<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Create CSR and Importing third party certificate in Mobile Access Blade in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Create-CSR-and-Importing-third-party-certificate-in-Mobile/m-p/39951#M13960</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi there, I would like to know the same thing. Did you perhaps managed to get it to work in cluster environment.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 28 Sep 2018 16:08:16 GMT</pubDate>
    <dc:creator>Di_Junior</dc:creator>
    <dc:date>2018-09-28T16:08:16Z</dc:date>
    <item>
      <title>Create CSR and Importing third party certificate in Mobile Access Blade</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Create-CSR-and-Importing-third-party-certificate-in-Mobile/m-p/39942#M13951</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;This is about Creating CSR and importing third party certificate to gateway for Mobile Access Blade. We have already &lt;STRONG&gt;SK69660&lt;/STRONG&gt; but adding snapshot for better idea.&lt;/P&gt;&lt;P&gt;First generate Request to generate certificate (CSR) with below command.&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: Courier New;"&gt;&lt;STRONG&gt;cpopenssl req -new -out &amp;lt;CERT.CSR&amp;gt; -keyout &amp;lt;KEYFILE.KEY&amp;gt; -config $CPDIR/conf/openssl.cnf&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;IMG __jive_id="63359" alt="" class="image-1 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/63359_Capture.JPG" style="width: 620px; height: 351px;" /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Then you can send this *.csr file to third party so that they can create certificate for you.&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="63360" alt="" class="image-2 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/63360_Capture1.JPG" style="height: auto;" /&gt;&lt;/P&gt;&lt;P&gt;Third party will give you combined certificate where 3 certificates (Primary SSL, Intermediate &amp;amp; Root) will resides or separate certificates. If you receive separate certificates then you need to combine all certificates in Text Editor as suggested in sk69660. Please make combined file in *.crt format.&lt;/P&gt;&lt;P&gt;Now the final stage is to&amp;nbsp;import certificate in Firewall but before that we need to convert this certificate ext from *.crt to&amp;nbsp;*.P12 You need to use below command for conversion.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;cpopenssl pkcs12 -export -out &amp;lt;New file name as P12&amp;gt; -in &amp;lt;Your combined certificate&amp;gt; -inkey &amp;lt;Private key which is generated during CSR&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="63361" alt="" class="image-3 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/63361_Capture2.JPG" style="height: auto;" /&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now this *.P12 file you need to import in Gateway --&amp;gt; Properties --&amp;gt; Mobile Access --&amp;gt; Portal Setting --&amp;gt; Import the file.&lt;/P&gt;&lt;P&gt;Save &amp;amp; Push policy.&lt;/P&gt;&lt;P&gt;Now when you connect sslvpn (&lt;A href="https://Gateway_IP/sslvpn"&gt;https://Gateway_IP/sslvpn&lt;/A&gt;), you will not get any certificate error and you can see certificate that is provided by third party.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Feb 2018 13:07:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Create-CSR-and-Importing-third-party-certificate-in-Mobile/m-p/39942#M13951</guid>
      <dc:creator>Gaurav_Pandya</dc:creator>
      <dc:date>2018-02-28T13:07:45Z</dc:date>
    </item>
    <item>
      <title>Re: Create CSR and Importing third party certificate in Mobile Access Blade</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Create-CSR-and-Importing-third-party-certificate-in-Mobile/m-p/39943#M13952</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am getting a pop up to key-in password, but I didn't set any password on .p12 file. Any idea please?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 May 2018 16:46:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Create-CSR-and-Importing-third-party-certificate-in-Mobile/m-p/39943#M13952</guid>
      <dc:creator>Zaw_Hein_Aung</dc:creator>
      <dc:date>2018-05-15T16:46:24Z</dc:date>
    </item>
    <item>
      <title>Re: Create CSR and Importing third party certificate in Mobile Access Blade</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Create-CSR-and-Importing-third-party-certificate-in-Mobile/m-p/39944#M13953</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have kept password. If you didn't set password then just keep it blank and enter, it fails then I think you can regenerate the .p12 and keep password.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 May 2018 15:39:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Create-CSR-and-Importing-third-party-certificate-in-Mobile/m-p/39944#M13953</guid>
      <dc:creator>Gaurav_Pandya</dc:creator>
      <dc:date>2018-05-16T15:39:01Z</dc:date>
    </item>
    <item>
      <title>Re: Create CSR and Importing third party certificate in Mobile Access Blade</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Create-CSR-and-Importing-third-party-certificate-in-Mobile/m-p/39945#M13954</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the reply, I had tried that too. Received the same "password is incorrect" error regardless the certificate is with or without password.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 May 2018 03:08:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Create-CSR-and-Importing-third-party-certificate-in-Mobile/m-p/39945#M13954</guid>
      <dc:creator>Zaw_Hein_Aung</dc:creator>
      <dc:date>2018-05-17T03:08:57Z</dc:date>
    </item>
    <item>
      <title>Re: Create CSR and Importing third party certificate in Mobile Access Blade</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Create-CSR-and-Importing-third-party-certificate-in-Mobile/m-p/39946#M13955</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hmm. Strange.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 May 2018 14:13:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Create-CSR-and-Importing-third-party-certificate-in-Mobile/m-p/39946#M13955</guid>
      <dc:creator>Gaurav_Pandya</dc:creator>
      <dc:date>2018-05-21T14:13:41Z</dc:date>
    </item>
    <item>
      <title>Re: Create CSR and Importing third party certificate in Mobile Access Blade</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Create-CSR-and-Importing-third-party-certificate-in-Mobile/m-p/39947#M13956</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I've managed to&amp;nbsp;make it work with a workaround. Export the .P12 cert using openssl on windows server and import to CP gateway.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CP tech support is still checking why the cert exported from security gateway is not working.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 May 2018 06:33:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Create-CSR-and-Importing-third-party-certificate-in-Mobile/m-p/39947#M13956</guid>
      <dc:creator>Zaw_Hein_Aung</dc:creator>
      <dc:date>2018-05-25T06:33:13Z</dc:date>
    </item>
    <item>
      <title>Re: Create CSR and Importing third party certificate in Mobile Access Blade</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Create-CSR-and-Importing-third-party-certificate-in-Mobile/m-p/39948#M13957</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok. Please let us know whatever the result is.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 May 2018 17:13:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Create-CSR-and-Importing-third-party-certificate-in-Mobile/m-p/39948#M13957</guid>
      <dc:creator>Gaurav_Pandya</dc:creator>
      <dc:date>2018-05-25T17:13:49Z</dc:date>
    </item>
    <item>
      <title>Re: Create CSR and Importing third party certificate in Mobile Access Blade</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Create-CSR-and-Importing-third-party-certificate-in-Mobile/m-p/39949#M13958</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I had a similar issue importing server certs for https inspection,&amp;nbsp; i&amp;nbsp; found that i needed to use the -passin and -passout options with openssl when creating the p12 or else the import always failed with incorrect password&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;openssl pkcs12 -export -out&amp;nbsp; website.p12 -inkey&amp;nbsp; website.key&amp;nbsp; -in website.pem&amp;nbsp; -certfile&amp;nbsp; ca-chain.pem -passin pass:privatekeypass&amp;nbsp; -passout pass:privatekeypass&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Jul 2018 17:09:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Create-CSR-and-Importing-third-party-certificate-in-Mobile/m-p/39949#M13958</guid>
      <dc:creator>Brian_Kirwan</dc:creator>
      <dc:date>2018-07-16T17:09:19Z</dc:date>
    </item>
    <item>
      <title>Re: Create CSR and Importing third party certificate in Mobile Access Blade</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Create-CSR-and-Importing-third-party-certificate-in-Mobile/m-p/39950#M13959</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is there any procedure on how to do it on cluster firewalls?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Aug 2018 02:44:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Create-CSR-and-Importing-third-party-certificate-in-Mobile/m-p/39950#M13959</guid>
      <dc:creator>Alsnator_C</dc:creator>
      <dc:date>2018-08-23T02:44:47Z</dc:date>
    </item>
    <item>
      <title>Re: Create CSR and Importing third party certificate in Mobile Access Blade</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Create-CSR-and-Importing-third-party-certificate-in-Mobile/m-p/39951#M13960</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi there, I would like to know the same thing. Did you perhaps managed to get it to work in cluster environment.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Sep 2018 16:08:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Create-CSR-and-Importing-third-party-certificate-in-Mobile/m-p/39951#M13960</guid>
      <dc:creator>Di_Junior</dc:creator>
      <dc:date>2018-09-28T16:08:16Z</dc:date>
    </item>
    <item>
      <title>Re: Create CSR and Importing third party certificate in Mobile Access Blade</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Create-CSR-and-Importing-third-party-certificate-in-Mobile/m-p/39952#M13961</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am about to do this in a clustered production environment and will try to remember to update this thread. Of note though is that when generating CSR, I had to include "-newkey rsa:2048" in the command:&lt;/P&gt;&lt;P&gt;"openssl req -new -newkey rsa:2048 -nodes -out gw8010.blablabla.com.rsa.csr -keyout gw8010.&lt;SPAN&gt;blablabla&lt;/SPAN&gt;.com.rsa.pkey -subj "/C=US/ST=New Jersey/L=Wayne/O=Higher Intelligence LLC/CN=gw8010.&lt;SPAN&gt;blablabla&lt;/SPAN&gt;.com"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Else the CA was complaining.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Oct 2018 19:08:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Create-CSR-and-Importing-third-party-certificate-in-Mobile/m-p/39952#M13961</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2018-10-19T19:08:25Z</dc:date>
    </item>
    <item>
      <title>Re: Create CSR and Importing third party certificate in Mobile Access Blade</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Create-CSR-and-Importing-third-party-certificate-in-Mobile/m-p/39953#M13962</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No problem with deployment in the clustered environment.&lt;/P&gt;&lt;P&gt;Just completed it today.&lt;/P&gt;&lt;P&gt;You perform CLI certificate operations on a single cluster member, but import resultant certificate in the SmartConsole in the Cluster Object's properties.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Oct 2018 19:07:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Create-CSR-and-Importing-third-party-certificate-in-Mobile/m-p/39953#M13962</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2018-10-24T19:07:50Z</dc:date>
    </item>
    <item>
      <title>Re: Create CSR and Importing third party certificate in Mobile Access Blade</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Create-CSR-and-Importing-third-party-certificate-in-Mobile/m-p/53507#M13963</link>
      <description>&lt;P&gt;I started this process last week, creating the CSR and requested the cert. Today when I was going to finish it, I realised that I should have noted the key-file which I used to sign the CSR request. Because I need to re-use that same key now to install the certificate, right?&lt;/P&gt;&lt;P&gt;Question is, what to do if I lost the pw to the .key file?&lt;/P&gt;</description>
      <pubDate>Wed, 15 May 2019 12:21:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Create-CSR-and-Importing-third-party-certificate-in-Mobile/m-p/53507#M13963</guid>
      <dc:creator>Ilmo_Anttonen</dc:creator>
      <dc:date>2019-05-15T12:21:22Z</dc:date>
    </item>
    <item>
      <title>Re: Create CSR and Importing third party certificate in Mobile Access Blade</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Create-CSR-and-Importing-third-party-certificate-in-Mobile/m-p/53521#M13964</link>
      <description>&lt;P&gt;The solution was to just create a new csr.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now I know I need to save the password for the inkey file.&lt;/P&gt;</description>
      <pubDate>Wed, 15 May 2019 14:13:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Create-CSR-and-Importing-third-party-certificate-in-Mobile/m-p/53521#M13964</guid>
      <dc:creator>Ilmo_Anttonen</dc:creator>
      <dc:date>2019-05-15T14:13:59Z</dc:date>
    </item>
    <item>
      <title>Re: Create CSR and Importing third party certificate in Mobile Access Blade</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Create-CSR-and-Importing-third-party-certificate-in-Mobile/m-p/140073#M13965</link>
      <description>&lt;P&gt;I recently encountered the same problem when importing a certificate - an error message about an incorrect password. I tried different options with openssl and a banal change in the extension of the certificate file from pfx to p12 helped me.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Feb 2022 10:19:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Create-CSR-and-Importing-third-party-certificate-in-Mobile/m-p/140073#M13965</guid>
      <dc:creator>AC1</dc:creator>
      <dc:date>2022-02-01T10:19:50Z</dc:date>
    </item>
    <item>
      <title>Re: Create CSR and Importing third party certificate in Mobile Access Blade</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Create-CSR-and-Importing-third-party-certificate-in-Mobile/m-p/191998#M13966</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I am using IPsec for remote access. How do i import the p12 certificate for that ?&lt;/P&gt;</description>
      <pubDate>Fri, 08 Sep 2023 07:31:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Create-CSR-and-Importing-third-party-certificate-in-Mobile/m-p/191998#M13966</guid>
      <dc:creator>shantilalSuthar</dc:creator>
      <dc:date>2023-09-08T07:31:35Z</dc:date>
    </item>
    <item>
      <title>Re: Create CSR and Importing third party certificate in Mobile Access Blade</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Create-CSR-and-Importing-third-party-certificate-in-Mobile/m-p/263800#M13967</link>
      <description>&lt;P&gt;hi folks quick one&lt;/P&gt;
&lt;P&gt;I'm seeking docs of cpopenssl pkcs12 -import but cannot find anything all over the web.&lt;/P&gt;
&lt;P&gt;I need to extract p12 on the shell of another gw but seems cpopenssl does not provide any syntax help on that.&lt;/P&gt;
&lt;P&gt;any ideas ?&lt;/P&gt;</description>
      <pubDate>Fri, 28 Nov 2025 09:20:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Create-CSR-and-Importing-third-party-certificate-in-Mobile/m-p/263800#M13967</guid>
      <dc:creator>Jerry</dc:creator>
      <dc:date>2025-11-28T09:20:16Z</dc:date>
    </item>
  </channel>
</rss>

