<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can we import PFX files through smartconsole in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Can-we-import-PFX-files-through-smartconsole/m-p/131228#M7927</link>
    <description>&lt;P&gt;Yes you can &amp;nbsp;8)&lt;/img&gt;&amp;nbsp;See&amp;nbsp;&amp;nbsp;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk69660&amp;amp;partition=Advanced&amp;amp;product=Mobile" target="_blank"&gt;sk69660: How to generate Server Certificate Signing Request (CSR) and import the new 3rd Party certificate to Mobile Access Blade&lt;/A&gt;:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Note: &lt;/STRONG&gt;&lt;SPAN&gt;if you receive a .pfx file, rename the file extension from .pfx to .p12 and move to Stage 3 of this document&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;But this will not spare you to send the CSR file to a trusted certificate authority and&amp;nbsp;request a Signed Certificate in PEM format.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 07 Oct 2021 07:50:58 GMT</pubDate>
    <dc:creator>G_W_Albrecht</dc:creator>
    <dc:date>2021-10-07T07:50:58Z</dc:date>
    <item>
      <title>Can we import PFX files through smartconsole</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Can-we-import-PFX-files-through-smartconsole/m-p/131198#M7926</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;this is just a general question and not relating to a current or specific issue. But the process of adding a CA signed SSL cert to the gateway is rather cumbersome for SSL VPN remote access gateway.&lt;/P&gt;
&lt;P&gt;Current procedure is&lt;/P&gt;
&lt;P&gt;- create the CA root certificate as a trusted CA on the gateway&lt;/P&gt;
&lt;P&gt;- create the CA intermediate certificate as a trusted subordinate on the gateway&lt;/P&gt;
&lt;P&gt;- generate a CSR through SmartConsole and select the intermediate certificate you created in step 2&lt;/P&gt;
&lt;P&gt;- complete the certificate by installing the signed certifcated and hope and pray they have signed it using the same root cert you created the csr against else it will fail to bind and if so the only way around it to is generate a new csr and get it signed again.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Would seem a lot easier if the Smartconsole had an option to import a pfx, so we can create a csr and private key through any means we prefer (openssl or even cpopenssl) get it signed, bundle the private key, signed cert and chain together as pfx and upload it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I know cpopenssl has some import options but I don't think it would allow us to import a cert and have it visible in the console for use.&lt;/P&gt;
&lt;DIV id="tinyMceEditorRyan_Ryan_0" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV id="tinyMceEditorRyan_Ryan_1" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Oct 2021 04:20:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Can-we-import-PFX-files-through-smartconsole/m-p/131198#M7926</guid>
      <dc:creator>Ryan_Ryan</dc:creator>
      <dc:date>2021-10-07T04:20:42Z</dc:date>
    </item>
    <item>
      <title>Re: Can we import PFX files through smartconsole</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Can-we-import-PFX-files-through-smartconsole/m-p/131228#M7927</link>
      <description>&lt;P&gt;Yes you can &amp;nbsp;8)&lt;/img&gt;&amp;nbsp;See&amp;nbsp;&amp;nbsp;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk69660&amp;amp;partition=Advanced&amp;amp;product=Mobile" target="_blank"&gt;sk69660: How to generate Server Certificate Signing Request (CSR) and import the new 3rd Party certificate to Mobile Access Blade&lt;/A&gt;:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Note: &lt;/STRONG&gt;&lt;SPAN&gt;if you receive a .pfx file, rename the file extension from .pfx to .p12 and move to Stage 3 of this document&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;But this will not spare you to send the CSR file to a trusted certificate authority and&amp;nbsp;request a Signed Certificate in PEM format.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Oct 2021 07:50:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Can-we-import-PFX-files-through-smartconsole/m-p/131228#M7927</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2021-10-07T07:50:58Z</dc:date>
    </item>
    <item>
      <title>Re: Can we import PFX files through smartconsole</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Can-we-import-PFX-files-through-smartconsole/m-p/131325#M7928</link>
      <description>&lt;P&gt;Thanks for the reply, I did see that article, but interesting point on our gateway we do not even have Mobile Access gateway blade enabled. if you see the attachment in the original post that is where we apply the vpn certificate, (we are doing remote Access VPN in the IPsec config)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;cheers&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Oct 2021 20:49:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Can-we-import-PFX-files-through-smartconsole/m-p/131325#M7928</guid>
      <dc:creator>Ryan_Ryan</dc:creator>
      <dc:date>2021-10-07T20:49:52Z</dc:date>
    </item>
    <item>
      <title>Re: Can we import PFX files through smartconsole</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Can-we-import-PFX-files-through-smartconsole/m-p/131340#M7929</link>
      <description>&lt;P&gt;You did talk about SSL VPN - this is from MAB Blade, other is IPSec VPN...&lt;/P&gt;</description>
      <pubDate>Fri, 08 Oct 2021 07:02:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Can-we-import-PFX-files-through-smartconsole/m-p/131340#M7929</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2021-10-08T07:02:25Z</dc:date>
    </item>
    <item>
      <title>Re: Can we import PFX files through smartconsole</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Can-we-import-PFX-files-through-smartconsole/m-p/131361#M7930</link>
      <description>&lt;P&gt;Günther: I guess you know it already, but for all other people reading here: Depending on if you are using modern or legacy licences for your Remote Access VPN, you usually use Mobile Access or IPsec VPN blade. Even if your are only having IPsec VPN blade installed, you are still able to do SSL VPN in terms of Endpoint Security VPN in Visitor Mode, SSL Network Extender and so on. Of course you cannot use Mobile Access Portal without Mobile Access blade.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Ryan, in case you are running Remote Access VPN on a gateway which has only IPsec VPN blade installed, may I ask you which kind of Remote Access (Client) you are using against that gateway?&lt;/P&gt;
&lt;P&gt;I'm asking because the environments I know which are operated this way (with Endpoint Security VPN as client), never needed to change the actual VPN certificate in the dialog in your screenshot but change the certificate the Multiportal Deamon is using for the SSL VPN endpoint, e.g. in using the Platform Portal dialog.&lt;/P&gt;
&lt;P&gt;Reason: in trac.conf on EPS client, there are two fingerprints:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&amp;lt;PARAM ccc_fingerprint="WHATEVER1"&amp;gt;&amp;lt;/PARAM&amp;gt;
&lt;UL&gt;
&lt;LI&gt;This is the RfC#1751 encoded representation of the SHA-1 fingerprint of the Root-CA of the certificate added via SmartConsole -&amp;gt; Platform Portal.&lt;/LI&gt;
&lt;LI&gt;Changing this certificate on gateway results in a popup on user side asking for trusting the new fingerprint&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;&amp;lt;PARAM internal_ca_fingerprint="WHATEVER2"&amp;gt;&amp;lt;/PARAM&amp;gt;
&lt;UL&gt;
&lt;LI&gt;This is the RfC#1751 encoded representation of the SHA-1 Fingerprints of the certificate added via SmartConsole -&amp;gt; IPSec-VPN.&lt;/LI&gt;
&lt;LI&gt;Changing this certificate on gateway does NOT result in a popup on user side asking for trusting the new fingerprint&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;This is what I saw in my environments. There is another thread here on CheckMates where another customer is reporting that ccc_fingerprint is intermediate and not root in his case. He and I double checked it on our sides and we did not understand the difference yet, so please check on your side before trusting me or him &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Leaving that aside, I agree to you that changing the VPN certificate in IPSec VPN dialog is really hard due to the process you described.&lt;/P&gt;</description>
      <pubDate>Fri, 08 Oct 2021 11:53:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Can-we-import-PFX-files-through-smartconsole/m-p/131361#M7930</guid>
      <dc:creator>Tobias_Moritz</dc:creator>
      <dc:date>2021-10-08T11:53:29Z</dc:date>
    </item>
    <item>
      <title>Re: Can we import PFX files through smartconsole</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Can-we-import-PFX-files-through-smartconsole/m-p/131363#M7931</link>
      <description>&lt;P&gt;You are completely correct ! Anyway - in the MAB&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk69660&amp;amp;partition=Advanced&amp;amp;product=Mobile" target="_blank" rel="noopener noreferrer"&gt;sk69660&lt;/A&gt;&amp;nbsp;it is also a complicated process and not much shorter...&lt;/P&gt;</description>
      <pubDate>Fri, 08 Oct 2021 12:16:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Can-we-import-PFX-files-through-smartconsole/m-p/131363#M7931</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2021-10-08T12:16:12Z</dc:date>
    </item>
    <item>
      <title>Re: Can we import PFX files through smartconsole</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Can-we-import-PFX-files-through-smartconsole/m-p/131435#M7932</link>
      <description>&lt;P&gt;Hi Tobias, thanks for the detailed reply.&lt;/P&gt;
&lt;P&gt;I should have mentioned in the screenshot I have shown, I had already deleted my expired cert before replacing the new cert, I agree the default cert doesn't need to be renewed ever but that is the same place we have our real cert vpn.example.com aswell.&lt;/P&gt;
&lt;P&gt;The clients use the old style SSL Extender, so they just browse to the gateway public ip, login and they get an SSL tunnel.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It is possible the cert could be changed through multiportal rather than the gui interface, I had not thought of that might try that next time.&lt;/P&gt;
&lt;P&gt;Your customer may have run into the same issue we did a year back, sometimes you need to generate the csr against the intermediate, and sometimes against the root depending on the signer (sk149253 - uses intermediate).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The other issue you can run into is, you cannot have two certs with the same DN, so when your cert comes up for expiry you need to do this in this order - delete your current cert, generate csr and install the signed cert. (assuming using the same root authority, else import their root/interm certs)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Oct 2021 22:49:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Can-we-import-PFX-files-through-smartconsole/m-p/131435#M7932</guid>
      <dc:creator>Ryan_Ryan</dc:creator>
      <dc:date>2021-10-10T22:49:43Z</dc:date>
    </item>
  </channel>
</rss>

