<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Machine Certificate Authentication with SAML (Azure) is not working in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Machine-Certificate-Authentication-with-SAML-Azure-is-not/m-p/183684#M4828</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I missed to mention that I have already configured LDAP Account Unit and Identity Awareness gathering information by using identity collectors which connects to the ADs.&amp;nbsp;&lt;/P&gt;&lt;P&gt;SAML is a second profile, if I use the first one which is based on RADIUS (NPS servers, same one used to host the identity collector agents) the connection works but not with machine certification. SAML works too, but not if I select any of the option related to the Machine Certificate Authentication.&lt;/P&gt;&lt;P&gt;Except of having a certificate with a subject value not empty, and of course importing Root CA and Subordinate CA in the SMS in order to check the local machine certificate, is there any other specific parameter / setting which we need to take care for making this work?&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
    <pubDate>Fri, 09 Jun 2023 10:41:25 GMT</pubDate>
    <dc:creator>Sky</dc:creator>
    <dc:date>2023-06-09T10:41:25Z</dc:date>
    <item>
      <title>Machine Certificate Authentication with SAML (Azure) is not working</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Machine-Certificate-Authentication-with-SAML-Azure-is-not/m-p/183555#M4822</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Trying to figure out why the configuration of the machine certificate authentication is not working....this one seems quite difficult.&lt;/P&gt;&lt;P&gt;SAML is working fine but adding cert auth for machines gives an error&amp;nbsp;"Internal error; connection failed. More details may be available in the logs".&lt;/P&gt;&lt;P&gt;I have placed respectively the Root CA that is in the local machine space as a Trusted CA and the same for the intermediate CA as Subordinate CA. Also have the signed certificate for the machine in the Personal Certificates. Saw some KB in regards to the subject name which was empty before, changed that to use the CN instead, but still no luck at all.&lt;/P&gt;&lt;P&gt;We have a distributed environment with SMS on R81 and a cluster on R80.40 and the Endpoint Security on E87.00&lt;/P&gt;&lt;P&gt;Has anyone faced something similar and were you able to fix this?&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jun 2023 21:30:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Machine-Certificate-Authentication-with-SAML-Azure-is-not/m-p/183555#M4822</guid>
      <dc:creator>Sky</dc:creator>
      <dc:date>2023-06-07T21:30:46Z</dc:date>
    </item>
    <item>
      <title>Re: Machine Certificate Authentication with SAML (Azure) is not working</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Machine-Certificate-Authentication-with-SAML-Azure-is-not/m-p/183560#M4823</link>
      <description>&lt;P&gt;What is the precise process you used to add machine certificate authentication?&lt;BR /&gt;Screenshots (with sensitive details redacted) would be exceptionally helpful here.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jun 2023 21:54:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Machine-Certificate-Authentication-with-SAML-Azure-is-not/m-p/183560#M4823</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-06-07T21:54:04Z</dc:date>
    </item>
    <item>
      <title>Re: Machine Certificate Authentication with SAML (Azure) is not working</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Machine-Certificate-Authentication-with-SAML-Azure-is-not/m-p/183565#M4824</link>
      <description>&lt;P&gt;I was using the approach described on the documentation and everything is running fine without machine cert auth:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Sky_0-1686175889817.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/21316i0AB7262D354D8F99/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Sky_0-1686175889817.png" alt="Sky_0-1686175889817.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Thinking as a more secure way trying to narrow down the access roles to the specific&amp;nbsp; OU containing the machines as well.&lt;BR /&gt;Checked also this one :&lt;/P&gt;&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk170140" target="_self"&gt;sk170140&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Some logs from the trac.log:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[ 5520 6368][8 Jun 0:19:17][RaisCertManager] SetFriendlyNameOnToken: __start__ 0:19:17.241&lt;BR /&gt;[ 5520 6368][8 Jun 0:19:17][RaisCertManager] GenerateFriendlyNameWithSerial: __start__ 0:19:17.241&lt;BR /&gt;[ 5520 6368][8 Jun 0:19:17][RaisCertManager] RaisCertManager::_GenerateFriendlyNameWithSerial: ERROR!! subject or serial is empty, return empty string&lt;BR /&gt;[ 5520 6368][8 Jun 0:19:17][RaisCertManager] GenerateFriendlyNameWithSerial: __end__ 0:19:17.241. Total time - 0 milliseconds&lt;BR /&gt;[ 5520 6368][8 Jun 0:19:17][RaisCertManager] SetFriendlyNameOnToken: __end__ 0:19:17.241. Total time - 0 milliseconds&lt;BR /&gt;[ 5520 6368][8 Jun 0:19:17][] fwCAPIProvider_imp::GetToken: Machine certificate, index 1.&lt;BR /&gt;[ 5520 6368][8 Jun 0:19:17][] fwCAPIToken::fwCAPIToken: enter (1) start (03331588, imp: 01E0A9F8)&lt;BR /&gt;[ 5520 6368][8 Jun 0:19:17][] fwCAPIToken_imp::Init2(PCCERT_CONTEXT TheCert): enter... machineCtx is 1&lt;BR /&gt;[ 5520 6368][8 Jun 0:19:17][] MyprintCertName:fwCAPIToken_imp::Init2(PCCERT_CONTEXT TheCert) enter...&lt;BR /&gt;[ 5520 6368][8 Jun 0:19:17][] MyprintCertName:fwCAPIToken_imp::Init2(PCCERT_CONTEXT TheCert) cert name is: CN=test.contoso.local&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[ 5520 6368][8 Jun 1:15:36][Rais_CAPICERT] Rais_CAPICERT::capi_cert_sign: Failed to sign Buffer&lt;BR /&gt;[ 5520 6368][8 Jun 1:15:36][] fwPubKey::SetMachineCtx: enter.. about to set to 0&lt;BR /&gt;[ 5520 6368][8 Jun 1:15:36][] fwWinPubKey_imp::SetMachineCtx: about to set machine contex to 0.&lt;BR /&gt;[ 5520 6368][8 Jun 1:15:36][Rais_CAPICERT] capi_cert_sign: __end__ 1:15:36.930. Total time - 5 milliseconds&lt;BR /&gt;[ 5520 6368][8 Jun 1:15:36][Rais_CAPICERT] CAPICert::Sign: __end__ 1:15:36.930. Total time - 5 milliseconds&lt;BR /&gt;[ 5520 6368][8 Jun 1:15:36][Rais_CAPICERT] Rais_CAPICERT::CAPICert::Machine_Sign: done.&lt;BR /&gt;[ 5520 6368][8 Jun 1:15:36][IKE] create_MM5(hybrid authentication): Failed to sign hash with the machine's certificate (-996)&lt;BR /&gt;[ 5520 6368][8 Jun 1:15:36][rais] [DEBUG] [RaisMessages::CreateMessageSet(s)] message: (msg_obj&lt;BR /&gt;:format (1.0)&lt;BR /&gt;:id (ClipsMessagesInternalError)&lt;BR /&gt;:def_msg ("Internal error; connection failed. More details may be available in the logs")&lt;BR /&gt;:arguments ()&lt;BR /&gt;)&lt;/P&gt;&lt;P&gt;[ 5520 6368][8 Jun 1:15:36][TR_FLOW_STEP] TR_FLOW_STEP::TrConnEngineConnectStep::operation_failed: Cb arrived&lt;BR /&gt;[ 5520 6368][8 Jun 1:15:36][FLOW] TrConnEngineConnectStep::operation_failed: user message set: (msg_obj&lt;BR /&gt;:format (1.0)&lt;BR /&gt;:id (ClipsMessagesInternalError)&lt;BR /&gt;:def_msg ("Internal error; connection failed. More details may be available in the logs")&lt;BR /&gt;:arguments ()&lt;/P&gt;&lt;P&gt;I am having hard time to understand why it is not working while I have the whole chain of certificates enrolled and on the relevant local machine relevant areas, have used the same PKI certificates in this case, just created a new one on the Personal Certificates on local machines since the subject was missing and we edited an existing template on the CA server in order to create a new request having the possibility to fill in the "Subject" filed there.&lt;BR /&gt;Not sure what important task I might have missed to mention here, please let me know if more needs to be described by me.&lt;/P&gt;&lt;P&gt;Thank you and best regards.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jun 2023 23:23:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Machine-Certificate-Authentication-with-SAML-Azure-is-not/m-p/183565#M4824</guid>
      <dc:creator>Sky</dc:creator>
      <dc:date>2023-06-07T23:23:30Z</dc:date>
    </item>
    <item>
      <title>Re: Machine Certificate Authentication with SAML (Azure) is not working</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Machine-Certificate-Authentication-with-SAML-Azure-is-not/m-p/183653#M4826</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I was able to find on this community some other situation describing somehow what I am facing:&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;A href="https://community.checkpoint.com/t5/Remote-Access-VPN/R81-New-VPN-users-unable-to-establish-VPN-via-SHA256/td-p/113828" target="_self"&gt;R81 - New VPN users unable to establish VPN via SHA256&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;After configuring phase 1 with SHA1 I still see issue when machine certification authentication is on "mandatory".&lt;/P&gt;&lt;P&gt;I get an error mentioning the Subordinate CA while I think the actual issue is with the ROOT CA on Trusted CA, because the real certificate is expiring in 2050 - while the one imported on SMS is expiring on 2038. This is really new to me, so I checked the ICA which is expiring as well on the same month on 2038 (maybe that is just a coincidence). Anyhow I thought to ask if someone might know or faced this before.&lt;/P&gt;&lt;P&gt;Thank you in advance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jun 2023 17:28:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Machine-Certificate-Authentication-with-SAML-Azure-is-not/m-p/183653#M4826</guid>
      <dc:creator>Sky</dc:creator>
      <dc:date>2023-06-08T17:28:23Z</dc:date>
    </item>
    <item>
      <title>Re: Machine Certificate Authentication with SAML (Azure) is not working</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Machine-Certificate-Authentication-with-SAML-Azure-is-not/m-p/183664#M4827</link>
      <description>&lt;P&gt;According to the &lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_RemoteAccessVPN_AdminGuide/Content/Topics-VPNRG/Machine-Certificate.htm?tocpath=_____12" target="_self"&gt;product documentation&lt;/A&gt;, you can only use Machine Certificates with a Microsoft AD server.&lt;BR /&gt;For Azure AD, you would configure the Machine Certification there as one of the authentication methods.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jun 2023 22:07:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Machine-Certificate-Authentication-with-SAML-Azure-is-not/m-p/183664#M4827</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-06-08T22:07:34Z</dc:date>
    </item>
    <item>
      <title>Re: Machine Certificate Authentication with SAML (Azure) is not working</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Machine-Certificate-Authentication-with-SAML-Azure-is-not/m-p/183684#M4828</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I missed to mention that I have already configured LDAP Account Unit and Identity Awareness gathering information by using identity collectors which connects to the ADs.&amp;nbsp;&lt;/P&gt;&lt;P&gt;SAML is a second profile, if I use the first one which is based on RADIUS (NPS servers, same one used to host the identity collector agents) the connection works but not with machine certification. SAML works too, but not if I select any of the option related to the Machine Certificate Authentication.&lt;/P&gt;&lt;P&gt;Except of having a certificate with a subject value not empty, and of course importing Root CA and Subordinate CA in the SMS in order to check the local machine certificate, is there any other specific parameter / setting which we need to take care for making this work?&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Fri, 09 Jun 2023 10:41:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Machine-Certificate-Authentication-with-SAML-Azure-is-not/m-p/183684#M4828</guid>
      <dc:creator>Sky</dc:creator>
      <dc:date>2023-06-09T10:41:25Z</dc:date>
    </item>
    <item>
      <title>Re: Machine Certificate Authentication with SAML (Azure) is not working</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Machine-Certificate-Authentication-with-SAML-Azure-is-not/m-p/183710#M4829</link>
      <description>&lt;P&gt;I believe the Machine Certificate setting applies to all profiles and SAML cannot be combined with other authentication methods (including Machine Certificate).&lt;BR /&gt;I think this will require a TAC case to more deeply investigate: &lt;A href="https://help.checkpoint.com" target="_blank"&gt;https://help.checkpoint.com&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Jun 2023 22:26:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Machine-Certificate-Authentication-with-SAML-Azure-is-not/m-p/183710#M4829</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-06-09T22:26:49Z</dc:date>
    </item>
    <item>
      <title>Re: Machine Certificate Authentication with SAML (Azure) is not working</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Machine-Certificate-Authentication-with-SAML-Azure-is-not/m-p/183722#M4830</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I understand that if Machine Certificate Authentication will be used, will&amp;nbsp; impact all realms configured but based on checkpoint documentation, it seems that is supported:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture.JPG" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/21354iB424C54797840C37/image-size/large?v=v2&amp;amp;px=999" role="button" title="Capture.JPG" alt="Capture.JPG" /&gt;&lt;/span&gt;&lt;BR /&gt;Unless I understand this in a wrong way&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":grinning_face_with_sweat:"&gt;😅&lt;/span&gt;&lt;BR /&gt;Regards&lt;/P&gt;</description>
      <pubDate>Sat, 10 Jun 2023 13:24:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Machine-Certificate-Authentication-with-SAML-Azure-is-not/m-p/183722#M4830</guid>
      <dc:creator>Sky</dc:creator>
      <dc:date>2023-06-10T13:24:35Z</dc:date>
    </item>
    <item>
      <title>Re: Machine Certificate Authentication with SAML (Azure) is not working</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Machine-Certificate-Authentication-with-SAML-Azure-is-not/m-p/183816#M4831</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Just thought to comment here as an update after I was able to solve this. It was a matter of internal communication from the firewall to the specific server where the certificate was pointing to in order to be checked against the CRL (communication towards that server on port 80 - http ). After that I can use the machine certification authentication as a factor with both SAML or Radius Servers (using Azure MFA as a second authentication factor except credentials).&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jun 2023 14:53:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Machine-Certificate-Authentication-with-SAML-Azure-is-not/m-p/183816#M4831</guid>
      <dc:creator>Sky</dc:creator>
      <dc:date>2023-06-12T14:53:17Z</dc:date>
    </item>
    <item>
      <title>Re: Machine Certificate Authentication with SAML (Azure) is not working</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Machine-Certificate-Authentication-with-SAML-Azure-is-not/m-p/183848#M4832</link>
      <description>&lt;P&gt;Good to know it's supported.&lt;BR /&gt;Still seems like the IdP would be a better place to configure this.&lt;BR /&gt;However, since it is supported to&lt;A href="https://sc1.checkpoint.com/documents/RemoteAccessClients_forWindows_AdminGuide/Content/Topics-RA-VPN-for-Win/Configuration-Examples-for-Machine-and-User-Authentication.htm" target="_self"&gt; use a Machine Certificate to bring up a Machine Tunnel&lt;/A&gt; before authenticating with a user via SAML, it makes sense these features would work together.&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jun 2023 23:05:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Machine-Certificate-Authentication-with-SAML-Azure-is-not/m-p/183848#M4832</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-06-12T23:05:08Z</dc:date>
    </item>
    <item>
      <title>Re: Machine Certificate Authentication with SAML (Azure) is not working</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Machine-Certificate-Authentication-with-SAML-Azure-is-not/m-p/203064#M4833</link>
      <description>&lt;P&gt;Hello Sky,&lt;BR /&gt;&lt;BR /&gt;Thanks for sharing the very good tips. I am gathering the information, and would like to test out this solution as well. Is there any changes, or attribute needs to modify at Azure side to implement the Machine Authentication? It&amp;nbsp; would be great if you could share the issue/challenging during the implementation.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jan 2024 08:24:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Machine-Certificate-Authentication-with-SAML-Azure-is-not/m-p/203064#M4833</guid>
      <dc:creator>sambath</dc:creator>
      <dc:date>2024-01-15T08:24:53Z</dc:date>
    </item>
  </channel>
</rss>

