<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Terminating Endpoint Connect with user certificate (CN) in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Terminating-Endpoint-Connect-with-user-certificate-CN/m-p/165648#M5810</link>
    <description>&lt;P&gt;Any ideas on this issue?&lt;/P&gt;</description>
    <pubDate>Tue, 20 Dec 2022 08:59:54 GMT</pubDate>
    <dc:creator>CP-Shark</dc:creator>
    <dc:date>2022-12-20T08:59:54Z</dc:date>
    <item>
      <title>Terminating Endpoint Connect with user certificate (CN)</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Terminating-Endpoint-Connect-with-user-certificate-CN/m-p/165200#M5809</link>
      <description>&lt;P&gt;Hi guys,&lt;/P&gt;&lt;P&gt;I want to implement the Endpoint Connect&amp;nbsp; VPN solution using Remote Access VPN Blade provided by Harmony.&lt;BR /&gt;It is working fine if I am using the Fully distinguished name (FQDN) in the certificate (MS Enterprise PKI):&lt;/P&gt;&lt;DIV class=""&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Cert.jpg" style="width: 373px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/18798i525D9CC9C5D1B728/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Cert.jpg" alt="Cert.jpg" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="123.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/18799i409AF98A160D9B4D/image-size/medium?v=v2&amp;amp;px=400" role="button" title="123.png" alt="123.png" /&gt;&lt;/span&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;But with this configuration I have the issue that when a user moves to another organisation unit in Active Directory the VPN is not connecting anymore and this is based on the configuration totally fine and correct. But in an environment with 5000+ users this is not handable so I want to use common name or email address. The change in the certificate template is not the problem, but if I change the Authentications settings on the gateway like this (or Subject Alternative Name.Email)&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="cert2.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/18797i2D28B1A14B91B6F2/image-size/medium?v=v2&amp;amp;px=400" role="button" title="cert2.png" alt="cert2.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;the VPN is not connecting anymore with error -&amp;gt; User CN=Common Name unknown.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;I am sure that this is not a unique requirement but I don´t now what I need to change to get this working.&lt;BR /&gt;&lt;BR /&gt;Cheers,&lt;BR /&gt;Olli&lt;/P&gt;</description>
      <pubDate>Wed, 14 Dec 2022 15:51:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Terminating-Endpoint-Connect-with-user-certificate-CN/m-p/165200#M5809</guid>
      <dc:creator>CP-Shark</dc:creator>
      <dc:date>2022-12-14T15:51:28Z</dc:date>
    </item>
    <item>
      <title>Re: Terminating Endpoint Connect with user certificate (CN)</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Terminating-Endpoint-Connect-with-user-certificate-CN/m-p/165648#M5810</link>
      <description>&lt;P&gt;Any ideas on this issue?&lt;/P&gt;</description>
      <pubDate>Tue, 20 Dec 2022 08:59:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Terminating-Endpoint-Connect-with-user-certificate-CN/m-p/165648#M5810</guid>
      <dc:creator>CP-Shark</dc:creator>
      <dc:date>2022-12-20T08:59:54Z</dc:date>
    </item>
    <item>
      <title>Re: Terminating Endpoint Connect with user certificate (CN)</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Terminating-Endpoint-Connect-with-user-certificate-CN/m-p/165727#M5811</link>
      <description>&lt;P&gt;Have you opened a TAC case?&lt;/P&gt;</description>
      <pubDate>Tue, 20 Dec 2022 23:57:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Terminating-Endpoint-Connect-with-user-certificate-CN/m-p/165727#M5811</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-12-20T23:57:05Z</dc:date>
    </item>
    <item>
      <title>Re: Terminating Endpoint Connect with user certificate (CN)</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Terminating-Endpoint-Connect-with-user-certificate-CN/m-p/210785#M5812</link>
      <description>&lt;P&gt;Any updates on this?&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Apr 2024 08:25:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Terminating-Endpoint-Connect-with-user-certificate-CN/m-p/210785#M5812</guid>
      <dc:creator>cenes</dc:creator>
      <dc:date>2024-04-09T08:25:51Z</dc:date>
    </item>
    <item>
      <title>Re: Terminating Endpoint Connect with user certificate (CN)</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Terminating-Endpoint-Connect-with-user-certificate-CN/m-p/210851#M5813</link>
      <description>&lt;P&gt;Most probably no, considering the post is from year 2022.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Apr 2024 13:22:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Terminating-Endpoint-Connect-with-user-certificate-CN/m-p/210851#M5813</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2024-04-09T13:22:53Z</dc:date>
    </item>
  </channel>
</rss>

