<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Public SSL Certificate Domain Validation options in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Public-SSL-Certificate-Domain-Validation-options/m-p/281603#M14631</link>
    <description>&lt;P&gt;Okay, had some clarifications with a former CP PSE and got some more insights on the VPN stuff.&lt;BR /&gt;We don't need to have the SAN elements on the certificates, hence, my requirement is obsolete.&lt;/P&gt;</description>
    <pubDate>Fri, 28 Aug 2026 08:42:58 GMT</pubDate>
    <dc:creator>dunkelmorten</dc:creator>
    <dc:date>2026-08-28T08:42:58Z</dc:date>
    <item>
      <title>Public SSL Certificate Domain Validation options</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Public-SSL-Certificate-Domain-Validation-options/m-p/281429#M14622</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;a customer of mine is running Remote Access using MEP VPN with site configuration having gateways defined by ip addressed insteaf of FQDNs using MFA with a third party provider solution hosted internally. As of now the GW certificates are self-signed by CP ICA and have been added to customer devices trust stores.&lt;/P&gt;&lt;P&gt;We are currently planning to switch to SAML/IdP integration using public certificates. Initially, in order not to change too many things at once, we don't want to change site configuration, but only do the SAML/IdP stuff and the public certificates. By this, the CSRs for the public certificates have been created as SAN with VIP FQDN, Node FQDN and their ip addresses as well.&lt;/P&gt;&lt;P&gt;However, public PKI provider (GlobalSign) requires domain validation (as per security defaults) which is working for the FQDNs within the CSR but not for the ip addresses. These would need to be checked by looking up a file on the CP web server under the path https://%GW-IP%/.well-known/pki-validation/gsdv.txt&lt;/P&gt;&lt;P&gt;Does anybody know if there is an option to create this file and knows in which path this needs to be located at enabling for domain validation of ip addresses provided in a SAN certificate?&lt;/P&gt;&lt;P&gt;I was trying with no luck to create at "/opt/CPshrd-R81.20/conf/multiportal/httpd-conf/" where "UserCheck" and "saml-vpn" folders are found with sub-folders ".well-known/pki-validation" and adding the required text file "gsdv.txt". Additionally, changed folder and file permission to 644, but the file could not be looked up externally, neither when addressing it my browser.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;BR,&lt;/P&gt;&lt;P&gt;Morten&lt;/P&gt;</description>
      <pubDate>Mon, 24 Aug 2026 12:40:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Public-SSL-Certificate-Domain-Validation-options/m-p/281429#M14622</guid>
      <dc:creator>dunkelmorten</dc:creator>
      <dc:date>2026-08-24T12:40:57Z</dc:date>
    </item>
    <item>
      <title>Re: Public SSL Certificate Domain Validation options</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Public-SSL-Certificate-Domain-Validation-options/m-p/281495#M14627</link>
      <description>&lt;P&gt;There are several web servers on a Check Point gateway, but there's one that rules them all: multiportal.&lt;BR /&gt;While I'm not clear on the specifics, perhaps there will be some clues in&amp;nbsp;$FWDIR/conf/multiportal&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Aug 2026 16:26:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Public-SSL-Certificate-Domain-Validation-options/m-p/281495#M14627</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2026-08-25T16:26:15Z</dc:date>
    </item>
    <item>
      <title>Re: Public SSL Certificate Domain Validation options</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Public-SSL-Certificate-Domain-Validation-options/m-p/281517#M14628</link>
      <description>&lt;P&gt;That was I my assumption as well, but with no luck.&lt;BR /&gt;I was trying &lt;SPAN&gt;"/opt/CPshrd-R81.20/conf/multiportal/httpd-conf/" as there are the sub-folders for "UserCheck" and "saml-vpn" located used for each of the portals. I was assuming that the path is sort of root directory for the multiportal instances, but only for those being enabled.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Looks like I would need to have an additional / manually created portal within multiportal enabling for domain validation checks, but I am not sure how to get this done or if there is an option at all for this.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;As of now, it looks like I cannot use a SAN certificate for VPN having ip addresses covered, but need to get remote access VPN changed to use FQDN within site configuration instead of ip addresses due to missing domain validation options by this text file on a web server on CP GW.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Aug 2026 06:16:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Public-SSL-Certificate-Domain-Validation-options/m-p/281517#M14628</guid>
      <dc:creator>dunkelmorten</dc:creator>
      <dc:date>2026-08-26T06:16:30Z</dc:date>
    </item>
    <item>
      <title>Re: Public SSL Certificate Domain Validation options</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Public-SSL-Certificate-Domain-Validation-options/m-p/281603#M14631</link>
      <description>&lt;P&gt;Okay, had some clarifications with a former CP PSE and got some more insights on the VPN stuff.&lt;BR /&gt;We don't need to have the SAN elements on the certificates, hence, my requirement is obsolete.&lt;/P&gt;</description>
      <pubDate>Fri, 28 Aug 2026 08:42:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Public-SSL-Certificate-Domain-Validation-options/m-p/281603#M14631</guid>
      <dc:creator>dunkelmorten</dc:creator>
      <dc:date>2026-08-28T08:42:58Z</dc:date>
    </item>
  </channel>
</rss>

