<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSL Certificate in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SSL-Certificate/m-p/141081#M7243</link>
    <description>&lt;P&gt;Oh! what 0 have found in the manual:&lt;/P&gt;&lt;OL class=""&gt;&lt;LI&gt;Install the Access Policy on the gateway.&lt;P class=""&gt;&lt;STRONG&gt;Note&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;- The&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Repository of Certificates&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;on the IPsec VPN page of the gateway object is only for self-signed certificates. It does not affect the certificate installed manually using this procedure.&lt;/P&gt;&lt;/LI&gt;&lt;/OL&gt;</description>
    <pubDate>Wed, 09 Feb 2022 20:44:41 GMT</pubDate>
    <dc:creator>Sergo89</dc:creator>
    <dc:date>2022-02-09T20:44:41Z</dc:date>
    <item>
      <title>SSL Certificate</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SSL-Certificate/m-p/140927#M7236</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;My main question, how to reach Rating A on ssllabs.com? My certificate chain is broken. And i have no idea how to fix it.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Actually CheckPoint's SSL certificates are not clear for me.&amp;nbsp; First of all - three location, first one - IPSec VPN (we can generate CSR with proper SSL Chain - Root/intermediate/Cert itself), second location - Mobile Access/Portal Settings, third - VPN Clients/SAML Portal.&lt;/P&gt;&lt;P&gt;When i&amp;nbsp; installed self-signed certificate into first location (IPSec VPN) and/or Mobile Access i was getting error. Third location (SAML) i guess not alive anymore. Which one using for Endpoint VPN client? i though Mobile is for Phones and IPSec like for legacy windows VPN clients. Is it right?&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My certificate expired and i have to update it, when i did it first time, two years ago, version 80.30 didnt support wild card certificates, and i generated certificate from IPSec VPN and next used openssl magic for conversion to PFX format and next installed it to Mobile access portal. But i dont remember how i did it, and checkpoint support guy said - its wrong and need two certificates. How it works in this case? for example vpn.contoso.com for IPSec and vpnssl.contoso.com for mobile? i think i will see error&lt;/P&gt;&lt;P&gt;same time i have DR firewall, and i generated one certificate from IPSec VPN, and it works fine, my Endpoint Client ignores Mobile Portal and use right certificate (and it has rating A, because certificate chain is ok).&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could explain how it works and how to configure it properly?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Feb 2022 18:14:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SSL-Certificate/m-p/140927#M7236</guid>
      <dc:creator>Sergo89</dc:creator>
      <dc:date>2022-02-08T18:14:33Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Certificate</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SSL-Certificate/m-p/140929#M7237</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/39515"&gt;@Sergo89&lt;/a&gt;,&lt;BR /&gt;&lt;BR /&gt;Here are some tips and sk's about the certificates.&lt;/P&gt;
&lt;TABLE border="1" width="100%"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="100%"&gt;&lt;STRONG&gt;Mobile Access Certificate&lt;BR /&gt;&lt;/STRONG&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&lt;BR /&gt;The Security Gateway does not have a server certificate that is signed by a trusted 3rd party. Make sure that the server certificate of the Mobile Access gateway is signed by a trusted 3rd party Certification Authority (for example, EnTrust, VeriSign). The 3rd party certificate must replace the self-signed (ICA) certificate.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Note: &lt;/STRONG&gt;if you receive a .pfx file, rename the file extension from .pfx to .p12&lt;/P&gt;
&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk69660&amp;amp;partition=Advanced&amp;amp;product=Mobile" target="_self"&gt;How to generate Server Certificate Signing Request (CSR) and import the new 3rd Party certificate to Mobile Access Blade&lt;/A&gt; &lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;TABLE border="1" width="100%"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="100%"&gt;&lt;STRONG&gt;GAIA Portal Certificate&lt;BR /&gt;&lt;/STRONG&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&lt;BR /&gt;See sk97648:&lt;BR /&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk97648&amp;amp;partition=Advanced&amp;amp;product=All" target="_self"&gt;How to create and set certificate for Gaia Portal&lt;/A&gt;&lt;BR /&gt;or sk116462 for old firewalls:&lt;BR /&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk116462&amp;amp;partition=General&amp;amp;product=Security" target="_blank" rel="noopener"&gt;How to Install P7b format 3rd-party signed certificate on Gaia Portal without Multiportal feature&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;TABLE border="1" width="100%"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="100%"&gt;&lt;STRONG&gt;Internal CA Certificate&lt;BR /&gt;&lt;/STRONG&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&lt;BR /&gt;&lt;A class="cp_link sc_ellipsis" style="max-width: 840px;" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk158096&amp;amp;partition=Advanced&amp;amp;product=Quantum" target="_blank" rel="noopener"&gt;sk158096: How to renew an Internal Certificate Authority (ICA) certificate&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;TABLE border="1" width="100%"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="100%"&gt;&lt;STRONG&gt;VPN Certificate&lt;BR /&gt;&lt;/STRONG&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&lt;BR /&gt;See R8x.x VPN admin guide chapter PKI:&lt;BR /&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_SitetoSiteVPN_AdminGuide/Topics-VPNSG/PKI.htm?tocpath=Public%20Key%20Infrastructure%7C_____0#Public_Key_Infrastructure" target="_blank" rel="noopener"&gt;R81.10 Site to Site VPN Administration Guide - PKI&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Feb 2022 19:10:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SSL-Certificate/m-p/140929#M7237</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2022-02-08T19:10:14Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Certificate</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SSL-Certificate/m-p/140930#M7238</link>
      <description>&lt;P&gt;Thanks Heiko, but what do you mean "server certificate"? IPSec or Mobile, and yes i know how to create mobile certificate, but it will be two different certificates with different names. and which one Endpoint client uses? right now it shows me Mobile certificate (wildcard)&lt;/P&gt;</description>
      <pubDate>Tue, 08 Feb 2022 18:57:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SSL-Certificate/m-p/140930#M7238</guid>
      <dc:creator>Sergo89</dc:creator>
      <dc:date>2022-02-08T18:57:11Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Certificate</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SSL-Certificate/m-p/140933#M7239</link>
      <description>&lt;P&gt;Then I still do not understand your question 100%.&lt;BR /&gt;&lt;BR /&gt;&amp;gt;&amp;gt;&amp;gt; and which one Endpoint client uses?&lt;BR /&gt;&lt;BR /&gt;With the VPN client, it depends on which one you install:&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="VPN_Client.jpg" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/15335i464ECC74E617CEC0/image-size/medium?v=v2&amp;amp;px=400" role="button" title="VPN_Client.jpg" alt="VPN_Client.jpg" /&gt;&lt;/span&gt;&lt;BR /&gt;Endpoint Security VPN&amp;nbsp; -&amp;gt; Uses the internal CA certificate (ICA) and before E80.60 + lower R80.20 the gateway certificate.&lt;BR /&gt;&lt;BR /&gt;Check Point Mobile&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -&amp;gt; Uses the Mobile Access blade SSL certificate&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Feb 2022 19:38:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SSL-Certificate/m-p/140933#M7239</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2022-02-08T19:38:26Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Certificate</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SSL-Certificate/m-p/140934#M7240</link>
      <description>&lt;P&gt;Its Endpoint VPN, full bundle with AV.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Endpoint Security VPN&amp;nbsp; -&amp;gt; Uses the internal CA certificate (ICA) and before E80.60 + lower R80.20 the gateway certificate.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;its mean - IPSec VPN cert?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Feb 2022 20:08:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SSL-Certificate/m-p/140934#M7240</guid>
      <dc:creator>Sergo89</dc:creator>
      <dc:date>2022-02-08T20:08:46Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Certificate</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SSL-Certificate/m-p/140971#M7241</link>
      <description>&lt;P&gt;&amp;gt;&amp;gt;&amp;gt; Its Endpoint VPN, full bundle with AV.&lt;BR /&gt;For AV scanning you need an additional endpoint server and the managed client sk166428:&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Managed_Client.jpg" style="width: 623px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/15337i8CEB46A5094E5774/image-dimensions/623x137?v=v2" width="623" height="137" role="button" title="Managed_Client.jpg" alt="Managed_Client.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;gt;&amp;gt;&amp;gt; its mean - IPSec VPN cert?&amp;nbsp;&lt;BR /&gt;Yes - IPSec VPN uses the internal certificate (ICA) for "Endpoint Security VPN" client.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Feb 2022 08:19:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SSL-Certificate/m-p/140971#M7241</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2022-02-09T08:19:50Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Certificate</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SSL-Certificate/m-p/141079#M7242</link>
      <description>&lt;P&gt;Thanks Heiko,&lt;/P&gt;&lt;P&gt;how to choose which type of VPN we will be using? Full Endpoint Version doesnt have options (Mobile is different story). Do i have to create two different SSL certificates for IPSec VPN and SSL VPN?&lt;/P&gt;</description>
      <pubDate>Wed, 09 Feb 2022 20:42:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SSL-Certificate/m-p/141079#M7242</guid>
      <dc:creator>Sergo89</dc:creator>
      <dc:date>2022-02-09T20:42:33Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Certificate</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SSL-Certificate/m-p/141081#M7243</link>
      <description>&lt;P&gt;Oh! what 0 have found in the manual:&lt;/P&gt;&lt;OL class=""&gt;&lt;LI&gt;Install the Access Policy on the gateway.&lt;P class=""&gt;&lt;STRONG&gt;Note&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;- The&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Repository of Certificates&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;on the IPsec VPN page of the gateway object is only for self-signed certificates. It does not affect the certificate installed manually using this procedure.&lt;/P&gt;&lt;/LI&gt;&lt;/OL&gt;</description>
      <pubDate>Wed, 09 Feb 2022 20:44:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SSL-Certificate/m-p/141081#M7243</guid>
      <dc:creator>Sergo89</dc:creator>
      <dc:date>2022-02-09T20:44:41Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Certificate</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SSL-Certificate/m-p/141082#M7244</link>
      <description>&lt;P&gt;its from here:&lt;/P&gt;&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R80.10/WebAdminGuides/EN/CP_R80.10_MobileAccess_AdminGuide/html_frameset.htm?topic=documents/R80.10/WebAdminGuides/EN/CP_R80.10_MobileAccess_AdminGuide/23007" target="_blank"&gt;https://sc1.checkpoint.com/documents/R80.10/WebAdminGuides/EN/CP_R80.10_MobileAccess_AdminGuide/html_frameset.htm?topic=documents/R80.10/WebAdminGuides/EN/CP_R80.10_MobileAccess_AdminGuide/23007&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Feb 2022 20:48:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SSL-Certificate/m-p/141082#M7244</guid>
      <dc:creator>Sergo89</dc:creator>
      <dc:date>2022-02-09T20:48:34Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Certificate</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SSL-Certificate/m-p/141099#M7245</link>
      <description>&lt;P&gt;Heiko,&lt;/P&gt;&lt;P&gt;is it possible to find somewhere Private Key when we generate certificate from GUI (IPSec VPN)?&lt;/P&gt;</description>
      <pubDate>Thu, 10 Feb 2022 00:23:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SSL-Certificate/m-p/141099#M7245</guid>
      <dc:creator>Sergo89</dc:creator>
      <dc:date>2022-02-10T00:23:13Z</dc:date>
    </item>
  </channel>
</rss>

