<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: The site's security certificate is not trusted! in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/The-site-s-security-certificate-is-not-trusted/m-p/11271#M13030</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Add the certificate as trusted to user computers?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 31 Oct 2018 10:00:37 GMT</pubDate>
    <dc:creator>AlekseiShelepov</dc:creator>
    <dc:date>2018-10-31T10:00:37Z</dc:date>
    <item>
      <title>The site's security certificate is not trusted!</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/The-site-s-security-certificate-is-not-trusted/m-p/11270#M13029</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello mates,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there any way how to get rid of below error message if user is trying to create new VPN site using SecuRemote VPN client ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/72966_pastedImage_2.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Some users within my company are complaining about it and we would like to simply solve it, if possible.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 31 Oct 2018 09:35:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/The-site-s-security-certificate-is-not-trusted/m-p/11270#M13029</guid>
      <dc:creator>JozkoMrkvicka</dc:creator>
      <dc:date>2018-10-31T09:35:20Z</dc:date>
    </item>
    <item>
      <title>Re: The site's security certificate is not trusted!</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/The-site-s-security-certificate-is-not-trusted/m-p/11271#M13030</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Add the certificate as trusted to user computers?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 31 Oct 2018 10:00:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/The-site-s-security-certificate-is-not-trusted/m-p/11271#M13030</guid>
      <dc:creator>AlekseiShelepov</dc:creator>
      <dc:date>2018-10-31T10:00:37Z</dc:date>
    </item>
    <item>
      <title>Re: The site's security certificate is not trusted!</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/The-site-s-security-certificate-is-not-trusted/m-p/11272#M13031</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you want to avoid seeing this alert, either distribute and install the self-signed certificate from your gateway or cluster to the users' PCs or define an A record in your external DNS for your gateway's public IP, buy the certificate issued by public CA and import it in your Gateway's or cluster's properties:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;This is what I had to do, (the text between &amp;lt;&amp;lt; and &amp;gt;&amp;gt; is my comments). The gw8010.mycompany.com&amp;lt;&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://gw8010.mycompany.com" rel="nofollow"&gt;http://gw8010.mycompany.com&lt;/A&gt;&lt;SPAN&gt;&amp;gt; is my gateway, the “gw8010csrfile” and “gw8010privatekeyfile” and other references to particular file and certificate names, should be replaced with your own values:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;lt;&amp;lt;&lt;BR /&gt;Original, from documentation: cpopenssl req -new -out &amp;lt;CSR file&amp;gt; -keyout &amp;lt;private key file&amp;gt; -config $CPDIR/conf/openssl.cnf&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;actual required: cpopenssl req -new -newkey rsa:2048 -out gw8010csrfile -keyout gw8010privatekeyfile -config $CPDIR/conf/openssl.cnf&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&amp;gt;&amp;gt;&lt;/P&gt;&lt;P&gt;[Expert@GW8010:0]# cpopenssl req -new -newkey rsa:2048 -out gw8010csrfile -keyout gw8010privatekeyfile -config $CPDIR/conf/openssl.cnf Generating a 2048 bit RSA private key ......++++++++++++ .........++++++++++++ writing new private key to 'gw8010privatekeyfile'&lt;BR /&gt;Enter PEM pass phrase:&lt;BR /&gt;Verifying - Enter PEM pass phrase:&lt;BR /&gt;-----&lt;BR /&gt;You are about to be asked to enter information that will be incorporated into your certificate request.&lt;BR /&gt;What you are about to enter is what is called a Distinguished Name or a DN.&lt;BR /&gt;There are quite a few fields but you can leave some blank For some fields there will be a default value, If you enter '.', the field will be left blank.&lt;BR /&gt;-----&lt;BR /&gt;Country Name (2 letter code) [AU]:US&lt;BR /&gt;&lt;SPAN&gt;State or Province Name (full name) [Some-State]:New Jersey Locality Name (eg, city) []:Wayne Organization Name (eg, company) [Internet Widgits Pty Ltd]:My Company Corp Organizational Unit Name (eg, section) []:IT Common Name (e.g. server FQDN or YOUR name) []:gw8010.mycompany.com&amp;lt;&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://gw8010.mycompany.com" rel="nofollow"&gt;http://gw8010.mycompany.com&lt;/A&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Email Address []:&lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:myemail@mycompany.com"&gt;myemail@mycompany.com&lt;/A&gt;&lt;SPAN&gt;&amp;lt;mailto:&lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:myemail@mycompany.com"&gt;myemail@mycompany.com&lt;/A&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Please enter the following 'extra' attributes to be sent with your certificate request A challenge password []:&lt;BR /&gt;An optional company name []:Higher Intelligence [Expert@GW8010:0]#&lt;/P&gt;&lt;P&gt;[Expert@GW8010:0]# ls&lt;BR /&gt;GW8010_config gw8010csrfile senderid_blue&lt;BR /&gt;expert gw8010privatekeyfile senderid_white&lt;BR /&gt;fw last_dump.log sessiond.elg&lt;BR /&gt;[Expert@GW8010:0]#&lt;/P&gt;&lt;P&gt;[Expert@GW8010:0]# chsh -s /bin/bash&lt;BR /&gt;Changing shell for admin.&lt;BR /&gt;Shell changed.&lt;BR /&gt;[Expert@GW8010:0]#&lt;/P&gt;&lt;P&gt;&amp;lt;&amp;lt;&lt;BR /&gt;Get the gw8010csrfile and gw8010privatekeyfile from the gateway to your PC using WinSCP Open gw8010csrfile in Notepad++ on windows or any editor on Mac and copy its content into clipboard In your CA's portal, paste the 2048 bit CSR into provided form and create a certificate Download the Certificate (works in TomCat format), with certificate chain included. It will typically be a .zip file containing .pem and two .crt files. The weirdly named file is, if you are using GoDaddy, the one assigned to your gateway/cluster.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;cpopenssl pkcs12 -export -out &amp;lt;output file&amp;gt; -in &amp;lt;signed cert chain file&amp;gt; -inkey &amp;lt;private key file&amp;gt;&lt;BR /&gt;Example: cpopenssl pkcs12 -export -out gw8010.p12 -in e5472599cd25bd68.crt -inkey gw8010privatekeyfile&lt;BR /&gt;&amp;gt;&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;[Expert@GW8010:0]# cpopenssl pkcs12 -export -out gw8010.p12 -in e5472599cd25bd68.crt -inkey gw8010privatekeyfile Enter pass phrase for gw8010privatekeyfile:&lt;BR /&gt;Enter Export Password:&lt;BR /&gt;Verifying - Enter Export Password:&lt;BR /&gt;[Expert@GW8010:0]# ls&lt;BR /&gt;GW8010_config gdig2.crt.pem gw8010privatekeyfile.old&lt;BR /&gt;e5472599cd25bd68.crt gw8010.p12 last_dump.log&lt;BR /&gt;expert gw8010csrfile senderid_blue&lt;BR /&gt;fw gw8010csrfile.old senderid_white&lt;BR /&gt;gd_bundle-g2-g1.crt gw8010privatekeyfile sessiond.elg&lt;BR /&gt;[Expert@GW8010:0]#&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&amp;lt;&amp;lt;&lt;BR /&gt;Copy gw8010.p12 back to your PC using WinSCP&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Create Alias for your gateway/cluster to include its FQDN (in this case gw8010.mycompany.com&amp;lt;&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://gw8010.mycompany.com" rel="nofollow"&gt;http://gw8010.mycompany.com&lt;/A&gt;&lt;SPAN&gt;&amp;gt;)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Import gw8010.p12 certificate in these sections of your gateway's or cluster's properties:&lt;/P&gt;&lt;P&gt;Mobile Access &amp;gt; Portal Settings&lt;BR /&gt;Platform Portal&lt;BR /&gt;Data Loss Prevention&lt;BR /&gt;Identity Awareness &amp;gt; Captive Portal &amp;gt; Settings &amp;gt; Access Settings In the Certificate section, click Import or Replace.&lt;BR /&gt;&amp;gt;&amp;gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 31 Oct 2018 13:23:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/The-site-s-security-certificate-is-not-trusted/m-p/11272#M13031</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2018-10-31T13:23:37Z</dc:date>
    </item>
  </channel>
</rss>

