<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Public SSL Certificate Domain Validation options in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Public-SSL-Certificate-Domain-Validation-options/m-p/281429#M14622</link>
    <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;a customer of mine is running Remote Access using MEP VPN with site configuration having gateways defined by ip addressed insteaf of FQDNs using MFA with a third party provider solution hosted internally. As of now the GW certificates are self-signed by CP ICA and have been added to customer devices trust stores.&lt;/P&gt;&lt;P&gt;We are currently planning to switch to SAML/IdP integration using public certificates. Initially, in order not to change too many things at once, we don't want to change site configuration, but only do the SAML/IdP stuff and the public certificates. By this, the CSRs for the public certificates have been created as SAN with VIP FQDN, Node FQDN and their ip addresses as well.&lt;/P&gt;&lt;P&gt;However, public PKI provider (GlobalSign) requires domain validation (as per security defaults) which is working for the FQDNs within the CSR but not for the ip addresses. These would need to be checked by looking up a file on the CP web server under the path https://%GW-IP%/.well-known/pki-validation/gsdv.txt&lt;/P&gt;&lt;P&gt;Does anybody know if there is an option to create this file and knows in which path this needs to be located at enabling for domain validation of ip addresses provided in a SAN certificate?&lt;/P&gt;&lt;P&gt;I was trying with no luck to create at "/opt/CPshrd-R81.20/conf/multiportal/httpd-conf/" where "UserCheck" and "saml-vpn" folders are found with sub-folders ".well-known/pki-validation" and adding the required text file "gsdv.txt". Additionally, changed folder and file permission to 644, but the file could not be looked up externally, neither when addressing it my browser.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;BR,&lt;/P&gt;&lt;P&gt;Morten&lt;/P&gt;</description>
    <pubDate>Mon, 24 Aug 2026 12:40:57 GMT</pubDate>
    <dc:creator>dunkelmorten</dc:creator>
    <dc:date>2026-08-24T12:40:57Z</dc:date>
    <item>
      <title>Public SSL Certificate Domain Validation options</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Public-SSL-Certificate-Domain-Validation-options/m-p/281429#M14622</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;a customer of mine is running Remote Access using MEP VPN with site configuration having gateways defined by ip addressed insteaf of FQDNs using MFA with a third party provider solution hosted internally. As of now the GW certificates are self-signed by CP ICA and have been added to customer devices trust stores.&lt;/P&gt;&lt;P&gt;We are currently planning to switch to SAML/IdP integration using public certificates. Initially, in order not to change too many things at once, we don't want to change site configuration, but only do the SAML/IdP stuff and the public certificates. By this, the CSRs for the public certificates have been created as SAN with VIP FQDN, Node FQDN and their ip addresses as well.&lt;/P&gt;&lt;P&gt;However, public PKI provider (GlobalSign) requires domain validation (as per security defaults) which is working for the FQDNs within the CSR but not for the ip addresses. These would need to be checked by looking up a file on the CP web server under the path https://%GW-IP%/.well-known/pki-validation/gsdv.txt&lt;/P&gt;&lt;P&gt;Does anybody know if there is an option to create this file and knows in which path this needs to be located at enabling for domain validation of ip addresses provided in a SAN certificate?&lt;/P&gt;&lt;P&gt;I was trying with no luck to create at "/opt/CPshrd-R81.20/conf/multiportal/httpd-conf/" where "UserCheck" and "saml-vpn" folders are found with sub-folders ".well-known/pki-validation" and adding the required text file "gsdv.txt". Additionally, changed folder and file permission to 644, but the file could not be looked up externally, neither when addressing it my browser.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;BR,&lt;/P&gt;&lt;P&gt;Morten&lt;/P&gt;</description>
      <pubDate>Mon, 24 Aug 2026 12:40:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Public-SSL-Certificate-Domain-Validation-options/m-p/281429#M14622</guid>
      <dc:creator>dunkelmorten</dc:creator>
      <dc:date>2026-08-24T12:40:57Z</dc:date>
    </item>
    <item>
      <title>Re: Public SSL Certificate Domain Validation options</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Public-SSL-Certificate-Domain-Validation-options/m-p/281495#M14627</link>
      <description>&lt;P&gt;There are several web servers on a Check Point gateway, but there's one that rules them all: multiportal.&lt;BR /&gt;While I'm not clear on the specifics, perhaps there will be some clues in&amp;nbsp;$FWDIR/conf/multiportal&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Aug 2026 16:26:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Public-SSL-Certificate-Domain-Validation-options/m-p/281495#M14627</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2026-08-25T16:26:15Z</dc:date>
    </item>
  </channel>
</rss>

