<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Adding certificate requirement on RAVPN for MAC's in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Adding-certificate-requirement-on-RAVPN-for-MAC-s/m-p/231251#M2931</link>
    <description>&lt;P&gt;Generally speaking, if you are doing certificate-based authentication against a specific certificate authority (CA), the device connecting would need to have a certificate from that specific CA in order to get authenticated.&lt;/P&gt;
&lt;P&gt;While I have not configured machine authentication on a Check Point, I would imagine the MAC in question would require a valid machine certificate from your Windows CA.&lt;/P&gt;
&lt;P&gt;How do you get one? You can try navigating to your CA and requesting one (&lt;A href="https://&amp;lt;YourWindowsCA&amp;gt;/certsrv/" target="_blank"&gt;https://&amp;lt;YourWindowsCA&amp;gt;/certsrv/&lt;/A&gt;), or this Apple article might still be valid (&lt;A href="https://support.apple.com/en-sg/101196" target="_blank"&gt;https://support.apple.com/en-sg/101196&lt;/A&gt;). Other material I see on this references using MDM to accomplish this task.&lt;/P&gt;</description>
    <pubDate>Wed, 30 Oct 2024 13:22:33 GMT</pubDate>
    <dc:creator>CaseyB</dc:creator>
    <dc:date>2024-10-30T13:22:33Z</dc:date>
    <item>
      <title>Adding certificate requirement on RAVPN for MAC's</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Adding-certificate-requirement-on-RAVPN-for-MAC-s/m-p/231249#M2930</link>
      <description>&lt;P&gt;Hey everyone. We recently rolled out certificate verification for Remote Access VPN login for an added layer of security, and it's working great...at least for Windows machines. Unfortunately MAC's can't connect, which isn't a huge deal since they represent a very small number in our environment. The MAC's have our root and intermediate certs installed in the System section of the Keychain app, but I don't believe that actually have a machine cert installed on them. Anyone know if the machine cert is required on the MAC, or should having the root and intermediate be enough? I'm not familiar with MAC's at all, has anyone else done this?&lt;/P&gt;</description>
      <pubDate>Wed, 30 Oct 2024 12:53:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Adding-certificate-requirement-on-RAVPN-for-MAC-s/m-p/231249#M2930</guid>
      <dc:creator>cdooer</dc:creator>
      <dc:date>2024-10-30T12:53:51Z</dc:date>
    </item>
    <item>
      <title>Re: Adding certificate requirement on RAVPN for MAC's</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Adding-certificate-requirement-on-RAVPN-for-MAC-s/m-p/231251#M2931</link>
      <description>&lt;P&gt;Generally speaking, if you are doing certificate-based authentication against a specific certificate authority (CA), the device connecting would need to have a certificate from that specific CA in order to get authenticated.&lt;/P&gt;
&lt;P&gt;While I have not configured machine authentication on a Check Point, I would imagine the MAC in question would require a valid machine certificate from your Windows CA.&lt;/P&gt;
&lt;P&gt;How do you get one? You can try navigating to your CA and requesting one (&lt;A href="https://&amp;lt;YourWindowsCA&amp;gt;/certsrv/" target="_blank"&gt;https://&amp;lt;YourWindowsCA&amp;gt;/certsrv/&lt;/A&gt;), or this Apple article might still be valid (&lt;A href="https://support.apple.com/en-sg/101196" target="_blank"&gt;https://support.apple.com/en-sg/101196&lt;/A&gt;). Other material I see on this references using MDM to accomplish this task.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Oct 2024 13:22:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Adding-certificate-requirement-on-RAVPN-for-MAC-s/m-p/231251#M2931</guid>
      <dc:creator>CaseyB</dc:creator>
      <dc:date>2024-10-30T13:22:33Z</dc:date>
    </item>
    <item>
      <title>Re: Adding certificate requirement on RAVPN for MAC's</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Adding-certificate-requirement-on-RAVPN-for-MAC-s/m-p/231298#M2932</link>
      <description>&lt;P&gt;If you are using Machine Certificates for authentication, then you have to deploy certificates to the Mac also.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Oct 2024 21:23:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Adding-certificate-requirement-on-RAVPN-for-MAC-s/m-p/231298#M2932</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-10-30T21:23:19Z</dc:date>
    </item>
  </channel>
</rss>

