<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Import the root CA and intermediate CAs for authentication with digital certificate to work in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Import-the-root-CA-and-intermediate-CAs-for-authentication-with/m-p/151882#M6540</link>
    <description>&lt;P&gt;Hello everybody,&lt;/P&gt;&lt;P&gt;We are trying to enable MFA on the remote VPN. Authentication is currently done through LDAP and works perfectly. We want to enable authentication with digital certificate from an external CA and LDAP username and password. We made the necessary settings informing the LDAP field used to compare with the digital certificate field. We verified in the logs that the field (Subject DN.CN) is correctly extracted from the certificate. However, during client authentication, the following error message is displayed:&lt;BR /&gt;"&lt;STRONG&gt;cannot complete certificate chain CN=Brazilian Root Certification Authority v5,OU=National Institute of Information Technology - ITI,O=ICP-Brasil,C=BR&lt;/STRONG&gt;"&lt;/P&gt;&lt;P&gt;I would like to know where and how to import the root CA and intermediate CAs.&lt;/P&gt;</description>
    <pubDate>Mon, 27 Jun 2022 23:26:26 GMT</pubDate>
    <dc:creator>efchaves</dc:creator>
    <dc:date>2022-06-27T23:26:26Z</dc:date>
    <item>
      <title>Import the root CA and intermediate CAs for authentication with digital certificate to work</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Import-the-root-CA-and-intermediate-CAs-for-authentication-with/m-p/151882#M6540</link>
      <description>&lt;P&gt;Hello everybody,&lt;/P&gt;&lt;P&gt;We are trying to enable MFA on the remote VPN. Authentication is currently done through LDAP and works perfectly. We want to enable authentication with digital certificate from an external CA and LDAP username and password. We made the necessary settings informing the LDAP field used to compare with the digital certificate field. We verified in the logs that the field (Subject DN.CN) is correctly extracted from the certificate. However, during client authentication, the following error message is displayed:&lt;BR /&gt;"&lt;STRONG&gt;cannot complete certificate chain CN=Brazilian Root Certification Authority v5,OU=National Institute of Information Technology - ITI,O=ICP-Brasil,C=BR&lt;/STRONG&gt;"&lt;/P&gt;&lt;P&gt;I would like to know where and how to import the root CA and intermediate CAs.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jun 2022 23:26:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Import-the-root-CA-and-intermediate-CAs-for-authentication-with/m-p/151882#M6540</guid>
      <dc:creator>efchaves</dc:creator>
      <dc:date>2022-06-27T23:26:26Z</dc:date>
    </item>
    <item>
      <title>Re: Import the root CA and intermediate CAs for authentication with digital certificate to work</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Import-the-root-CA-and-intermediate-CAs-for-authentication-with/m-p/151943#M6541</link>
      <description>&lt;P&gt;You need to create a Certificate Authority object if you haven't already.&lt;BR /&gt;In the file you import, you will need to include the entire certificate chain (root plus intermediate ones).&lt;/P&gt;
&lt;P&gt;If you've done that already, it's possible you will need to import the root and intermediate certs to the clients themselves.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jun 2022 17:49:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Import-the-root-CA-and-intermediate-CAs-for-authentication-with/m-p/151943#M6541</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-06-28T17:49:11Z</dc:date>
    </item>
  </channel>
</rss>

