<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Machine Auth via Certificate Not Working in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Machine-Auth-via-Certificate-Not-Working/m-p/129731#M8124</link>
    <description>&lt;P&gt;Problem was solved with&amp;nbsp;&lt;SPAN&gt;sk175111.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 20 Sep 2021 02:48:48 GMT</pubDate>
    <dc:creator>Rajan_Pradhan</dc:creator>
    <dc:date>2021-09-20T02:48:48Z</dc:date>
    <item>
      <title>Machine Auth via Certificate Not Working</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Machine-Auth-via-Certificate-Not-Working/m-p/128118#M8121</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;I have client version 85.2, trying to configure machine certificate authentication. SMC and gateway is R80.40. I cannot get it to authenticate, client errors with "negotiation with site failed". Trac.log shows the telling below errors, however when I check the SMC the root CA is definitely installed there correctly. and the second log below shows the matching DN, so the client does seem to trying to macth the right cert. Ive tried different client versions, replacing client certificates, reinstalling root CA, running out of ideas. ANy help appreciated!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[ 5356 10308][26 Aug 21:55:53][RaisCertManager] RaisCertManager::CertManager::GetCertByName: Can't retrieve the Root CA for the cert.&lt;BR /&gt;[ 5356 10308][26 Aug 21:55:53][RaisCertManager] RaisCertManager::CertManager::GetCertByName: temp_cert is null!! =&amp;gt; No cert was found with the given cert_name= [CN=XXX,O=XXX,L=XXX,ST=XX,C=XX;O=XXX.f97wmb]&lt;BR /&gt;[&lt;/P&gt;</description>
      <pubDate>Thu, 26 Aug 2021 14:22:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Machine-Auth-via-Certificate-Not-Working/m-p/128118#M8121</guid>
      <dc:creator>Rajan_Pradhan</dc:creator>
      <dc:date>2021-08-26T14:22:59Z</dc:date>
    </item>
    <item>
      <title>Re: Machine Auth via Certificate Not Working</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Machine-Auth-via-Certificate-Not-Working/m-p/128143#M8122</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;What's in the Subject field of the machine certificate, note it cannot be empty?&lt;/P&gt;</description>
      <pubDate>Thu, 26 Aug 2021 15:37:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Machine-Auth-via-Certificate-Not-Working/m-p/128143#M8122</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2021-08-26T15:37:23Z</dc:date>
    </item>
    <item>
      <title>Re: Machine Auth via Certificate Not Working</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Machine-Auth-via-Certificate-Not-Working/m-p/128190#M8123</link>
      <description>&lt;P&gt;Hi Chris! Thanks so much for your response. Yes, by default autoenrolled machine certificates have a blank subject. However I have manually created a new cert with FQDN in the subject, which made no difference to the issue. &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Aug 2021 03:15:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Machine-Auth-via-Certificate-Not-Working/m-p/128190#M8123</guid>
      <dc:creator>Rajan_Pradhan</dc:creator>
      <dc:date>2021-08-27T03:15:24Z</dc:date>
    </item>
    <item>
      <title>Re: Machine Auth via Certificate Not Working</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Machine-Auth-via-Certificate-Not-Working/m-p/129731#M8124</link>
      <description>&lt;P&gt;Problem was solved with&amp;nbsp;&lt;SPAN&gt;sk175111.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Sep 2021 02:48:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Machine-Auth-via-Certificate-Not-Working/m-p/129731#M8124</guid>
      <dc:creator>Rajan_Pradhan</dc:creator>
      <dc:date>2021-09-20T02:48:48Z</dc:date>
    </item>
  </channel>
</rss>

