<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: External CA certificate authentication in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/External-CA-certificate-authentication/m-p/208371#M3973</link>
    <description>&lt;P&gt;Whenever certificates are used, either CRL or OSCP must be used to validate the certificates, regardless of source.&lt;BR /&gt;The exact URL that is used to do this (listed in the certificate itself) must be accessible to all parties involved.&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2024 18:03:02 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2024-03-11T18:03:02Z</dc:date>
    <item>
      <title>External CA certificate authentication</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/External-CA-certificate-authentication/m-p/207466#M3972</link>
      <description>&lt;P&gt;Hello community!&lt;/P&gt;
&lt;P&gt;I wanted to ask some doubts we are facing during the re-design of remote access service with one customer. The goal is to provide MFA. One factor is RADIUS and working fine, This is a cluster of 2 X 1800 on R81.10.08 centrally managed, mgmt version is R81.20 jumbo 41.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For the other factor we are trying certificates. With certs created from the mgmt it works perfectly, but customer needs to use certificates from an existing CA (it is not the AD). The certificates are already deployed on the clients, but when we try to use that cert we get an error certificate invalid on the client, and logs on mgmt show "OCSP: could not connect to server. Make sure the server is up and running."&lt;/P&gt;
&lt;P&gt;We already have created CA and subCA objects on mgmt, also i can see traffic on port 80 from the gateway to the CA server, i think trying to validate the cert.&lt;/P&gt;
&lt;P&gt;Is it mandatory to use OSCP to validate certificates from the CA? or we have other options?&lt;/P&gt;
&lt;P&gt;The cert CN is &lt;A href="mailto:user@domain," target="_blank"&gt;username@domain,&lt;/A&gt;&amp;nbsp;is there any configuration to make the gateway only reads the username portion?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;is there anything else we should do on checkpoint side? customer already asked the CA admin to check if OSCP is enabled on the server, but wanted to see if i am missing something.&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Thu, 29 Feb 2024 12:57:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/External-CA-certificate-authentication/m-p/207466#M3972</guid>
      <dc:creator>RS_Daniel</dc:creator>
      <dc:date>2024-02-29T12:57:42Z</dc:date>
    </item>
    <item>
      <title>Re: External CA certificate authentication</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/External-CA-certificate-authentication/m-p/208371#M3973</link>
      <description>&lt;P&gt;Whenever certificates are used, either CRL or OSCP must be used to validate the certificates, regardless of source.&lt;BR /&gt;The exact URL that is used to do this (listed in the certificate itself) must be accessible to all parties involved.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2024 18:03:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/External-CA-certificate-authentication/m-p/208371#M3973</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-03-11T18:03:02Z</dc:date>
    </item>
    <item>
      <title>Re: External CA certificate authentication</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/External-CA-certificate-authentication/m-p/211980#M3974</link>
      <description>&lt;P&gt;But why is my client trying to validate OCSP now when it did not before? This was being handled by the server.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Apr 2024 17:53:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/External-CA-certificate-authentication/m-p/211980#M3974</guid>
      <dc:creator>rbeck-TMWA</dc:creator>
      <dc:date>2024-04-22T17:53:19Z</dc:date>
    </item>
    <item>
      <title>Re: External CA certificate authentication</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/External-CA-certificate-authentication/m-p/211982#M3975</link>
      <description>&lt;P&gt;Disregard my last reply&lt;/P&gt;</description>
      <pubDate>Mon, 22 Apr 2024 18:26:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/External-CA-certificate-authentication/m-p/211982#M3975</guid>
      <dc:creator>rbeck-TMWA</dc:creator>
      <dc:date>2024-04-22T18:26:52Z</dc:date>
    </item>
  </channel>
</rss>

