<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Changing Checkpoint Mobile Desktop Client wildcard Hostname in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Changing-Checkpoint-Mobile-Desktop-Client-wildcard-Hostname/m-p/34826#M13130</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Understood.&lt;/P&gt;&lt;P&gt;I'm guessing this is expected behavior but will ask the experts to confirm &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 15 Oct 2018 17:22:28 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2018-10-15T17:22:28Z</dc:date>
    <item>
      <title>Changing Checkpoint Mobile Desktop Client wildcard Hostname</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Changing-Checkpoint-Mobile-Desktop-Client-wildcard-Hostname/m-p/34821#M13125</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We use a wildcard for our mobile blade platform portal, which is also used for the desktop client. The platform portal is working correctly and has the correct hostname selected.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The desktop client gets a certificate error, saying the site is presenting itself as the wildcard instead of the proper hostname&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"The site presents itself as *.domain.xxx and not as mobile.domain.xxx"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How do I get this hostname to match up?&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Oct 2018 11:55:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Changing-Checkpoint-Mobile-Desktop-Client-wildcard-Hostname/m-p/34821#M13125</guid>
      <dc:creator>NorthernNetGuy</dc:creator>
      <dc:date>2018-10-12T11:55:57Z</dc:date>
    </item>
    <item>
      <title>Re: Changing Checkpoint Mobile Desktop Client wildcard Hostname</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Changing-Checkpoint-Mobile-Desktop-Client-wildcard-Hostname/m-p/34822#M13126</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is it a certificate error or?&lt;/P&gt;&lt;P&gt;A screenshot (with information obscured if needed) would be helpful.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 13 Oct 2018 09:03:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Changing-Checkpoint-Mobile-Desktop-Client-wildcard-Hostname/m-p/34822#M13126</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-10-13T09:03:17Z</dc:date>
    </item>
    <item>
      <title>Re: Changing Checkpoint Mobile Desktop Client wildcard Hostname</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Changing-Checkpoint-Mobile-Desktop-Client-wildcard-Hostname/m-p/34823#M13127</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here is what displays. I opened a ticket with support, who said&amp;nbsp; this is expected and that wildcards can work if you trust them manually&amp;nbsp;for each first connection, but the Mobile client doesn't fully support wildcards in this format.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/71440_pastedImage_1.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-2 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/71441_pastedImage_2.png" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 15 Oct 2018 14:37:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Changing-Checkpoint-Mobile-Desktop-Client-wildcard-Hostname/m-p/34823#M13127</guid>
      <dc:creator>NorthernNetGuy</dc:creator>
      <dc:date>2018-10-15T14:37:04Z</dc:date>
    </item>
    <item>
      <title>Re: Changing Checkpoint Mobile Desktop Client wildcard Hostname</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Changing-Checkpoint-Mobile-Desktop-Client-wildcard-Hostname/m-p/34824#M13128</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So are you saying the Mobile client never trusts it, even if you manually accept it the first time?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 15 Oct 2018 16:37:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Changing-Checkpoint-Mobile-Desktop-Client-wildcard-Hostname/m-p/34824#M13128</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-10-15T16:37:43Z</dc:date>
    </item>
    <item>
      <title>Re: Changing Checkpoint Mobile Desktop Client wildcard Hostname</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Changing-Checkpoint-Mobile-Desktop-Client-wildcard-Hostname/m-p/34825#M13129</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It does trust it after we manually accept it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ideally the endpoint client would recognize the wildcard and apply it to the expected hostname.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Seeing an error like this causes concern for many of our users, which bogs down our helpdesk with calls even if we try to inform our users that it is okay to trust and continue.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 15 Oct 2018 16:53:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Changing-Checkpoint-Mobile-Desktop-Client-wildcard-Hostname/m-p/34825#M13129</guid>
      <dc:creator>NorthernNetGuy</dc:creator>
      <dc:date>2018-10-15T16:53:57Z</dc:date>
    </item>
    <item>
      <title>Re: Changing Checkpoint Mobile Desktop Client wildcard Hostname</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Changing-Checkpoint-Mobile-Desktop-Client-wildcard-Hostname/m-p/34826#M13130</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Understood.&lt;/P&gt;&lt;P&gt;I'm guessing this is expected behavior but will ask the experts to confirm &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 15 Oct 2018 17:22:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Changing-Checkpoint-Mobile-Desktop-Client-wildcard-Hostname/m-p/34826#M13130</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-10-15T17:22:28Z</dc:date>
    </item>
    <item>
      <title>Re: Changing Checkpoint Mobile Desktop Client wildcard Hostname</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Changing-Checkpoint-Mobile-Desktop-Client-wildcard-Hostname/m-p/34827#M13131</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;According to the TAC rep I had it is expected behaviour, but an RFE has been created to have the mobile client better support wildcards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 15 Oct 2018 17:42:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Changing-Checkpoint-Mobile-Desktop-Client-wildcard-Hostname/m-p/34827#M13131</guid>
      <dc:creator>NorthernNetGuy</dc:creator>
      <dc:date>2018-10-15T17:42:06Z</dc:date>
    </item>
    <item>
      <title>Re: Changing Checkpoint Mobile Desktop Client wildcard Hostname</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Changing-Checkpoint-Mobile-Desktop-Client-wildcard-Hostname/m-p/34828#M13132</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is the site's FDQN specified as part of the SAN of the certificate?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Oct 2018 23:02:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Changing-Checkpoint-Mobile-Desktop-Client-wildcard-Hostname/m-p/34828#M13132</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-10-26T23:02:38Z</dc:date>
    </item>
    <item>
      <title>Re: Changing Checkpoint Mobile Desktop Client wildcard Hostname</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Changing-Checkpoint-Mobile-Desktop-Client-wildcard-Hostname/m-p/34829#M13133</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;No, as this is a wildcard cert and not a SAN cert.&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;Wildcard certs will just contain *.domain.com and domain.com as the SANs. You never see it contain further subdomains.&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;You'll sometimes see a Wildcard SAN cert that contains multiple domains such as *.domain.com , *.domain2.com, and, but again, no subdomains. (yahoo cert is a good example)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Oct 2018 13:12:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Changing-Checkpoint-Mobile-Desktop-Client-wildcard-Hostname/m-p/34829#M13133</guid>
      <dc:creator>NorthernNetGuy</dc:creator>
      <dc:date>2018-10-29T13:12:29Z</dc:date>
    </item>
    <item>
      <title>Re: Changing Checkpoint Mobile Desktop Client wildcard Hostname</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Changing-Checkpoint-Mobile-Desktop-Client-wildcard-Hostname/m-p/34830#M13134</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;My firm has a wildcard cert with Digicert, and we can request free duplicates with up to 10 SANS per duplicate, the SANs can be individually specified FQDNs of subdomain hosts, i.e. the (obfuscated) wildcard cert is :&lt;/P&gt;&lt;P&gt;*.contoso.com&lt;/P&gt;&lt;P&gt;matches&lt;/P&gt;&lt;P&gt;&amp;lt;AnyHostname&amp;gt;.contoso.com&lt;/P&gt;&lt;P&gt;contoso.com&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But you can specify up to 10 SANs on a given duplicate which could cover:&lt;/P&gt;&lt;P&gt;ethernetswitch1.corp.contoso.com&lt;/P&gt;&lt;P&gt;mail01.corp.contoso.com&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;etc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It works beautifully for us, allowing all our internal device management and printer web management etc etc to work without certificate errors, and it saved us a TON of money.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Oct 2018 13:55:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Changing-Checkpoint-Mobile-Desktop-Client-wildcard-Hostname/m-p/34830#M13134</guid>
      <dc:creator>Chris_Butler</dc:creator>
      <dc:date>2018-10-29T13:55:05Z</dc:date>
    </item>
    <item>
      <title>Re: Changing Checkpoint Mobile Desktop Client wildcard Hostname</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Changing-Checkpoint-Mobile-Desktop-Client-wildcard-Hostname/m-p/34831#M13135</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'll see if I can add a SAN that is covered by the wildcard onto the wildcard, but this still seems to be a problem with the Mobile Client.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;*.domain.com should match with &amp;lt;anyhostname&amp;gt;.domain.com. However the Checkpoint Mobile Client errors when it sees this, and does not recognize a match.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Oct 2018 14:01:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Changing-Checkpoint-Mobile-Desktop-Client-wildcard-Hostname/m-p/34831#M13135</guid>
      <dc:creator>NorthernNetGuy</dc:creator>
      <dc:date>2018-10-29T14:01:16Z</dc:date>
    </item>
    <item>
      <title>Re: Changing Checkpoint Mobile Desktop Client wildcard Hostname</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Changing-Checkpoint-Mobile-Desktop-Client-wildcard-Hostname/m-p/34832#M13136</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi David,&lt;/P&gt;&lt;P&gt;I have gotten it to work, and I will have a write-up posted on another thread here which shows the most direct and efficient way to do it as far as I have found.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TAC pointed me toward this SK.&lt;/P&gt;&lt;P&gt;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk69660&amp;amp;partition=Advanced&amp;amp;product=Mobile" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk69660&amp;amp;partition=Advanced&amp;amp;product=Mobile"&gt;How to generate Server Certificate Signing Request (CSR) and import the new 3rd Party certificate to Mobile Access Blade&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There are two command line examples there in stage one, they are not two steps. That bit me because I did the steps without reading ahead. You want to use the second example, as nobody is supporting 1024bit signing anymore&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;====================================&lt;BR /&gt; To Generate the 2048 bit CSR please use below command:&lt;BR /&gt; &lt;SPAN style="font-weight: bold;"&gt;[Expert@GW]# cpopenssl req -new -newkey rsa:2048 -out &amp;lt;CERT.CSR&amp;gt; -keyout &amp;lt;KEYFILE.KEY&amp;gt; -config $CPDIR/conf/openssl.cnf&lt;BR /&gt; &lt;/SPAN&gt;====================================&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Bottom line, when you use the cpopenssl command to generate the CSR and the KEY files, it will prompt you for a few attributes; put the FQDN of the host in as the CN when it asks you for it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When you go to your CA they usually have a field where you can add SANs when you request a duplicate, put that FQDN hostname in as one of them, and that is half&amp;nbsp; the battle.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My write up will cover the whole generation and import process, stay tuned.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Note, there is a significant delay after importing the finished cert, publishing the changes, and installing the policy.&lt;/P&gt;&lt;P&gt;I am not sure if the gateway waits for a window before the new cert becomes internet facing, but in my case it was more than 10 minutes. I did not restart any services to get it to happen, either.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Nov 2018 15:09:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Changing-Checkpoint-Mobile-Desktop-Client-wildcard-Hostname/m-p/34832#M13136</guid>
      <dc:creator>Chris_Butler</dc:creator>
      <dc:date>2018-11-08T15:09:36Z</dc:date>
    </item>
  </channel>
</rss>

