<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Endpoint VPN with ext. CA - cannot complete certificate chain in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-VPN-with-ext-CA-cannot-complete-certificate-chain/m-p/56983#M12191</link>
    <description>Specifically when you import the root CA key, you need to include as part of the bundle all of the intermediate certificates that might be necessary.</description>
    <pubDate>Fri, 28 Jun 2019 19:14:15 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2019-06-28T19:14:15Z</dc:date>
    <item>
      <title>Endpoint VPN with ext. CA - cannot complete certificate chain</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-VPN-with-ext-CA-cannot-complete-certificate-chain/m-p/56959#M12188</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;endpoint-vpn with username/password is working well.&lt;/P&gt;&lt;P&gt;but with certificate from external ca it isnt working.&lt;/P&gt;&lt;P&gt;CA and SUBCA are setup as objects. ldap-accountunit is also setup.&lt;/P&gt;&lt;P&gt;i got the following error:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Time: 2019-06-28T12:52:51Z&lt;BR /&gt;Id: d977d512-0972-0000-5d16-0da300000000&lt;BR /&gt;Sequencenum: 2147483647&lt;BR /&gt;Category: Session&lt;BR /&gt;Event Type: Login&lt;BR /&gt;Name: Endpoint Security&lt;BR /&gt;Version: E81.00&lt;BR /&gt;Build Number: 986100516&lt;BR /&gt;User: yyy&lt;BR /&gt;Authentication Method: Certificate&lt;BR /&gt;User DN: CN=xxx,OU=Mitarbeiter,OU=Benutzer,OU=xxx,DC=intern,DC=xxx,DC=de&lt;BR /&gt;Certificate Fingerprint: 2f:79:67:2e:99:5b:95:68:83:8d:9c:c6:e3:ea:79:aa:8a:8d:30:69&lt;BR /&gt;Certificate Serial Number:74000004294ef08ececf626662000000000429&lt;BR /&gt;User Groups: ad_branch_Benutzer&lt;BR /&gt;Model: PC&lt;BR /&gt;OS Name: Windows&lt;BR /&gt;OS Version: 7&lt;BR /&gt;OS Edition: Professional&lt;BR /&gt;OS Service Pack: Service Pack 1&lt;BR /&gt;OS Build: 7601&lt;BR /&gt;OS Bits: 64bit&lt;BR /&gt;ID: C3DCD549-1354-4D35-A163-81495FDFDDF9&lt;BR /&gt;Re-authentication every:&lt;BR /&gt;Login Timestamp: 2019-06-28T12:52:51Z&lt;BR /&gt;Source Country: Germany&lt;BR /&gt;Source: ip&lt;BR /&gt;IP: ip&lt;BR /&gt;IP Protocol: 6&lt;BR /&gt;Destination Port: 443&lt;BR /&gt;Data Protocol: IPSec&lt;BR /&gt;Status: Failure&lt;BR /&gt;Reason: cannot complete certificate chain CN=yyy,OU=Mitarbeiter,OU=Benutzer,OU=xxx,DC=intern,DC=xxx,DC=de&lt;BR /&gt;Suppressed Logs: 0&lt;BR /&gt;Action: Failed Log In&lt;BR /&gt;Type: Log&lt;BR /&gt;Blade: Mobile Access&lt;BR /&gt;Origin: fw01&lt;BR /&gt;Service: TCP/443&lt;BR /&gt;Product Family: Access&lt;BR /&gt;Marker: @A@@B@1561712292@C@6990655&lt;BR /&gt;Index Time: 2019-06-28T12:52:51Z&lt;BR /&gt;Lastupdatetime: 1561726371000&lt;BR /&gt;Lastupdateseqnum: 2147483647&lt;BR /&gt;MAC Address: a0:b3:cc:c2:6e:bc&lt;BR /&gt;Stored: true&lt;BR /&gt;Name: hostname&lt;BR /&gt;Source Machine Name: ag-401-1324&lt;BR /&gt;Data Encryption: AES-256 + SHA1 + Group 2&lt;BR /&gt;Severity: Informational&lt;BR /&gt;Rounded Sent Bytes: 0&lt;BR /&gt;Confidence Level: N/A&lt;BR /&gt;Rounded Bytes: 0&lt;BR /&gt;Rounded Received Bytes: 0&lt;BR /&gt;OS: Windows 7 Professional Service Pack 1 64bit (build 7601)&lt;BR /&gt;Login Option Factors: Certificate&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i think gateway needs certificate from external CA, but i cant import a certificate. creating csr works, but i got error from ca.&lt;/P&gt;&lt;P&gt;can anyone help, howto create cert for gateway? or is it another problem?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks&amp;nbsp;&lt;/P&gt;&lt;P&gt;daniel&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jun 2019 13:12:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-VPN-with-ext-CA-cannot-complete-certificate-chain/m-p/56959#M12188</guid>
      <dc:creator>Daniel_Hainich</dc:creator>
      <dc:date>2019-06-28T13:12:01Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint VPN with ext. CA - cannot complete certificate chain</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-VPN-with-ext-CA-cannot-complete-certificate-chain/m-p/56968#M12189</link>
      <description>&lt;P&gt;Have you already imported your trusted ca on the management?&lt;/P&gt;&lt;P&gt;Once you have a certificate for the security gateway you need to specify wich certificat the vpn client need to use to authenticate in the vpn client gateway tab and then you need to move authentication to personal certificate , if you have a subca you need to import that too&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jun 2019 15:09:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-VPN-with-ext-CA-cannot-complete-certificate-chain/m-p/56968#M12189</guid>
      <dc:creator>Marco_Valenti</dc:creator>
      <dc:date>2019-06-28T15:09:50Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint VPN with ext. CA - cannot complete certificate chain</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-VPN-with-ext-CA-cannot-complete-certificate-chain/m-p/56977#M12190</link>
      <description>Hi, yes ca and subca are successfully Imported. I need Gateway certificate from subca with CSR. But I don't know how I finsh this CSR with Windows-CA.</description>
      <pubDate>Fri, 28 Jun 2019 17:53:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-VPN-with-ext-CA-cannot-complete-certificate-chain/m-p/56977#M12190</guid>
      <dc:creator>Daniel_Hainich</dc:creator>
      <dc:date>2019-06-28T17:53:58Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint VPN with ext. CA - cannot complete certificate chain</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-VPN-with-ext-CA-cannot-complete-certificate-chain/m-p/56983#M12191</link>
      <description>Specifically when you import the root CA key, you need to include as part of the bundle all of the intermediate certificates that might be necessary.</description>
      <pubDate>Fri, 28 Jun 2019 19:14:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-VPN-with-ext-CA-cannot-complete-certificate-chain/m-p/56983#M12191</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-06-28T19:14:15Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint VPN with ext. CA - cannot complete certificate chain</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-VPN-with-ext-CA-cannot-complete-certificate-chain/m-p/56987#M12192</link>
      <description>I have added root-ca and sub-ca as 2 objects in mgmt. Do I have to bundle root and sub cert to add root-ca?</description>
      <pubDate>Fri, 28 Jun 2019 19:32:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-VPN-with-ext-CA-cannot-complete-certificate-chain/m-p/56987#M12192</guid>
      <dc:creator>Daniel_Hainich</dc:creator>
      <dc:date>2019-06-28T19:32:00Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint VPN with ext. CA - cannot complete certificate chain</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-VPN-with-ext-CA-cannot-complete-certificate-chain/m-p/56990#M12193</link>
      <description>Both the root and sub-ca need to be bundled and imported as a single object.</description>
      <pubDate>Fri, 28 Jun 2019 21:07:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-VPN-with-ext-CA-cannot-complete-certificate-chain/m-p/56990#M12193</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-06-28T21:07:32Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint VPN with ext. CA - cannot complete certificate chain</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-VPN-with-ext-CA-cannot-complete-certificate-chain/m-p/57063#M12194</link>
      <description>i have delete root-ca and sub-ca to create a new one.&lt;BR /&gt;but now i got error:&lt;BR /&gt;&lt;BR /&gt;Error: Certificate with the same Distinguished Name already installed for another CA.&lt;BR /&gt;&lt;BR /&gt;how i can delete the certificate?&lt;BR /&gt;&lt;BR /&gt;Management is on R80.20 Take 47&lt;BR /&gt;&lt;BR /&gt;thanks&lt;BR /&gt;daniel</description>
      <pubDate>Mon, 01 Jul 2019 06:27:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-VPN-with-ext-CA-cannot-complete-certificate-chain/m-p/57063#M12194</guid>
      <dc:creator>Daniel_Hainich</dc:creator>
      <dc:date>2019-07-01T06:27:16Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint VPN with ext. CA - cannot complete certificate chain</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-VPN-with-ext-CA-cannot-complete-certificate-chain/m-p/57192#M12195</link>
      <description>&lt;P&gt;i have delete the root-ca and sub-ca, but i did not find the certificates within guidbedit.&lt;/P&gt;&lt;P&gt;i solved the problem with an reboot of the sms.&lt;/P&gt;&lt;P&gt;now all "old" certificates are gone and i recreate root-ca with bundled p7b certificate.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jul 2019 05:57:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-VPN-with-ext-CA-cannot-complete-certificate-chain/m-p/57192#M12195</guid>
      <dc:creator>Daniel_Hainich</dc:creator>
      <dc:date>2019-07-02T05:57:24Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint VPN with ext. CA - cannot complete certificate chain</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-VPN-with-ext-CA-cannot-complete-certificate-chain/m-p/97231#M12196</link>
      <description>&lt;P&gt;Reboot just fixed the issue for me.&lt;BR /&gt;I recreated it in a Lab so thought I would add this note for future readers.&lt;/P&gt;&lt;P&gt;My error was caused by adding Trusted and Sub CA's but discarding them before publishing. So...&lt;BR /&gt;&lt;BR /&gt;DO NOT ‘Discard Changes’ in SmartConsole until Certs, Trusted and Subordinate CA’s are deleted in the correct order sub/intermediate/root (which you are forced to do anyway), or you will not be able to add the same CA’s until the manager is rebooted.&lt;/P&gt;&lt;P&gt;i.e. Delete VPN certs. Then Delete Sub. Then Intermediate. Then Root. Then discard changes.&lt;/P&gt;&lt;P&gt;Or publish the changes, then delete certs and CA's etc, and publish again.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Sep 2020 02:15:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-VPN-with-ext-CA-cannot-complete-certificate-chain/m-p/97231#M12196</guid>
      <dc:creator>spottex</dc:creator>
      <dc:date>2020-09-22T02:15:43Z</dc:date>
    </item>
  </channel>
</rss>

