:32:38Z</dc:date>
    </item>
    <item>
      <title>Re: SBOM / SPDX support for Checkpoint products</title>
      <link>https://community.checkpoint.com/t5/General-Topics/SBOM-SPDX-support-for-Checkpoint-products/m-p/280605#M46643</link>
      <description>&lt;P&gt;If I understand it correctly the european Cyber Resilance Act will need SBOM for any digital product in december 2027. I think that checkpoint is aware of this and will provide such lists in 2027.&lt;/P&gt;</description>
      <pubDate>Fri, 31 Jul 2026 09:41:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/SBOM-SPDX-support-for-Checkpoint-products/m-p/280605#M46643</guid>
      <dc:creator>Jan_Kleinhans</dc:creator>
      <dc:date>2026-07-31T09:41:01Z</dc:date>
    </item>
    <item>
      <title>Re: SBOM / SPDX support for Checkpoint products</title>
      <link>https://community.checkpoint.com/t5/General-Topics/SBOM-SPDX-support-for-Checkpoint-products/m-p/280606#M46644</link>
      <description>&lt;P&gt;To my knowledge, CRA is applied to "products". That means Checkpoint has to take care of this internally for the stuff they sell. But CRA does not necessarily require Checkpoint to provide its customers this info.&lt;/P&gt;&lt;P&gt;However many "regulation" or "certification" bodys do require it for Checkpoints customers. E.g. Finance, Automotive, Government, NIS2?, etc.&lt;/P&gt;&lt;P&gt;But i am by no means an expert on the regulation rules, so my current knowledge may be wrong.&lt;/P&gt;</description>
      <pubDate>Fri, 31 Jul 2026 10:28:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/SBOM-SPDX-support-for-Checkpoint-products/m-p/280606#M46644</guid>
      <dc:creator>Matthias42</dc:creator>
      <dc:date>2026-07-31T10:28:25Z</dc:date>
    </item>
  </channel>
</rss>

