- Products
- Learn
- Local User Groups
- Partners
- More
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Improve Your Security Posture with
Threat Prevention and Policy Insights
Overlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
an outage occurred with users being unable to connect via Check Point Mobile which was resolved it by re-fetching the domain controller fingerprints in the LDAP settings. My question is to avoid this issue occurring every year as the certificate renews yearly
- Can Check Point Auto Renew/Pull the certificate fingerprint?
- Can Check Point Warn of alert before expiry to allow for planning / proactive action?
Or, even more simply: Coordinate with LDAP responsible admins to inform Check Point firewall guys and coordinate change of certificate together (task in the change ticket).
I dont believe it can auto renew, but I saw a post indicating it now gives 60 day warning before its supposed to expire, though thats starting with R81.20.
Andy
I believe you can remove the fingerprint in the LDAP Server definition, which will skip this check.
Unfortunately, there is no way to automatically update the fingerprint.
yes, the fingerprint can be left empty. The gateway will accept any fingerprint presented by LDAP/AD. That might be security violation, since there is no way of checking.
That is correct.
As I said, there's no way to automatically check or update the fingerprint.
Pretty certain LDAP Server objects do not have API support either (though maybe you can update via generic-object calls).
API is out of game here, but there must be a way how CP is able to figure out if fingerprint matches or not. Maybe some command like "fwm fingerprint" can be used to check fingerprint from LDAP. If there is some easy way, then some linux bash script can be created (for example to send a mail if fingerprint is changed on LDAP side)
The public key is communicated on first connection with the LDAP server as part of the initial TLS negotiation.
Which means you should be able to employ a technique like the following to obtain the fingerprint: https://askubuntu.com/questions/156620/how-to-verify-the-ssl-fingerprint-by-command-line-wget-curl
(The Check Point binary for openssl is called cpopenssl)
Or, maybe more simply: see if the certificate has changed.
Or, even more simply: Coordinate with LDAP responsible admins to inform Check Point firewall guys and coordinate change of certificate together (task in the change ticket).
Ideally, this is probably the best approach.
Absent that, this points to a way this can be detected in a semi-automated fashion.
Microsoft will do this at it's own convinience sometimes after reaching 80% of it's life time. Preferably friday evening so it will take the longest time to get "resolved".
We have several customer that align with us to do this on a scheduled maintenance window for this particular activity. (Usually right after lunch.)
But the akward thing is that there is now design to validate new certificates based on their CA inside Check Point. Like someone still klings to the old putkey methods for this particular feature and CA's are not to be trusted.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 23 | |
| 19 | |
| 7 | |
| 5 | |
| 4 | |
| 3 | |
| 2 | |
| 2 | |
| 2 | |
| 2 |
Wed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY