<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Changing the Certificate presented during  Endpoint Security Client in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Changing-the-Certificate-presented-during-Endpoint-Security/m-p/105662#M10810</link>
    <description>&lt;P&gt;if you have "mobile access" blade disabled, this setting is ignored, and it always uses the defaultCert from the internal CA...&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2020-12-16 190433.jpg" style="width: 761px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/9785i3946DDA989BBC645/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2020-12-16 190433.jpg" alt="Screenshot 2020-12-16 190433.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;no way to change the certificate for me... &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 16 Dec 2020 18:20:33 GMT</pubDate>
    <dc:creator>GHaider</dc:creator>
    <dc:date>2020-12-16T18:20:33Z</dc:date>
    <item>
      <title>Changing the Certificate presented during  Endpoint Security Client</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Changing-the-Certificate-presented-during-Endpoint-Security/m-p/80714#M10798</link>
      <description>&lt;P&gt;Good day Mates&lt;/P&gt;&lt;P&gt;We are currently using the Check Point Endpoint Security, and during the Site creation, we are presented with a self-signed certificate. We wish to change that to a certificate signed by a CA.&lt;/P&gt;&lt;P&gt;Any idea on how that could be accomplished? we are using R80.20.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Fri, 03 Apr 2020 08:09:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Changing-the-Certificate-presented-during-Endpoint-Security/m-p/80714#M10798</guid>
      <dc:creator>Di_Junior</dc:creator>
      <dc:date>2020-04-03T08:09:55Z</dc:date>
    </item>
    <item>
      <title>Re: Changing the Certificate presented during  Endpoint Security Client</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Changing-the-Certificate-presented-during-Endpoint-Security/m-p/80888#M10799</link>
      <description>&lt;P&gt;Why do you wish to change the CA used here exactly?&lt;/P&gt;
&lt;P&gt;The key presented is signed by a Certificate Authority: the internal Check Point one.&lt;BR /&gt;As it is used for a lot of things (including VPN), the internal CA cannot be removed.&lt;BR /&gt;You also cannot replace the internal CA with an external one.&lt;/P&gt;
&lt;P&gt;I know for site-to-site VPNs for third parties, you can specify which Certificate Authorities can be used for VPN.&lt;BR /&gt;That's done here:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2020-04-05 at 8.40.52 PM.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/5394i17D96115962CE021/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screen Shot 2020-04-05 at 8.40.52 PM.png" alt="Screen Shot 2020-04-05 at 8.40.52 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;To add a different trusted CA, you need to create an object for it:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2020-04-05 at 8.44.14 PM.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/5395i3F39133B52FA2FA1/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screen Shot 2020-04-05 at 8.44.14 PM.png" alt="Screen Shot 2020-04-05 at 8.44.14 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Whether that works for Remote Access VPN is a separate question.&amp;nbsp;&lt;BR /&gt;Even if you could, I don't believe it changes the end user experience at all (i.e. they'll still get prompted to validate the site certificate when they first connect).&lt;/P&gt;</description>
      <pubDate>Mon, 06 Apr 2020 03:50:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Changing-the-Certificate-presented-during-Endpoint-Security/m-p/80888#M10799</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-04-06T03:50:18Z</dc:date>
    </item>
    <item>
      <title>Re: Changing the Certificate presented during  Endpoint Security Client</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Changing-the-Certificate-presented-during-Endpoint-Security/m-p/80896#M10800</link>
      <description>&lt;P&gt;Sure it can be changed and it is often necessary, if you have external partners connecting using a client VPN solution.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You have to first add the CAs, then create a CSR in the IPSEC VPN of the gateway.&lt;/P&gt;
&lt;P&gt;Here an example from my lab:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2020-04-06_08-00-35.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/5396i03B275BF693E19A2/image-size/medium?v=v2&amp;amp;px=400" role="button" title="2020-04-06_08-00-35.png" alt="2020-04-06_08-00-35.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;After completing the CSR, you can choose the certificate under "VPN Client":&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="2020-04-06_08-00-52.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/5397i1A18EEF88BE05E89/image-size/medium?v=v2&amp;amp;px=400" role="button" title="2020-04-06_08-00-52.png" alt="2020-04-06_08-00-52.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But if you have Mobile Access active and you change the certificate there on the MP daemon, you don't need this and it is also changed for VPN clients:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2020-04-06_08-05-40.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/5398i06BC5DAD1B546808/image-size/medium?v=v2&amp;amp;px=400" role="button" title="2020-04-06_08-05-40.png" alt="2020-04-06_08-05-40.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Apr 2020 06:06:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Changing-the-Certificate-presented-during-Endpoint-Security/m-p/80896#M10800</guid>
      <dc:creator>Norbert_Bohusch</dc:creator>
      <dc:date>2020-04-06T06:06:16Z</dc:date>
    </item>
    <item>
      <title>Re: Changing the Certificate presented during  Endpoint Security Client</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Changing-the-Certificate-presented-during-Endpoint-Security/m-p/80905#M10801</link>
      <description>Hi Norbert&lt;BR /&gt;Thanks for your help.&lt;BR /&gt;Could you kindly tel me how to generate a CSR in the IPSEC of the gateway?&lt;BR /&gt;Thanks once again</description>
      <pubDate>Mon, 06 Apr 2020 07:27:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Changing-the-Certificate-presented-during-Endpoint-Security/m-p/80905#M10801</guid>
      <dc:creator>Di_Junior</dc:creator>
      <dc:date>2020-04-06T07:27:32Z</dc:date>
    </item>
    <item>
      <title>Re: Changing the Certificate presented during  Endpoint Security Client</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Changing-the-Certificate-presented-during-Endpoint-Security/m-p/80906#M10802</link>
      <description>You click add, choose the right CA (has to be imported before), then enter details like DN and SAN.&lt;BR /&gt;After clicking ok, you can select the line with the new certificate and click view. Then you see the CSR.&lt;BR /&gt;You let your CA sign the CSR and then go back to this menu and click complete and paste the cert.&lt;BR /&gt;</description>
      <pubDate>Mon, 06 Apr 2020 07:29:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Changing-the-Certificate-presented-during-Endpoint-Security/m-p/80906#M10802</guid>
      <dc:creator>Norbert_Bohusch</dc:creator>
      <dc:date>2020-04-06T07:29:59Z</dc:date>
    </item>
    <item>
      <title>Re: Changing the Certificate presented during  Endpoint Security Client</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Changing-the-Certificate-presented-during-Endpoint-Security/m-p/80915#M10803</link>
      <description>Hi Norbet&lt;BR /&gt;This is something I have not done before, so please where can I get the CA to be imported? and where is it imported from?&lt;BR /&gt;Thanks&lt;BR /&gt;</description>
      <pubDate>Mon, 06 Apr 2020 08:22:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Changing-the-Certificate-presented-during-Endpoint-Security/m-p/80915#M10803</guid>
      <dc:creator>Di_Junior</dc:creator>
      <dc:date>2020-04-06T08:22:06Z</dc:date>
    </item>
    <item>
      <title>Re: Changing the Certificate presented during  Endpoint Security Client</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Changing-the-Certificate-presented-during-Endpoint-Security/m-p/80917#M10804</link>
      <description>This was already by Phoneboy above.&lt;BR /&gt;Just add an object called "Trusted CA" (and Intermediate if you have Sub CAs) and import the certificate of the CA.</description>
      <pubDate>Mon, 06 Apr 2020 08:26:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Changing-the-Certificate-presented-during-Endpoint-Security/m-p/80917#M10804</guid>
      <dc:creator>Norbert_Bohusch</dc:creator>
      <dc:date>2020-04-06T08:26:21Z</dc:date>
    </item>
    <item>
      <title>Re: Changing the Certificate presented during  Endpoint Security Client</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Changing-the-Certificate-presented-during-Endpoint-Security/m-p/80920#M10805</link>
      <description>Hi Norbet&lt;BR /&gt;&lt;BR /&gt;I saw it thanks.&lt;BR /&gt;One final question, once the certificate is signed by CA, users will no longer get that Certificate Error Message when configuring VPN site right?</description>
      <pubDate>Mon, 06 Apr 2020 08:59:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Changing-the-Certificate-presented-during-Endpoint-Security/m-p/80920#M10805</guid>
      <dc:creator>Di_Junior</dc:creator>
      <dc:date>2020-04-06T08:59:25Z</dc:date>
    </item>
    <item>
      <title>Re: Changing the Certificate presented during  Endpoint Security Client</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Changing-the-Certificate-presented-during-Endpoint-Security/m-p/80921#M10806</link>
      <description>Users who are trusting the relevant CA will not receive a warning...</description>
      <pubDate>Mon, 06 Apr 2020 09:03:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Changing-the-Certificate-presented-during-Endpoint-Security/m-p/80921#M10806</guid>
      <dc:creator>Norbert_Bohusch</dc:creator>
      <dc:date>2020-04-06T09:03:44Z</dc:date>
    </item>
    <item>
      <title>Re: Changing the Certificate presented during  Endpoint Security Client</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Changing-the-Certificate-presented-during-Endpoint-Security/m-p/80939#M10807</link>
      <description>Hi Phoneboy&lt;BR /&gt;Thanks for your feedback.&lt;BR /&gt;Just for knowledge purposes, I would like to know which other things uses this certificate.</description>
      <pubDate>Mon, 06 Apr 2020 10:56:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Changing-the-Certificate-presented-during-Endpoint-Security/m-p/80939#M10807</guid>
      <dc:creator>Di_Junior</dc:creator>
      <dc:date>2020-04-06T10:56:14Z</dc:date>
    </item>
    <item>
      <title>Re: Changing the Certificate presented during  Endpoint Security Client</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Changing-the-Certificate-presented-during-Endpoint-Security/m-p/80940#M10808</link>
      <description>If you only import for IPSEC VPN, it can only be used for VPN and Remote Access.</description>
      <pubDate>Mon, 06 Apr 2020 10:57:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Changing-the-Certificate-presented-during-Endpoint-Security/m-p/80940#M10808</guid>
      <dc:creator>Norbert_Bohusch</dc:creator>
      <dc:date>2020-04-06T10:57:36Z</dc:date>
    </item>
    <item>
      <title>Re: Changing the Certificate presented during  Endpoint Security Client</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Changing-the-Certificate-presented-during-Endpoint-Security/m-p/81313#M10809</link>
      <description>Hi Norbert&lt;BR /&gt;Thank you very much.&lt;BR /&gt;&lt;BR /&gt;It worked...</description>
      <pubDate>Wed, 08 Apr 2020 11:39:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Changing-the-Certificate-presented-during-Endpoint-Security/m-p/81313#M10809</guid>
      <dc:creator>Di_Junior</dc:creator>
      <dc:date>2020-04-08T11:39:27Z</dc:date>
    </item>
    <item>
      <title>Re: Changing the Certificate presented during  Endpoint Security Client</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Changing-the-Certificate-presented-during-Endpoint-Security/m-p/105662#M10810</link>
      <description>&lt;P&gt;if you have "mobile access" blade disabled, this setting is ignored, and it always uses the defaultCert from the internal CA...&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2020-12-16 190433.jpg" style="width: 761px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/9785i3946DDA989BBC645/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2020-12-16 190433.jpg" alt="Screenshot 2020-12-16 190433.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;no way to change the certificate for me... &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Dec 2020 18:20:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Changing-the-Certificate-presented-during-Endpoint-Security/m-p/105662#M10810</guid>
      <dc:creator>GHaider</dc:creator>
      <dc:date>2020-12-16T18:20:33Z</dc:date>
    </item>
    <item>
      <title>Re: Changing the Certificate presented during  Endpoint Security Client</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Changing-the-Certificate-presented-during-Endpoint-Security/m-p/105724#M10811</link>
      <description>&lt;P&gt;It might be that some other cert is used from another https portal.&lt;/P&gt;
&lt;P&gt;Enabling one portal, changing certificate there and disabling it, might help.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Dec 2020 08:47:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Changing-the-Certificate-presented-during-Endpoint-Security/m-p/105724#M10811</guid>
      <dc:creator>Norbert_Bohusch</dc:creator>
      <dc:date>2020-12-17T08:47:03Z</dc:date>
    </item>
    <item>
      <title>Re: Changing the Certificate presented during  Endpoint Security Client</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Changing-the-Certificate-presented-during-Endpoint-Security/m-p/197857#M10812</link>
      <description>&lt;P&gt;Hello Nobert!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I came to this forum last year and based on this discussion, I was able to gen a CSR and use a valid third-party certificate in my RA-VPN. Now I need renew my cert and form some reason, I'm getting an erro message that a similar cert is in use. I've tried different methods, but nothing seems to work.&lt;/P&gt;&lt;P&gt;I'm dropping a screenshot with the error for reference. Is there a way to gen a CSR without deleting the actual certificate?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Nov 2023 20:19:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Changing-the-Certificate-presented-during-Endpoint-Security/m-p/197857#M10812</guid>
      <dc:creator>brunoobr</dc:creator>
      <dc:date>2023-11-13T20:19:16Z</dc:date>
    </item>
    <item>
      <title>Re: Changing the Certificate presented during  Endpoint Security Client</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Changing-the-Certificate-presented-during-Endpoint-Security/m-p/197859#M10813</link>
      <description>&lt;P&gt;You have to delete it.&lt;/P&gt;
&lt;P&gt;Just don’t push policy until you complete the procedure.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Nov 2023 20:38:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Changing-the-Certificate-presented-during-Endpoint-Security/m-p/197859#M10813</guid>
      <dc:creator>Norbert_Bohusch</dc:creator>
      <dc:date>2023-11-13T20:38:47Z</dc:date>
    </item>
    <item>
      <title>Re: Changing the Certificate presented during  Endpoint Security Client</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Changing-the-Certificate-presented-during-Endpoint-Security/m-p/197860#M10814</link>
      <description>&lt;P&gt;Ok. Got it. Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 13 Nov 2023 20:40:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Changing-the-Certificate-presented-during-Endpoint-Security/m-p/197860#M10814</guid>
      <dc:creator>brunoobr</dc:creator>
      <dc:date>2023-11-13T20:40:37Z</dc:date>
    </item>
    <item>
      <title>Re: Changing the Certificate presented during  Endpoint Security Client</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Changing-the-Certificate-presented-during-Endpoint-Security/m-p/204890#M10815</link>
      <description>&lt;P&gt;Hi Norbert,&lt;/P&gt;&lt;P&gt;Thank you for the above information, this is all very helpful. Silly question time, for the users trusting the relevant subordinate CA and CA, I assume this trust is validated using the respective CA certificates stored in the local machines Trusted Root Certification Authorities and Intermediate Certification Authorities certificate repository?&lt;BR /&gt;&lt;BR /&gt;Then the remote client validates the certificate presented by the Gateway using this chain without prompting the user to trust the new/updated certificate?&lt;/P&gt;</description>
      <pubDate>Fri, 02 Feb 2024 14:20:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Changing-the-Certificate-presented-during-Endpoint-Security/m-p/204890#M10815</guid>
      <dc:creator>Leon_Noble</dc:creator>
      <dc:date>2024-02-02T14:20:56Z</dc:date>
    </item>
    <item>
      <title>Re: Changing the Certificate presented during  Endpoint Security Client</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Changing-the-Certificate-presented-during-Endpoint-Security/m-p/205533#M10816</link>
      <description>&lt;P&gt;That's correct to the best of my knowledge.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Feb 2024 23:19:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Changing-the-Certificate-presented-during-Endpoint-Security/m-p/205533#M10816</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-02-08T23:19:40Z</dc:date>
    </item>
  </channel>
</rss>

