<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Machine certificate authentication on R80.20 in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Machine-certificate-authentication-on-R80-20/m-p/83505#M10564</link>
    <description>&lt;P&gt;I have an end customer who wants to be able to deploy machine authentication for clients and username and password but then if they have people using their own PC, they will use the clientless portal (SNX).&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Following SK121173, we obtained the hotfix "&lt;SPAN&gt;fw1_wrapper_HOTFIX_R80_20_JHF_T114_469_470_MAIN_GA_FULL&lt;/SPAN&gt;" from our local SE.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I implement the following, we are able to log in with just username and password: -&lt;/P&gt;&lt;P&gt;&lt;EM&gt;ckp_regedit -a SOFTWARE/CheckPoint/VPN1 machine_cert_auth 1&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;But if I enforce machine certificate authentication by running&amp;nbsp;ckp_regedit -a SOFTWARE/CheckPoint/VPN1 machine_cert_auth 2 , it fails.&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;At first I was receiving an error stating the CRL could not be fetched. I disabled this by unchecking the option on the trusted CA server object as I wanted to be able to test it working first.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I now get the following error: -&lt;/P&gt;&lt;P&gt;"Connection Failed: Machine certificate is required".&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I generated a certificate and installed on the client PC but still get the same error message.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does the certificate have to be installed in a particular certificate store?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 28 Apr 2020 15:53:09 GMT</pubDate>
    <dc:creator>scottikon</dc:creator>
    <dc:date>2020-04-28T15:53:09Z</dc:date>
    <item>
      <title>Machine certificate authentication on R80.20</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Machine-certificate-authentication-on-R80-20/m-p/83505#M10564</link>
      <description>&lt;P&gt;I have an end customer who wants to be able to deploy machine authentication for clients and username and password but then if they have people using their own PC, they will use the clientless portal (SNX).&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Following SK121173, we obtained the hotfix "&lt;SPAN&gt;fw1_wrapper_HOTFIX_R80_20_JHF_T114_469_470_MAIN_GA_FULL&lt;/SPAN&gt;" from our local SE.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I implement the following, we are able to log in with just username and password: -&lt;/P&gt;&lt;P&gt;&lt;EM&gt;ckp_regedit -a SOFTWARE/CheckPoint/VPN1 machine_cert_auth 1&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;But if I enforce machine certificate authentication by running&amp;nbsp;ckp_regedit -a SOFTWARE/CheckPoint/VPN1 machine_cert_auth 2 , it fails.&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;At first I was receiving an error stating the CRL could not be fetched. I disabled this by unchecking the option on the trusted CA server object as I wanted to be able to test it working first.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I now get the following error: -&lt;/P&gt;&lt;P&gt;"Connection Failed: Machine certificate is required".&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I generated a certificate and installed on the client PC but still get the same error message.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does the certificate have to be installed in a particular certificate store?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Apr 2020 15:53:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Machine-certificate-authentication-on-R80-20/m-p/83505#M10564</guid>
      <dc:creator>scottikon</dc:creator>
      <dc:date>2020-04-28T15:53:09Z</dc:date>
    </item>
    <item>
      <title>Re: Machine certificate authentication on R80.20</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Machine-certificate-authentication-on-R80-20/m-p/83518#M10565</link>
      <description>Yes, it needs to be a machine certificate from the Windows System Store.&lt;BR /&gt;Note that if you have multiple machine certs, we will choose the one with the longest expiration date to authenticate with.</description>
      <pubDate>Tue, 28 Apr 2020 17:25:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Machine-certificate-authentication-on-R80-20/m-p/83518#M10565</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-04-28T17:25:06Z</dc:date>
    </item>
    <item>
      <title>Machine certificate authentication on R80.20</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Machine-certificate-authentication-on-R80-20/m-p/89689#M10566</link>
      <description>&lt;P&gt;The issue was resolved by adding the Root CA as a trusted CA server and importing that certificate. The subs wouldn't work. This solution was in collaboration with Check Point R&amp;amp;D.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have asked for the SK121173 to be updated but doesn't look like it has yet.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jun 2020 13:24:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Machine-certificate-authentication-on-R80-20/m-p/89689#M10566</guid>
      <dc:creator>scottikon</dc:creator>
      <dc:date>2020-06-24T13:24:08Z</dc:date>
    </item>
  </channel>
</rss>

