cancel
Showing results for 
Search instead for 
Did you mean: 
Create a Post
Highlighted
Vladimir
Pearl

UserCheck portal using Certificate not created for HTTPS inspection

Jump to solution

For the gateway configured to perform HTTPS inspection, with certificate created and distributed to clients, normal traffic behaves as expected:

But when UserCheck is encountered in the rulebase, the gateway serving its VPN certificate:

Which, as it happens, was not distributed to internal hosts.

Is there a way to address it properly?

1 Solution

Accepted Solutions

Re: UserCheck portal using Certificate not created for HTTPS inspection

Jump to solution

Yes, on the cluster/gateway properties under UserCheck you can enter the FQDN for UserCheck Portal and import a proper certificate matching it.

For sure FQDN must be resolvable to Cluster/Gateway IP.

View solution in original post

5 Replies

Re: UserCheck portal using Certificate not created for HTTPS inspection

Jump to solution

Yes, on the cluster/gateway properties under UserCheck you can enter the FQDN for UserCheck Portal and import a proper certificate matching it.

For sure FQDN must be resolvable to Cluster/Gateway IP.

View solution in original post

Admin
Admin

Re: UserCheck portal using Certificate not created for HTTPS inspection

Jump to solution

Just to clarify, the UserCheck portal serves it's own certificate that is not subject to HTTPS Inspection (if I recall correctly).

Thus that certificate needs to be correct/something the client is configured to accept.

It would definitely be better if we could leverage the HTTPS Inspection CA in this case Smiley Happy

Vladimir
Pearl

Re: UserCheck portal using Certificate not created for HTTPS inspection

Jump to solution

Agree with you on idea of using same cert for multiple purposes. It would actually be nice if the CA on SMS would've been a bit more functional with good front end. Some environments do not have PKI in place and could've used Check Point for this purpose.

0 Kudos
Admin
Admin

Re: UserCheck portal using Certificate not created for HTTPS inspection

Jump to solution

The front end of the Internal CA is called SmartConsole Smiley Happy

Granted, it's not meant as a full CA but for specific functionality, which could potentially be expanded.

0 Kudos
Vladimir
Pearl

Re: UserCheck portal using Certificate not created for HTTPS inspection

Jump to solution

Smiley Happy good one

0 Kudos