<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HTTPS inspection with trusted certificate in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/HTTPS-inspection-with-trusted-certificate/m-p/24793#M4960</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;However, the custom categories do not appear in the list using the ACST.exe tool.  Only Checkpoints standard categories.  I am using ACST_v1.3.1.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 02 Feb 2018 17:15:53 GMT</pubDate>
    <dc:creator>John_Curtiss</dc:creator>
    <dc:date>2018-02-02T17:15:53Z</dc:date>
    <item>
      <title>HTTPS inspection with trusted certificate</title>
      <link>https://community.checkpoint.com/t5/General-Topics/HTTPS-inspection-with-trusted-certificate/m-p/24785#M4952</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Guys, I need your help regarding https.&lt;/P&gt;&lt;P&gt;We have a checkpoint deployment and want to enable https inspection but need a trusted certificate.&lt;/P&gt;&lt;P&gt;Please do advice on how/where to get this trusted certificates and types with details on how to make filtering sub https pages.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Jan 2018 09:49:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/HTTPS-inspection-with-trusted-certificate/m-p/24785#M4952</guid>
      <dc:creator>Ewane_Junior</dc:creator>
      <dc:date>2018-01-23T09:49:25Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS inspection with trusted certificate</title>
      <link>https://community.checkpoint.com/t5/General-Topics/HTTPS-inspection-with-trusted-certificate/m-p/24786#M4953</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ewane,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In order to implement HTTPS inspection, you need to either use Root or sub-CA.&lt;/P&gt;&lt;P&gt;The easiest way to get this to work is to issue a self-signed certificate on your Check Point gateway and distribute it to PCs and servers in your organization via GPO, (or installed manually or scripted).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Alternatively, if you have an established PKI in your organization, you can create certificate in there and import it in Check Point gateways.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you were thinking about using host certificate purchased from one of the vendors such as Comodo, GoDaddy, etc, this will not work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I strongly suggest reading&amp;nbsp;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk65123" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk65123"&gt;HTTPS Inspection FAQ&lt;/A&gt;&amp;nbsp;and&amp;nbsp;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk98025" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk98025"&gt;HTTPS inspection with 3rd party certificate shows browser error&lt;/A&gt;&amp;nbsp;.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Jan 2018 13:55:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/HTTPS-inspection-with-trusted-certificate/m-p/24786#M4953</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2018-01-23T13:55:51Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS inspection with trusted certificate</title>
      <link>https://community.checkpoint.com/t5/General-Topics/HTTPS-inspection-with-trusted-certificate/m-p/24787#M4954</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can watch this short video that illustrates the process using manual root CA certificate installation process:&lt;/P&gt;&lt;P&gt;&lt;A class="jivelink13" href="https://youtu.be/hzpCxlLTge0" title="https://youtu.be/hzpCxlLTge0"&gt;https://youtu.be/hzpCxlLTge0&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Jan 2018 14:44:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/HTTPS-inspection-with-trusted-certificate/m-p/24787#M4954</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2018-01-23T14:44:22Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS inspection with trusted certificate</title>
      <link>https://community.checkpoint.com/t5/General-Topics/HTTPS-inspection-with-trusted-certificate/m-p/24788#M4955</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;BLOCKQUOTE class="jive_macro_quote jive-quote jive_text_macro"&gt;&lt;P&gt;If you were thinking about using host certificate purchased from one of the vendors such as Comodo, GoDaddy, etc, this will not work.&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Using such sub-CA keys for HTTPS Inspection purposes is explicitly against the Terms of Service of public CAs.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 27 Jan 2018 06:38:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/HTTPS-inspection-with-trusted-certificate/m-p/24788#M4955</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-01-27T06:38:45Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS inspection with trusted certificate</title>
      <link>https://community.checkpoint.com/t5/General-Topics/HTTPS-inspection-with-trusted-certificate/m-p/24789#M4956</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I found that when using https inspection that if an sub-https page is called for certificate exchange - in the client hello SNI field that the exchange will fail as the firewall detects the first packet is not a syn.&amp;nbsp; The way I have bypassed this is downloading the "Application Control Signature Tool" from Checkpoint.&amp;nbsp; You build your own app from the contents of the SNI field as if it were a Checkpoint built app.&amp;nbsp; (Unfortunately you cannot add custom categories so I just use Government.)&amp;nbsp; In my https inspection policies I bypass Government.&amp;nbsp; It not perfect but it is allowing https inspection to run for all applications.&amp;nbsp; Of course I have to build an app any time something fails.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Jan 2018 21:13:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/HTTPS-inspection-with-trusted-certificate/m-p/24789#M4956</guid>
      <dc:creator>John_Curtiss</dc:creator>
      <dc:date>2018-01-29T21:13:52Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS inspection with trusted certificate</title>
      <link>https://community.checkpoint.com/t5/General-Topics/HTTPS-inspection-with-trusted-certificate/m-p/24790#M4957</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello John,&lt;/P&gt;&lt;P&gt;It is possible to create a custom category and include all your self-signed build app instead of using Checkpoint already assigned category.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Feb 2018 08:38:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/HTTPS-inspection-with-trusted-certificate/m-p/24790#M4957</guid>
      <dc:creator>Ewane_Junior</dc:creator>
      <dc:date>2018-02-02T08:38:50Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS inspection with trusted certificate</title>
      <link>https://community.checkpoint.com/t5/General-Topics/HTTPS-inspection-with-trusted-certificate/m-p/24791#M4958</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;How?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Feb 2018 16:35:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/HTTPS-inspection-with-trusted-certificate/m-p/24791#M4958</guid>
      <dc:creator>John_Curtiss</dc:creator>
      <dc:date>2018-02-02T16:35:41Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS inspection with trusted certificate</title>
      <link>https://community.checkpoint.com/t5/General-Topics/HTTPS-inspection-with-trusted-certificate/m-p/24792#M4959</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Go to the application tab&lt;/P&gt;&lt;P&gt;click on application/sites&lt;/P&gt;&lt;P&gt;click on new and select category&lt;/P&gt;&lt;P&gt;add a name and click finish&lt;/P&gt;&lt;P&gt;Now when you are creating your application use that category new.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/62814_pastedImage_2.png" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Feb 2018 16:55:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/HTTPS-inspection-with-trusted-certificate/m-p/24792#M4959</guid>
      <dc:creator>Ewane_Junior</dc:creator>
      <dc:date>2018-02-02T16:55:21Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS inspection with trusted certificate</title>
      <link>https://community.checkpoint.com/t5/General-Topics/HTTPS-inspection-with-trusted-certificate/m-p/24793#M4960</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;However, the custom categories do not appear in the list using the ACST.exe tool.  Only Checkpoints standard categories.  I am using ACST_v1.3.1.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Feb 2018 17:15:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/HTTPS-inspection-with-trusted-certificate/m-p/24793#M4960</guid>
      <dc:creator>John_Curtiss</dc:creator>
      <dc:date>2018-02-02T17:15:53Z</dc:date>
    </item>
  </channel>
</rss>

