<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Certificate Authentication for Remote Access VPN user in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Certificate-Authentication-for-Remote-Access-VPN-user/m-p/114994#M9031</link>
    <description>&lt;P&gt;I don't understand this question?&lt;/P&gt;
&lt;P&gt;Can you post a sample Subject or SAN and tell me which part of it you want to use for finding the user in LDAP?&lt;/P&gt;</description>
    <pubDate>Wed, 31 Mar 2021 05:55:45 GMT</pubDate>
    <dc:creator>Norbert_Bohusch</dc:creator>
    <dc:date>2021-03-31T05:55:45Z</dc:date>
    <item>
      <title>Certificate Authentication for Remote Access VPN user</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Certificate-Authentication-for-Remote-Access-VPN-user/m-p/113839#M9019</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;We have configured personal certificate as First factor and Radius as second factor authentication.&lt;/P&gt;&lt;P&gt;In personal certificate authentication, the firewall will check for the DN(correct me if I am wrong),can we make it to check only CN instead of DN.&lt;/P&gt;&lt;P&gt;Second query is that the user is having multiple certificates, so in that case how Check Point will match the exact certificate&amp;nbsp; if there are two VPN certificate with two different templates?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Mar 2021 16:54:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Certificate-Authentication-for-Remote-Access-VPN-user/m-p/113839#M9019</guid>
      <dc:creator>Nagaraja</dc:creator>
      <dc:date>2021-03-17T16:54:03Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate Authentication for Remote Access VPN user</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Certificate-Authentication-for-Remote-Access-VPN-user/m-p/113860#M9020</link>
      <description>&lt;P&gt;I believe it only checks DN. Your 2nd inquiry, are you referring to just a specific user cert here?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 17 Mar 2021 21:57:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Certificate-Authentication-for-Remote-Access-VPN-user/m-p/113860#M9020</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-03-17T21:57:58Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate Authentication for Remote Access VPN user</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Certificate-Authentication-for-Remote-Access-VPN-user/m-p/113861#M9021</link>
      <description>&lt;P&gt;As far as I know, what we check in the cert is hard coded and can't be changed.&lt;BR /&gt;For the second question, it depends on what kind of a certificate we're talking about.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;For a user-specific certificate, I believe the user chooses what certificate to offer.&lt;/LI&gt;
&lt;LI&gt;For a machine certificate, we use the most recent one, I believe (and that's hardcoded).&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Wed, 17 Mar 2021 22:06:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Certificate-Authentication-for-Remote-Access-VPN-user/m-p/113861#M9021</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-03-17T22:06:54Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate Authentication for Remote Access VPN user</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Certificate-Authentication-for-Remote-Access-VPN-user/m-p/113920#M9022</link>
      <description>&lt;P&gt;Yes, it is user certificate&lt;/P&gt;</description>
      <pubDate>Thu, 18 Mar 2021 11:40:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Certificate-Authentication-for-Remote-Access-VPN-user/m-p/113920#M9022</guid>
      <dc:creator>Nagaraja</dc:creator>
      <dc:date>2021-03-18T11:40:26Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate Authentication for Remote Access VPN user</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Certificate-Authentication-for-Remote-Access-VPN-user/m-p/113922#M9023</link>
      <description>&lt;P&gt;Hi Phoneboy,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the information.&lt;/P&gt;&lt;P&gt;Is there any supporting document which says that we can't change the configuration to check CN instead of DN.&lt;/P&gt;&lt;P&gt;Any article which says that it will use the latest certificate if it is machine certificate.&lt;/P&gt;&lt;P&gt;We are using user based certificate&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Mar 2021 11:44:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Certificate-Authentication-for-Remote-Access-VPN-user/m-p/113922#M9023</guid>
      <dc:creator>Nagaraja</dc:creator>
      <dc:date>2021-03-18T11:44:46Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate Authentication for Remote Access VPN user</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Certificate-Authentication-for-Remote-Access-VPN-user/m-p/113948#M9024</link>
      <description>&lt;P&gt;Hi Phoneboy,&lt;/P&gt;&lt;P&gt;We are using user based certificate and there are multiple certificates(eg. includes expired cert aslo) in user machine.&lt;/P&gt;&lt;P&gt;Why Check Point is not able to pick the valid certificate ? User is not aware of the valid/expired certificates.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Mar 2021 14:09:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Certificate-Authentication-for-Remote-Access-VPN-user/m-p/113948#M9024</guid>
      <dc:creator>Nagaraja</dc:creator>
      <dc:date>2021-03-18T14:09:45Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate Authentication for Remote Access VPN user</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Certificate-Authentication-for-Remote-Access-VPN-user/m-p/114566#M9025</link>
      <description>&lt;P&gt;Hi Phoneboy,&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;For a user-specific certificate, I believe the user chooses what certificate to offer - Can We configure this on gateway end to select the certificate automatically instead of user selecting the certificate manually.&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Thu, 25 Mar 2021 10:32:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Certificate-Authentication-for-Remote-Access-VPN-user/m-p/114566#M9025</guid>
      <dc:creator>Nagaraja</dc:creator>
      <dc:date>2021-03-25T10:32:19Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate Authentication for Remote Access VPN user</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Certificate-Authentication-for-Remote-Access-VPN-user/m-p/114580#M9026</link>
      <description>&lt;P&gt;You can change what is taken from the certificate for matching it against the user base (LDAP or local).&lt;/P&gt;
&lt;P&gt;Before R80.x it was a bit of a pain to configure through GuiDBedit, but since R80.10 you can select it when configuration Multiple Login Options:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_RemoteAccessVPN_AdminGuide/Topics-VPNRG/User-and-Client-Authentication.htm?tocpath=User%20and%20Client%20Authentication%20for%20Remote%20Access%7C_____0#Multiple_Login_Options_for_R80.xx_Gateways" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_RemoteAccessVPN_AdminGuide/Topics-VPNRG/User-and-Client-Authentication.htm?tocpath=User%20and%20Client%20Authentication%20for%20Remote%20Access%7C_____0#Multiple_Login_Options_for_R80.xx_Gateways&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;See chapter:&amp;nbsp; Certificate Parsing&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Besides the "Fetch username from" setting as described, you will have to match the "search LDAP for", so it can find it.&lt;/P&gt;
&lt;P&gt;So you can even go for CN, SAN.email, SAN.UPN, etc...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Btw. I configured this on R77.10 already but not that comfortable &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Mar 2021 10:59:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Certificate-Authentication-for-Remote-Access-VPN-user/m-p/114580#M9026</guid>
      <dc:creator>Norbert_Bohusch</dc:creator>
      <dc:date>2021-03-25T10:59:44Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate Authentication for Remote Access VPN user</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Certificate-Authentication-for-Remote-Access-VPN-user/m-p/114859#M9027</link>
      <description>&lt;P&gt;Hi Norbert,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There is no option to configure only CN validation check.&lt;/P&gt;&lt;P&gt;We can configure DN.CN,it seems like this is 'AND' operation not 'OR' operation.&lt;/P&gt;&lt;P&gt;Attaching the screenshot for your reference.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Mar 2021 09:30:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Certificate-Authentication-for-Remote-Access-VPN-user/m-p/114859#M9027</guid>
      <dc:creator>Nagaraja</dc:creator>
      <dc:date>2021-03-29T09:30:48Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate Authentication for Remote Access VPN user</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Certificate-Authentication-for-Remote-Access-VPN-user/m-p/114933#M9028</link>
      <description>&lt;P&gt;DN.CN means the CN part of the DN.&lt;/P&gt;
&lt;P&gt;A certificate has always CN as part of DN... So exactly what you asked.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I don‘t understand the and/or part of your answer?!&lt;/P&gt;</description>
      <pubDate>Tue, 30 Mar 2021 10:04:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Certificate-Authentication-for-Remote-Access-VPN-user/m-p/114933#M9028</guid>
      <dc:creator>Norbert_Bohusch</dc:creator>
      <dc:date>2021-03-30T10:04:13Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate Authentication for Remote Access VPN user</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Certificate-Authentication-for-Remote-Access-VPN-user/m-p/114934#M9029</link>
      <description>&lt;P&gt;Hi Norbert,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We don't want to validate DN.&lt;/P&gt;&lt;P&gt;We need to validate only CN.&lt;/P&gt;&lt;P&gt;Is that possible ?&lt;/P&gt;</description>
      <pubDate>Tue, 30 Mar 2021 11:12:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Certificate-Authentication-for-Remote-Access-VPN-user/m-p/114934#M9029</guid>
      <dc:creator>Nagaraja</dc:creator>
      <dc:date>2021-03-30T11:12:55Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate Authentication for Remote Access VPN user</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Certificate-Authentication-for-Remote-Access-VPN-user/m-p/114979#M9030</link>
      <description>&lt;P&gt;You can try Custom Fields, otherwise I assume this would be an RFE.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Mar 2021 22:44:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Certificate-Authentication-for-Remote-Access-VPN-user/m-p/114979#M9030</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-03-30T22:44:52Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate Authentication for Remote Access VPN user</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Certificate-Authentication-for-Remote-Access-VPN-user/m-p/114994#M9031</link>
      <description>&lt;P&gt;I don't understand this question?&lt;/P&gt;
&lt;P&gt;Can you post a sample Subject or SAN and tell me which part of it you want to use for finding the user in LDAP?&lt;/P&gt;</description>
      <pubDate>Wed, 31 Mar 2021 05:55:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Certificate-Authentication-for-Remote-Access-VPN-user/m-p/114994#M9031</guid>
      <dc:creator>Norbert_Bohusch</dc:creator>
      <dc:date>2021-03-31T05:55:45Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate Authentication for Remote Access VPN user</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Certificate-Authentication-for-Remote-Access-VPN-user/m-p/174491#M9032</link>
      <description>&lt;P&gt;Hello Phoneboy,&lt;/P&gt;
&lt;P&gt;I have a&amp;nbsp; question about user authentication when user/pass + user certificate is configured: did the user need to select the certificate every time he connects to vpn or the vpn client automatically recognize the certs from repository?&lt;/P&gt;
&lt;P&gt;Thanks a lot&lt;/P&gt;</description>
      <pubDate>Sun, 12 Mar 2023 21:08:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Certificate-Authentication-for-Remote-Access-VPN-user/m-p/174491#M9032</guid>
      <dc:creator>CheckPointerXL</dc:creator>
      <dc:date>2023-03-12T21:08:19Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate Authentication for Remote Access VPN user</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Certificate-Authentication-for-Remote-Access-VPN-user/m-p/174615#M9033</link>
      <description>&lt;P&gt;I believe the first time you need to specify the certificate.&lt;BR /&gt;After that, the certificate should be reused.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Mar 2023 16:24:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Certificate-Authentication-for-Remote-Access-VPN-user/m-p/174615#M9033</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-03-13T16:24:28Z</dc:date>
    </item>
  </channel>
</rss>

