- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
We are exploring the vast wonders of the R80.30 API commands and would like to expand further but have some security concerns. What we need is a way to make API calls (that does more than read) and not have to hard code the credentials into the call itself.
Is there some type of API key that can be used for this type of work or some other method we can use to encrypt this? A fear is that if the box is compromised, then a bad actor could just crack open the content and have some real fun, or possibly even sniff the credentials while we are making a call.
Thanks,
Patrick
What we need is a way to make API calls (that does more than read) and not have to hard code the credentials into the call itself.
Are you using the username and password for each command run? If so, then I would recommend starting each session by with login command and then referencing the sid that is created on a successful login. This would prevent each call requiring a username/password scenario.
Support for using an API key is available in the newly released R80.40
- https://sc1.checkpoint.com/documents/latest/APIs/index.html#cli/add-api-key~v1.6
It might be possible to use certificate authentication for your API calls if you're using the mgmt_cli command. There is an option to use a client certificate (-c ), however I don't know how this would work when using a POST from curl, python, etc. Unfortunately, it would still require knowing the certificate password and supplying it as a part of the script.
I'm not aware of an option to lock-down users to specific hosts. There are some restrictions in the Management API settings that might help, but they are probably not as granular as you would like to see.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 4 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY