<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Query on using Registration Key to enroll remote access certificate in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Query-on-using-Registration-Key-to-enroll-remote-access/m-p/267341#M2376</link>
    <description>&lt;P&gt;Great job!&lt;/P&gt;</description>
    <pubDate>Wed, 14 Jan 2026 14:26:51 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2026-01-14T14:26:51Z</dc:date>
    <item>
      <title>Query on using Registration Key to enroll remote access certificate</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Query-on-using-Registration-Key-to-enroll-remote-access/m-p/242510#M2368</link>
      <description>&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;SPAN&gt;Hi Checkmates,&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;P&gt;&lt;BR /&gt;I am testing on using the registration key for Certificate Enrolment, so that I can distribute the VPN certificates to user using registration key.&lt;/P&gt;&lt;P&gt;However I got message that the enrolment failed.. But if I download the certificate manually then everything works fine.&lt;BR /&gt;&lt;BR /&gt;Am I missing out something to use registration key for enrolment? I have attached the images for reference, appreciate any advise on this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Thu, 27 Feb 2025 08:52:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Query-on-using-Registration-Key-to-enroll-remote-access/m-p/242510#M2368</guid>
      <dc:creator>PJ_WONG</dc:creator>
      <dc:date>2025-02-27T08:52:43Z</dc:date>
    </item>
    <item>
      <title>Re: Query on using Registration Key to enroll remote access certificate</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Query-on-using-Registration-Key-to-enroll-remote-access/m-p/242575#M2369</link>
      <description>&lt;P&gt;What version/JHF of gateway?&lt;BR /&gt;What client version?&lt;BR /&gt;Did you pull the client logs to see if there any clues there?&lt;/P&gt;</description>
      <pubDate>Thu, 27 Feb 2025 17:24:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Query-on-using-Registration-Key-to-enroll-remote-access/m-p/242575#M2369</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-02-27T17:24:00Z</dc:date>
    </item>
    <item>
      <title>Re: Query on using Registration Key to enroll remote access certificate</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Query-on-using-Registration-Key-to-enroll-remote-access/m-p/242619#M2370</link>
      <description>&lt;P&gt;Hi PhoneBoy,&lt;BR /&gt;&lt;BR /&gt;I am using R81.10 JHF 150 in my lab.&lt;/P&gt;&lt;P&gt;The client version is E88.50 Build 98105707&lt;/P&gt;&lt;P&gt;I can see this error in logs:&lt;/P&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;[TrGUI] EnrollCBFunc: callback called with error code -&lt;/SPAN&gt;&lt;SPAN&gt;4&lt;/SPAN&gt;&lt;SPAN&gt; , (Remote Access VPN could not establish connection with Internal CA. &lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Enter the server IP or server name and try again.&lt;BR /&gt;&lt;BR /&gt;The firewall policy is allow any traffic, and I can ping it, is additional settings needed?&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Thanks,&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;PJ&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Fri, 28 Feb 2025 02:47:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Query-on-using-Registration-Key-to-enroll-remote-access/m-p/242619#M2370</guid>
      <dc:creator>PJ_WONG</dc:creator>
      <dc:date>2025-02-28T02:47:51Z</dc:date>
    </item>
    <item>
      <title>Re: Query on using Registration Key to enroll remote access certificate</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Query-on-using-Registration-Key-to-enroll-remote-access/m-p/242620#M2371</link>
      <description>&lt;P&gt;Does it happen on every machine? Maybe try E88.62 client as a test. Though, based on those messages you sent, appears its communication to the gateway thats failing. Do you see any logs about this in smart console?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 28 Feb 2025 03:00:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Query-on-using-Registration-Key-to-enroll-remote-access/m-p/242620#M2371</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-02-28T03:00:40Z</dc:date>
    </item>
    <item>
      <title>Re: Query on using Registration Key to enroll remote access certificate</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Query-on-using-Registration-Key-to-enroll-remote-access/m-p/242623#M2372</link>
      <description>&lt;P&gt;Hi Andy,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Am able to connect with E88.62 client, appreciate your suggestion on this.&lt;BR /&gt;&lt;BR /&gt;Didn't suspect it is a version issue as the key enrolment should be a basic function..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;PJ&lt;/P&gt;</description>
      <pubDate>Fri, 28 Feb 2025 04:15:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Query-on-using-Registration-Key-to-enroll-remote-access/m-p/242623#M2372</guid>
      <dc:creator>PJ_WONG</dc:creator>
      <dc:date>2025-02-28T04:15:59Z</dc:date>
    </item>
    <item>
      <title>Re: Query on using Registration Key to enroll remote access certificate</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Query-on-using-Registration-Key-to-enroll-remote-access/m-p/242624#M2373</link>
      <description>&lt;P&gt;Glad we can help. Yea, always something to consider with endpoint clients, for sure.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 28 Feb 2025 04:19:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Query-on-using-Registration-Key-to-enroll-remote-access/m-p/242624#M2373</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-02-28T04:19:39Z</dc:date>
    </item>
    <item>
      <title>Re: Query on using Registration Key to enroll remote access certificate</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Query-on-using-Registration-Key-to-enroll-remote-access/m-p/242706#M2374</link>
      <description>&lt;P&gt;Key Enrollment has been there for quite some time.&lt;BR /&gt;Not sure what in E88.50 causes issues with it, but glad the latest version is working.&lt;/P&gt;</description>
      <pubDate>Fri, 28 Feb 2025 16:46:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Query-on-using-Registration-Key-to-enroll-remote-access/m-p/242706#M2374</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-02-28T16:46:19Z</dc:date>
    </item>
    <item>
      <title>Re: Query on using Registration Key to enroll remote access certificate</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Query-on-using-Registration-Key-to-enroll-remote-access/m-p/267340#M2375</link>
      <description>&lt;P&gt;I worked through this very problem only yesterday!&lt;BR /&gt;&lt;BR /&gt;It's a permission problem. Standard Windows Users (without Administrative permissions have this problem) - but there is an easy solution&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":grinning_face:"&gt;😀&lt;/span&gt;.&lt;BR /&gt;&lt;BR /&gt;When you do the Certificate Enrolment on the client machine, it actually tries to install &lt;EM&gt;two&lt;/EM&gt; certificates not one - but you have no visibility of this...&lt;BR /&gt;&lt;BR /&gt;The user's specific certificate with its private key can be enrolled into the the &lt;STRONG&gt;User's Personal Certificate Store&lt;/STRONG&gt; in Windows (with standard user permissions) without any problem, but the corresponding Issuing Certificate from your Firewall Manager also needs to be located in the&lt;STRONG&gt;&amp;nbsp;Trusted Root Certification Authorities Store &lt;/STRONG&gt;on your computer. The certificate enrolment process tries to install the certificate if it doesn't exist, but the process fails if you don't have Administrative permissions on the computer.&lt;BR /&gt;&lt;BR /&gt;The solution is to use Group Policy to pre-distribute the Issuing Certificate to the&amp;nbsp;&lt;STRONG&gt;Trusted Root Certification Authorities Store &lt;/STRONG&gt;on all the relevant computers in your domain (for example all your laptop computers):&lt;BR /&gt;&lt;BR /&gt;Required GPO settings:&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="GPO.jpg" style="width: 483px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/32718i432222C497312D0A/image-dimensions/483x189?v=v2" width="483" height="189" role="button" title="GPO.jpg" alt="GPO.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;When you create the GPO, you just need a copy of the required certificate (you can copy it from an already working computer in .cer format). The certificate becomes embedded as part of the GPO object.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;After the computers refresh Group Policy, they now have the required certificate located in&amp;nbsp;&lt;STRONG&gt;Trusted Root Certification Authorities Store.&amp;nbsp;&lt;/STRONG&gt;Because the valid certificate is now already located on the computer, when you perform certificate enrolment process, it will now work without error.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jan 2026 15:28:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Query-on-using-Registration-Key-to-enroll-remote-access/m-p/267340#M2375</guid>
      <dc:creator>ccsjnw</dc:creator>
      <dc:date>2026-01-14T15:28:56Z</dc:date>
    </item>
    <item>
      <title>Re: Query on using Registration Key to enroll remote access certificate</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Query-on-using-Registration-Key-to-enroll-remote-access/m-p/267341#M2376</link>
      <description>&lt;P&gt;Great job!&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jan 2026 14:26:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Query-on-using-Registration-Key-to-enroll-remote-access/m-p/267341#M2376</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2026-01-14T14:26:51Z</dc:date>
    </item>
  </channel>
</rss>

