cancel
Showing results for 
Search instead for 
Did you mean: 
Create a Post
Highlighted

Extract SMTP TLS certificate from management

Jump to solution

Hi Folks ,

 

I have two environments - data-centers . One with MTA enabled on Checkpoint gateway and other without .

Now , I am in a process to enable MTA in the other environment as well . 

However the mail exchange service owners no longer have the private keys of the SMTP/TLS certificate used in my first environment , and I am interested in re-using that SMTP/TLS certificate in our another environment .

 

Is there a way to extract the SMTP/TLS certificate used in the MTA setting of the Gateway ? Does the gateway , or management stores the certificate (.pfx / .pkcs7 / .pkcs12) , from where I can extract these to be re-used in other Gateways ?

0 Kudos
1 Solution

Accepted Solutions
Wolfgang
Silver

Re: Extract SMTP TLS certificate from management

Jump to solution

You can find the certificate files here on the gateway:

/opt/postfix/etc/postfix/mta_cert.pem
/opt/postfix/etc/postfix/mta_cert_key.pem

But they are overwritten everytime postfix restarts or after policy install.

Wolfgang

 

5 Replies
Wolfgang
Silver

Re: Extract SMTP TLS certificate from management

Jump to solution

Abhishek,

I think it is not possible to get the complete certificate back. If this will be possible you have security breach, anyone can extract your own certificate.

If you don‘t have the private key and the password, why you don‘t recreate a new certificate with your issuing CA and use this on your environment?

Wolfgang

0 Kudos
Admin
Admin

Re: Extract SMTP TLS certificate from management

Jump to solution
It'd most likely be referred to in one of the Postfix configuration files, e.g.:
/opt/postfix/etc/postfix/master.cf
/opt/postfix/etc/postfix/main.cf
Don't edit these files directly.
See also: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...
0 Kudos
Wolfgang
Silver

Re: Extract SMTP TLS certificate from management

Jump to solution

You can find the certificate files here on the gateway:

/opt/postfix/etc/postfix/mta_cert.pem
/opt/postfix/etc/postfix/mta_cert_key.pem

But they are overwritten everytime postfix restarts or after policy install.

Wolfgang

 

Admin
Admin

Re: Extract SMTP TLS certificate from management

Jump to solution
I assume the content of the certificates won't change unless you actually change it in SmartConsole.
That said, I would expect it would get rewritten on each policy install.
0 Kudos

Re: Extract SMTP TLS certificate from management

Jump to solution
Yes , thats correct . Same cert gets installed/re-written on each policy install 🙂
0 Kudos