- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi All,
I need to integrate LDAP over SSL with my Checkpoint SmartEndpoint. I'm trying to import the SSL certificate and facing the following error: "An Error has occurred while importing the certificate. Internal Error.."
The certificate is in .pem format.
What can be potential cause for this error? How do I solve it?
If it is possible, can I get the commands to import the certificate from CLI expert mode, please?
I've also imported the CA certificate of the LDAP server. No issues with that.
*Attached Server Logs*
Thank you.
Endpoint Management Harmony Endpoint Quantum Security Management
I suggest you follow the steps outlined in the Harmony Endpoint server administration guide https://sc1.checkpoint.com/documents/R81.10/SmartEndpoint_OLH/EN/Topics-EPSG-R81.10/DirectoryScanner...
The relevant steps will be from step 6. onward at the bottom of the article. You should use the keytool program to establish trust.
To obtain the TLS/SSL certificate from the domain controller I find it easiest to perform the following command on the EP MGMT server in Expert mode.
cpopenssl s_client -connect domain.contoller:636 | cpopenssl x509 > LDAPScert.cer
Thank you for the guide.
I followed the same steps as there are in the document from downloading the certificate from DC and importing it to the Endpoint Security Server. But still I'm encountering the same error "SSL certificate is not installed" when I try to integrate the AD server with SmartEndpoint.
cpopenssl s_client -connect domain.contoller:636 | cpopenssl x509 > LDAPScert.cer
And the above command keeps on running without a output.
I assume you've corrected the "domain.contoller:636" to the hostname of the domain controller you're binding extracting the SSL certificate from?
@Swiftyyyy wrote:I assume you've corrected the "domain.contoller:636" to the hostname of the domain controller you're binding extracting the SSL certificate from?
Off course yes. I have.
Could you try without the redirect at the end? So without writing into a file.
This way you should see the raw output of the certificate being shown. Note that to finish writing the certificate into the file, you would have to press "Enter" at some point to "close" the SSL CONNECT session.
Assuming you just hang without output at this command; I'd suggest verifying your Endpoint server can even reach your directory server over port 636.
cpopenssl s_client -connect domain.controller:636 | cpopenssl x509
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 8 | |
| 4 | |
| 2 | |
| 2 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY