<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Secure Domain Logon with certificate based authentication in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Secure-Domain-Logon-with-certificate-based-authentication/m-p/173425#M5418</link>
    <description>&lt;P&gt;Ouch, I missed this. Thanks a lot!&lt;/P&gt;</description>
    <pubDate>Thu, 02 Mar 2023 20:42:50 GMT</pubDate>
    <dc:creator>Kilian_Huber</dc:creator>
    <dc:date>2023-03-02T20:42:50Z</dc:date>
    <item>
      <title>Secure Domain Logon with certificate based authentication</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Secure-Domain-Logon-with-certificate-based-authentication/m-p/173365#M5411</link>
      <description>&lt;P&gt;Hi CheckMates,&lt;/P&gt;&lt;P&gt;when trying to use Secure Domain Logon with certificate based authentication (E86.26 client), the Secure Domain Logon dialogue does not offer any certificate to be chosen as shown in the screenshot below:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="EPS-SDL.jpg" style="width: 600px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/19891i813725557E415543/image-size/large?v=v2&amp;amp;px=999" role="button" title="EPS-SDL.jpg" alt="EPS-SDL.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;The user certificate store contains a certificate for the user which should be authenticated and the computer certificate store contains a machine certificate.&lt;/P&gt;&lt;P&gt;When skipping SDL and logging in with cached credentials, and then manually establishing a VPN connection, the user's certificate is correctly fetched via CAPI and certificate authentication is successful.&lt;/P&gt;&lt;P&gt;Any idea on how to troubleshoot why no certificate is available in the SDL authentication dialogue?&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 02 Mar 2023 13:35:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Secure-Domain-Logon-with-certificate-based-authentication/m-p/173365#M5411</guid>
      <dc:creator>Kilian_Huber</dc:creator>
      <dc:date>2023-03-02T13:35:09Z</dc:date>
    </item>
    <item>
      <title>Re: Secure Domain Logon with certificate based authentication</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Secure-Domain-Logon-with-certificate-based-authentication/m-p/173368#M5412</link>
      <description>&lt;P&gt;Is this an EPS client with TP blades ? sk146712&lt;/P&gt;</description>
      <pubDate>Thu, 02 Mar 2023 13:47:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Secure-Domain-Logon-with-certificate-based-authentication/m-p/173368#M5412</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-03-02T13:47:21Z</dc:date>
    </item>
    <item>
      <title>Re: Secure Domain Logon with certificate based authentication</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Secure-Domain-Logon-with-certificate-based-authentication/m-p/173369#M5413</link>
      <description>&lt;P&gt;It is an Endpoint Security Client, yes, but the FDE blade is not installed.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Mar 2023 13:52:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Secure-Domain-Logon-with-certificate-based-authentication/m-p/173369#M5413</guid>
      <dc:creator>Kilian_Huber</dc:creator>
      <dc:date>2023-03-02T13:52:07Z</dc:date>
    </item>
    <item>
      <title>Re: Secure Domain Logon with certificate based authentication</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Secure-Domain-Logon-with-certificate-based-authentication/m-p/173370#M5414</link>
      <description>&lt;P&gt;I don’t believe SDL is necessary for this.&lt;BR /&gt;See:&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/Remote-Access-VPN/How-to-Have-Remote-Access-VPN-Tunnel-Before-User-is-Logged-In/m-p/173047" target="_blank"&gt;https://community.checkpoint.com/t5/Remote-Access-VPN/How-to-Have-Remote-Access-VPN-Tunnel-Before-User-is-Logged-In/m-p/173047&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Mar 2023 13:55:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Secure-Domain-Logon-with-certificate-based-authentication/m-p/173370#M5414</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-03-02T13:55:35Z</dc:date>
    </item>
    <item>
      <title>Re: Secure Domain Logon with certificate based authentication</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Secure-Domain-Logon-with-certificate-based-authentication/m-p/173377#M5415</link>
      <description>&lt;P&gt;So i would suggest TAC...&lt;/P&gt;</description>
      <pubDate>Thu, 02 Mar 2023 14:36:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Secure-Domain-Logon-with-certificate-based-authentication/m-p/173377#M5415</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-03-02T14:36:08Z</dc:date>
    </item>
    <item>
      <title>Re: Secure Domain Logon with certificate based authentication</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Secure-Domain-Logon-with-certificate-based-authentication/m-p/173378#M5416</link>
      <description>&lt;P&gt;The machine certificate was just a test to see if I could select this certificate from the drop down list on the SDL window since I don't see the user certificate either. I do not actually want to use machine based authentication; all endpoints already have a user certificates rolled out and this should be used for authentication. IMHO this should be working since the user authenticates to Windows before the SDL window appears, therefore the personal certificate store should be accessible.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Mar 2023 14:44:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Secure-Domain-Logon-with-certificate-based-authentication/m-p/173378#M5416</guid>
      <dc:creator>Kilian_Huber</dc:creator>
      <dc:date>2023-03-02T14:44:02Z</dc:date>
    </item>
    <item>
      <title>Re: Secure Domain Logon with certificate based authentication</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Secure-Domain-Logon-with-certificate-based-authentication/m-p/173422#M5417</link>
      <description>&lt;P&gt;CAPI certificates cannot be used for SDL.&lt;BR /&gt;This is in the documentation:&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/RemoteAccessClients_forWindows_AdminGuide/Content/Topics-RA-VPN-for-Win/SDL-for-SmartConsole-Managed-Clients.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/RemoteAccessClients_forWindows_AdminGuide/Content/Topics-RA-VPN-for-Win/SDL-for-SmartConsole-Managed-Clients.htm&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Mar 2023 20:30:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Secure-Domain-Logon-with-certificate-based-authentication/m-p/173422#M5417</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-03-02T20:30:00Z</dc:date>
    </item>
    <item>
      <title>Re: Secure Domain Logon with certificate based authentication</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Secure-Domain-Logon-with-certificate-based-authentication/m-p/173425#M5418</link>
      <description>&lt;P&gt;Ouch, I missed this. Thanks a lot!&lt;/P&gt;</description>
      <pubDate>Thu, 02 Mar 2023 20:42:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Secure-Domain-Logon-with-certificate-based-authentication/m-p/173425#M5418</guid>
      <dc:creator>Kilian_Huber</dc:creator>
      <dc:date>2023-03-02T20:42:50Z</dc:date>
    </item>
  </channel>
</rss>

