<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Automatic certificate renewal in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Automatic-certificate-renewal/m-p/181656#M7828</link>
    <description>&lt;P&gt;NO - at least if you do an upgrade, not fresh install without db import 8)&lt;/img&gt; After Jumbo install, GAiA WebGUI may need a new exception for the self-signed cert in browser, but that is all...&lt;/P&gt;
&lt;P&gt;See &lt;A href="https://support.checkpoint.com/results/sk/sk158096" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;sk158096: How to &lt;STRONG&gt;renew&lt;/STRONG&gt; an Internal Certificate Authority (&lt;STRONG&gt;ICA&lt;/STRONG&gt;) certificate&lt;/SPAN&gt;&lt;/A&gt; for on-purpose renewals - &lt;A href="https://support.checkpoint.com/results/sk/sk164255" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;sk164255: SIC Certificate fails to &lt;STRONG&gt;renew&lt;/STRONG&gt; &lt;STRONG&gt;automatically&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/A&gt; for issues with that!&lt;/P&gt;</description>
    <pubDate>Mon, 22 May 2023 14:56:56 GMT</pubDate>
    <dc:creator>G_W_Albrecht</dc:creator>
    <dc:date>2023-05-22T14:56:56Z</dc:date>
    <item>
      <title>Automatic certificate renewal</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Automatic-certificate-renewal/m-p/131840#M7816</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;With the maximum validity period of certificates becoming shorter all the time it is a challenge for large deployments to renew everything. Is there a known solution to automate this for the remote access solutions of Check Point? And maybe even the Gaia interface as well? (some of our customers even have an external wildcard certificate on their Gaia webinterface).&amp;nbsp;&lt;/P&gt;&lt;P&gt;Things like certbot don't apply for the VPN solution I guess, or maybe via the API?&lt;/P&gt;&lt;P&gt;Thanks in advance,&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Erik&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Oct 2021 12:30:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Automatic-certificate-renewal/m-p/131840#M7816</guid>
      <dc:creator>ErikV</dc:creator>
      <dc:date>2021-10-15T12:30:03Z</dc:date>
    </item>
    <item>
      <title>Re: Automatic certificate renewal</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Automatic-certificate-renewal/m-p/131929#M7817</link>
      <description>&lt;P&gt;If you're using the ICA, then in theory, the certificates should renew automatically.&lt;BR /&gt;For an external CA, I'm not aware of an easy way to automate this stuff as there aren't really APIs or CLI commands to do this that I'm aware of.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Oct 2021 07:06:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Automatic-certificate-renewal/m-p/131929#M7817</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-10-18T07:06:40Z</dc:date>
    </item>
    <item>
      <title>Re: Automatic certificate renewal</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Automatic-certificate-renewal/m-p/132541#M7818</link>
      <description>&lt;P&gt;There must be something for this right?&lt;/P&gt;&lt;P&gt;Can't believe that we still need to do this time consuming job by hand every year again.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Oct 2021 10:32:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Automatic-certificate-renewal/m-p/132541#M7818</guid>
      <dc:creator>checkfreehs</dc:creator>
      <dc:date>2021-10-25T10:32:03Z</dc:date>
    </item>
    <item>
      <title>Re: Automatic certificate renewal</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Automatic-certificate-renewal/m-p/132665#M7819</link>
      <description>&lt;P&gt;I see in API v1.8 there are certificate installation options for the platform portal and the usercheck page, but not for the mobile access portal (or I did not find it yet). Let's hope this will be added in the near future as well!&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Erik&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Oct 2021 21:10:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Automatic-certificate-renewal/m-p/132665#M7819</guid>
      <dc:creator>ErikV</dc:creator>
      <dc:date>2021-10-26T21:10:19Z</dc:date>
    </item>
    <item>
      <title>Re: Automatic certificate renewal</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Automatic-certificate-renewal/m-p/157778#M7820</link>
      <description>&lt;P&gt;Hi, Did you find any solution on this problem.?&lt;/P&gt;</description>
      <pubDate>Thu, 22 Sep 2022 06:31:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Automatic-certificate-renewal/m-p/157778#M7820</guid>
      <dc:creator>Baasanjargal_Ts</dc:creator>
      <dc:date>2022-09-22T06:31:58Z</dc:date>
    </item>
    <item>
      <title>Re: Automatic certificate renewal</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Automatic-certificate-renewal/m-p/162218#M7821</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;i just had the same issue now, VPN from a remote GW just stopped.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;EM&gt;Not Valid Before: Mon Nov 15 12:55:30 2021 Local Time&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Not Valid After:&amp;nbsp;&amp;nbsp;Wed Nov 16 12:55:30 2022 Local Time&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="Unbenannt.PNG" style="width: 349px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/18424i70C75898E594ECDA/image-size/large?v=v2&amp;amp;px=999" role="button" title="Unbenannt.PNG" alt="Unbenannt.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;But iam not sure if VPN certificates really get&amp;nbsp;renewed automatically?&lt;BR /&gt;Where in a guide/SK is this written?&lt;BR /&gt;Anyway, i have seen this too often i will open a case and ask TAC.&lt;/P&gt;
&lt;P&gt;i will keep u posted!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Nov 2022 17:54:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Automatic-certificate-renewal/m-p/162218#M7821</guid>
      <dc:creator>Thomas_Eichelbu</dc:creator>
      <dc:date>2022-11-16T17:54:19Z</dc:date>
    </item>
    <item>
      <title>Re: Automatic certificate renewal</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Automatic-certificate-renewal/m-p/168346#M7822</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;I have the same question, I talked to my certificate provider, and they told my, that I should expect that the lifetime on certificate will go to 3 month or lower, so a automated way of doing it is a must.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jan 2023 12:27:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Automatic-certificate-renewal/m-p/168346#M7822</guid>
      <dc:creator>Soren_Kristense</dc:creator>
      <dc:date>2023-01-19T12:27:50Z</dc:date>
    </item>
    <item>
      <title>Re: Automatic certificate renewal</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Automatic-certificate-renewal/m-p/168420#M7823</link>
      <description>&lt;P&gt;I suspect we'll have a way to update this information via API in the future.&amp;nbsp;&lt;BR /&gt;Having said that, I highly recommend approaching your Check Point SE with your precise requirements for this.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jan 2023 17:56:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Automatic-certificate-renewal/m-p/168420#M7823</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-01-19T17:56:49Z</dc:date>
    </item>
    <item>
      <title>Re: Automatic certificate renewal</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Automatic-certificate-renewal/m-p/170732#M7824</link>
      <description>&lt;P&gt;The future is NOW.&lt;/P&gt;&lt;P&gt;You are rather later with this.&lt;/P&gt;</description>
      <pubDate>Wed, 08 Feb 2023 14:01:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Automatic-certificate-renewal/m-p/170732#M7824</guid>
      <dc:creator>checkfreehs</dc:creator>
      <dc:date>2023-02-08T14:01:38Z</dc:date>
    </item>
    <item>
      <title>Re: Automatic certificate renewal</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Automatic-certificate-renewal/m-p/170736#M7825</link>
      <description>&lt;P&gt;This sounds rather strange - 3 months or lower ? Then we better stay with the internal CA...&lt;/P&gt;</description>
      <pubDate>Wed, 08 Feb 2023 14:18:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Automatic-certificate-renewal/m-p/170736#M7825</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-02-08T14:18:07Z</dc:date>
    </item>
    <item>
      <title>Re: Automatic certificate renewal</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Automatic-certificate-renewal/m-p/170780#M7826</link>
      <description>&lt;P&gt;&lt;A href="https://letsencrypt.org/docs/faq/" target="_blank" rel="noopener"&gt;https://letsencrypt.org/docs/faq/&lt;/A&gt;&lt;/P&gt;&lt;H2&gt;What is the lifetime for Let’s Encrypt certificates? For how long are they valid?&lt;/H2&gt;&lt;P&gt;Our certificates are valid for 90 days. You can read about why &lt;A href="https://letsencrypt.org/2015/11/09/why-90-days.html" target="_blank" rel="noopener"&gt;here&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;There is no way to adjust this, there are no exceptions. We recommend automatically renewing your certificates every 60 days.&lt;/P&gt;&lt;P&gt;&lt;A href="https://letsencrypt.org/2015/11/09/why-90-days.html" target="_blank" rel="noopener"&gt;https://letsencrypt.org/2015/11/09/why-90-days.html&lt;/A&gt;&lt;/P&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;H1&gt;Why ninety-day lifetimes for certificates?&lt;/H1&gt;&lt;P class=""&gt;Nov 9, 2015 • Josh Aas, ISRG Executive Director&lt;/P&gt;&lt;P&gt;We’re sometimes asked why we only offer certificates with ninety-day lifetimes. People who ask this are usually concerned that ninety days is too short and wish we would offer certificates lasting a year or more, like some other CAs do.&lt;/P&gt;&lt;P&gt;Ninety days is nothing new on the Web. According to Firefox Telemetry, 29% of TLS transactions use ninety-day certificates. That’s more than any other lifetime. From our perspective, there are two primary advantages to such short certificate lifetimes:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;They limit damage from key compromise and mis-issuance. Stolen keys and mis-issued certificates are valid for a shorter period of time.&lt;/LI&gt;&lt;LI&gt;They encourage automation, which is absolutely essential for ease-of-use. If we’re going to move the entire Web to HTTPS, we can’t continue to expect system administrators to manually handle renewals. Once issuance and renewal are automated, shorter lifetimes won’t be any less convenient than longer ones.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;For these reasons, we do not offer certificates with lifetimes longer than ninety days. We realize that our service is young, and that automation is new to many subscribers, so we chose a lifetime that allows plenty of time for manual renewal if necessary. We recommend that subscribers renew every sixty days. Once automated renewal tools are widely deployed and working well, we may consider even shorter lifetimes.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the future was already before 2015, almost 10 years from now.&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 08 Feb 2023 19:57:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Automatic-certificate-renewal/m-p/170780#M7826</guid>
      <dc:creator>checkfreehs</dc:creator>
      <dc:date>2023-02-08T19:57:36Z</dc:date>
    </item>
    <item>
      <title>Re: Automatic certificate renewal</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Automatic-certificate-renewal/m-p/181654#M7827</link>
      <description>&lt;P&gt;Hi PhoneBoy,&lt;BR /&gt;I have question regarding the ICA renewal, is it any way to ICA will be automatically renewed ? eg. by installing new software/hot fix ?&lt;/P&gt;</description>
      <pubDate>Mon, 22 May 2023 14:16:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Automatic-certificate-renewal/m-p/181654#M7827</guid>
      <dc:creator>AS2021</dc:creator>
      <dc:date>2023-05-22T14:16:00Z</dc:date>
    </item>
    <item>
      <title>Re: Automatic certificate renewal</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Automatic-certificate-renewal/m-p/181656#M7828</link>
      <description>&lt;P&gt;NO - at least if you do an upgrade, not fresh install without db import 8)&lt;/img&gt; After Jumbo install, GAiA WebGUI may need a new exception for the self-signed cert in browser, but that is all...&lt;/P&gt;
&lt;P&gt;See &lt;A href="https://support.checkpoint.com/results/sk/sk158096" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;sk158096: How to &lt;STRONG&gt;renew&lt;/STRONG&gt; an Internal Certificate Authority (&lt;STRONG&gt;ICA&lt;/STRONG&gt;) certificate&lt;/SPAN&gt;&lt;/A&gt; for on-purpose renewals - &lt;A href="https://support.checkpoint.com/results/sk/sk164255" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;sk164255: SIC Certificate fails to &lt;STRONG&gt;renew&lt;/STRONG&gt; &lt;STRONG&gt;automatically&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/A&gt; for issues with that!&lt;/P&gt;</description>
      <pubDate>Mon, 22 May 2023 14:56:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Automatic-certificate-renewal/m-p/181656#M7828</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-05-22T14:56:56Z</dc:date>
    </item>
    <item>
      <title>Re: Automatic certificate renewal</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Automatic-certificate-renewal/m-p/181688#M7829</link>
      <description>&lt;P&gt;We now do an automatic renewal of the ICA as of R81.10 JHF 95 (PRJ-44576, PMTR-90463).&lt;BR /&gt;I presume this will also get rolled into other JHF streams.&lt;/P&gt;</description>
      <pubDate>Mon, 22 May 2023 23:36:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Automatic-certificate-renewal/m-p/181688#M7829</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-05-22T23:36:06Z</dc:date>
    </item>
    <item>
      <title>Re: Automatic certificate renewal</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Automatic-certificate-renewal/m-p/198876#M7830</link>
      <description>&lt;P&gt;Is there any planes to auto renew the internal certificates on the gateways they now only have a lifetime on 1 year, and are used with identity collector, vpn and more, and do a renew on +100 gateways takes time.&lt;/P&gt;</description>
      <pubDate>Fri, 24 Nov 2023 15:59:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Automatic-certificate-renewal/m-p/198876#M7830</guid>
      <dc:creator>Soren_Kristense</dc:creator>
      <dc:date>2023-11-24T15:59:36Z</dc:date>
    </item>
    <item>
      <title>Re: Automatic certificate renewal</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Automatic-certificate-renewal/m-p/199015#M7831</link>
      <description>&lt;P&gt;Last I heard, there was a plan to provide an automated mechanism to do this in the near future...&lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2023 13:43:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Automatic-certificate-renewal/m-p/199015#M7831</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-11-27T13:43:09Z</dc:date>
    </item>
    <item>
      <title>Re: Automatic certificate renewal</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Automatic-certificate-renewal/m-p/209710#M7832</link>
      <description>&lt;P&gt;Starting from R81.10, all IKE certificates are valid only for 1 year by default.&lt;/P&gt;
&lt;P&gt;If customer has many FWs used for RA or S2S, where IKE certificate must be valid, it will help if there is some automated way to renew defaultCert automatically (like SIC, InternalCA).&lt;/P&gt;</description>
      <pubDate>Tue, 26 Mar 2024 13:45:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Automatic-certificate-renewal/m-p/209710#M7832</guid>
      <dc:creator>JozkoMrkvicka</dc:creator>
      <dc:date>2024-03-26T13:45:53Z</dc:date>
    </item>
    <item>
      <title>Re: Automatic certificate renewal</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Automatic-certificate-renewal/m-p/210906#M7833</link>
      <description>&lt;P&gt;Hopefully this will get sorted. VPN certificate expiry has caused us pain.&lt;/P&gt;&lt;P&gt;And for one customer who uses SAML, this needs a proper certificate and so far LetsEncrypt isn't available so that's entailed a different manual process!&lt;/P&gt;</description>
      <pubDate>Wed, 10 Apr 2024 08:55:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Automatic-certificate-renewal/m-p/210906#M7833</guid>
      <dc:creator>stallwoodj</dc:creator>
      <dc:date>2024-04-10T08:55:24Z</dc:date>
    </item>
    <item>
      <title>Re: Automatic certificate renewal</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Automatic-certificate-renewal/m-p/210912#M7834</link>
      <description>&lt;P&gt;I keep track of the expire dates in our systems so we get alerted before it expires. Just make a note in a calendar or internal system it is not that difficult. Also when the certificate will expire soon Check Point will give alert at the policy push.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So instead of waiting for Check Point to get it 'sorted' I would recommend to check your own procedures.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Apr 2024 09:19:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Automatic-certificate-renewal/m-p/210912#M7834</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-04-10T09:19:51Z</dc:date>
    </item>
    <item>
      <title>Re: Automatic certificate renewal</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Automatic-certificate-renewal/m-p/211092#M7835</link>
      <description>&lt;P&gt;The script we are planning to make available to manage IKE certificates has an "in progress" SK for the functionality (only visible for Check Point employees).&lt;BR /&gt;Unfortunately, I do not know the timeline for it, though it is expected to be available as part of R82 and backported to R81.x releases via JHF.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Apr 2024 22:23:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Automatic-certificate-renewal/m-p/211092#M7835</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-04-11T22:23:37Z</dc:date>
    </item>
  </channel>
</rss>

