- Products
- Learn
- Local User Groups
- Partners
- More
AI Security Masters E7:
How CPR Broke ChatGPT's Isolation and What It Means for You
Blueprint Architecture for Securing
The AI Factory & AI Data Center
Call For Papers
Your Expertise. Our Stage
Good, Better, Best:
Prioritizing Defenses Against Credential Abuse
Ink Dragon: A Major Nation-State Campaign
Watch HereCheckMates Go:
CheckMates Fest
an outage occurred with users being unable to connect via Check Point Mobile which was resolved it by re-fetching the domain controller fingerprints in the LDAP settings. My question is to avoid this issue occurring every year as the certificate renews yearly
- Can Check Point Auto Renew/Pull the certificate fingerprint?
- Can Check Point Warn of alert before expiry to allow for planning / proactive action?
Or, even more simply: Coordinate with LDAP responsible admins to inform Check Point firewall guys and coordinate change of certificate together (task in the change ticket).
I dont believe it can auto renew, but I saw a post indicating it now gives 60 day warning before its supposed to expire, though thats starting with R81.20.
Andy
I believe you can remove the fingerprint in the LDAP Server definition, which will skip this check.
Unfortunately, there is no way to automatically update the fingerprint.
yes, the fingerprint can be left empty. The gateway will accept any fingerprint presented by LDAP/AD. That might be security violation, since there is no way of checking.
That is correct.
As I said, there's no way to automatically check or update the fingerprint.
Pretty certain LDAP Server objects do not have API support either (though maybe you can update via generic-object calls).
API is out of game here, but there must be a way how CP is able to figure out if fingerprint matches or not. Maybe some command like "fwm fingerprint" can be used to check fingerprint from LDAP. If there is some easy way, then some linux bash script can be created (for example to send a mail if fingerprint is changed on LDAP side)
The public key is communicated on first connection with the LDAP server as part of the initial TLS negotiation.
Which means you should be able to employ a technique like the following to obtain the fingerprint: https://askubuntu.com/questions/156620/how-to-verify-the-ssl-fingerprint-by-command-line-wget-curl
(The Check Point binary for openssl is called cpopenssl)
Or, maybe more simply: see if the certificate has changed.
Or, even more simply: Coordinate with LDAP responsible admins to inform Check Point firewall guys and coordinate change of certificate together (task in the change ticket).
Ideally, this is probably the best approach.
Absent that, this points to a way this can be detected in a semi-automated fashion.
Microsoft will do this at it's own convinience sometimes after reaching 80% of it's life time. Preferably friday evening so it will take the longest time to get "resolved".
We have several customer that align with us to do this on a scheduled maintenance window for this particular activity. (Usually right after lunch.)
But the akward thing is that there is now design to validate new certificates based on their CA inside Check Point. Like someone still klings to the old putkey methods for this particular feature and CA's are not to be trusted.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 8 | |
| 8 | |
| 4 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 2 | |
| 2 | |
| 2 |
Tue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementTue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFTue 12 May 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point Cloud Firewall delivered as a serviceThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY