<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Remove Access VPN: Gateway presenting wrong certificate? in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remove-Access-VPN-Gateway-presenting-wrong-certificate/m-p/168985#M5589</link>
    <description>&lt;P&gt;Yes it was changed a while back, on R77.30 some 4-5 years ago when it expired to what you currently see. I did renew that same cert a few weeks ago since they expired.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Checkpoint support have seen this setting multiple times without mentioning this would be problem so I'm a bit confused...&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 24 Jan 2023 19:07:52 GMT</pubDate>
    <dc:creator>casgrain</dc:creator>
    <dc:date>2023-01-24T19:07:52Z</dc:date>
    <item>
      <title>Remove Access VPN: Gateway presenting wrong certificate?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remove-Access-VPN-Gateway-presenting-wrong-certificate/m-p/168974#M5586</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I've noticed our gateways are presenting the web certificate configured for platform portal/usercheck/saml portal instead of the one under IPSEC VPN.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Am I missing something? From my understanding this is not the expected behavior. I've attached some screenshot in hope it'll help understand my context.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;We on R81.10 with hotfix take 81. All clients are version E84 or above.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jan 2023 17:30:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remove-Access-VPN-Gateway-presenting-wrong-certificate/m-p/168974#M5586</guid>
      <dc:creator>casgrain</dc:creator>
      <dc:date>2023-01-24T17:30:57Z</dc:date>
    </item>
    <item>
      <title>Re: Remove Access VPN: Gateway presenting wrong certificate?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remove-Access-VPN-Gateway-presenting-wrong-certificate/m-p/168979#M5587</link>
      <description>&lt;P&gt;That does not appear right. Let me check it in cusomer's environment and will update you.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jan 2023 18:34:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remove-Access-VPN-Gateway-presenting-wrong-certificate/m-p/168979#M5587</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-01-24T18:34:18Z</dc:date>
    </item>
    <item>
      <title>Re: Remove Access VPN: Gateway presenting wrong certificate?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remove-Access-VPN-Gateway-presenting-wrong-certificate/m-p/168980#M5588</link>
      <description>&lt;P&gt;Question...did you actually end up removing defaultCert that was there? I ask because you can NOT change nickname of a cert, unless new one is created. By the way, checked for another client and they have default cert there and works fine, I deleted their VPN site and created it again and get proper fingerprint. They also use another cert for web UI which is also presented correctly.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jan 2023 18:48:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remove-Access-VPN-Gateway-presenting-wrong-certificate/m-p/168980#M5588</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-01-24T18:48:31Z</dc:date>
    </item>
    <item>
      <title>Re: Remove Access VPN: Gateway presenting wrong certificate?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remove-Access-VPN-Gateway-presenting-wrong-certificate/m-p/168985#M5589</link>
      <description>&lt;P&gt;Yes it was changed a while back, on R77.30 some 4-5 years ago when it expired to what you currently see. I did renew that same cert a few weeks ago since they expired.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Checkpoint support have seen this setting multiple times without mentioning this would be problem so I'm a bit confused...&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jan 2023 19:07:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remove-Access-VPN-Gateway-presenting-wrong-certificate/m-p/168985#M5589</guid>
      <dc:creator>casgrain</dc:creator>
      <dc:date>2023-01-24T19:07:52Z</dc:date>
    </item>
    <item>
      <title>Re: Remove Access VPN: Gateway presenting wrong certificate?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remove-Access-VPN-Gateway-presenting-wrong-certificate/m-p/168986#M5590</link>
      <description>&lt;P&gt;Dont believe its an issue per se, but was more curious.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jan 2023 19:12:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remove-Access-VPN-Gateway-presenting-wrong-certificate/m-p/168986#M5590</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-01-24T19:12:58Z</dc:date>
    </item>
    <item>
      <title>Re: Remove Access VPN: Gateway presenting wrong certificate?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remove-Access-VPN-Gateway-presenting-wrong-certificate/m-p/175598#M5591</link>
      <description>&lt;P&gt;I have the same issue on same version. Any ideas how to resolve this?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Mar 2023 16:18:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remove-Access-VPN-Gateway-presenting-wrong-certificate/m-p/175598#M5591</guid>
      <dc:creator>casgrain</dc:creator>
      <dc:date>2023-03-21T16:18:05Z</dc:date>
    </item>
    <item>
      <title>Re: Remove Access VPN: Gateway presenting wrong certificate?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remove-Access-VPN-Gateway-presenting-wrong-certificate/m-p/175599#M5592</link>
      <description>&lt;P&gt;Whats gw, client version?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 21 Mar 2023 16:25:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remove-Access-VPN-Gateway-presenting-wrong-certificate/m-p/175599#M5592</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-03-21T16:25:47Z</dc:date>
    </item>
    <item>
      <title>Re: Remove Access VPN: Gateway presenting wrong certificate?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remove-Access-VPN-Gateway-presenting-wrong-certificate/m-p/219593#M5593</link>
      <description>&lt;P&gt;I have similar. Customer had a pen test the highlighted SHA1 in the chain of certs on &lt;A href="https://ipadrress:443" target="_blank"&gt;https://ipadrress:443&lt;/A&gt;. So regenerated the ICA cert with&amp;nbsp;sk158096 script. ICA looks to sign with Sha256. So renewed vpn cert and pushed policy but the certificate on the web page doesn't seem to update. They have a saml portal enabled with default cert. GW and MGMT on R81.20. If I do the same process in a lab the cert changes on the web page. Been looking at&amp;nbsp;sk131212, sk94965, sk152713. No idea at moment.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jul 2024 16:16:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remove-Access-VPN-Gateway-presenting-wrong-certificate/m-p/219593#M5593</guid>
      <dc:creator>LazarusG</dc:creator>
      <dc:date>2024-07-03T16:16:32Z</dc:date>
    </item>
    <item>
      <title>Re: Remove Access VPN: Gateway presenting wrong certificate?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remove-Access-VPN-Gateway-presenting-wrong-certificate/m-p/219616#M5594</link>
      <description>&lt;P&gt;If you're just concerned with the fingerprint for the VPN client, then that fingerprint the one of the management server CA, not the gateway's own certificate. &amp;nbsp;This is why the fingerprint doesn't change for the clients just because the gateway's certificate is renewed by the management server. &amp;nbsp;HOWEVER... if you changed your management server certificate, then this WILL change.&lt;/P&gt;
&lt;P&gt;I have a script I posted to the Toolbox that can decode it for you:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Scripts/rfc1751-py/m-p/194975#M1130" target="_blank"&gt;https://community.checkpoint.com/t5/Scripts/rfc1751-py/m-p/194975#M1130&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Get this Python script, and you can run the inline "openssl s_client" command against your gateway which will get you the correct fingerprint you can verify.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jul 2024 19:09:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remove-Access-VPN-Gateway-presenting-wrong-certificate/m-p/219616#M5594</guid>
      <dc:creator>Duane_Toler</dc:creator>
      <dc:date>2024-07-03T19:09:14Z</dc:date>
    </item>
  </channel>
</rss>

