- CheckMates
- :
- Products
- :
- General Topics
- :
- Re: renew IA portal certificate
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
renew IA portal certificate
We need to renew the portal/ia certificate on the gateway, because it is going to expire soon August 30, 2023 (verified by browsing to the firewall), however when we look into the cluster properties and certificate settings window it shows that the certificate had already been expired, which is not the case.
How can we assure that we will replace the correct certificate, should we engage with TAC on this matter?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
maybe i am looking into the wrong place, the certificate we need to update is used by the IA identity agents installed on the laptops so that one need to be renewed, is there a procedure for that one?
ps: i believe when expired that would impact the connection for IA agents to the gateway (TLS handshake not untrusted), but the URL for IA is the same as mentioned in screenshot starting with cpia.
and the current cert is actually from a known CA provider not from Check Point internal CA
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Was it used in setting a 3rd party cert for the portal like here: https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_IdentityAwareness_AdminGuide...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Did you already check "sk106500: How to replace Identity Agent Certificate in the Security Gateway object" ?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I followed sk Chris gave last year with the customer and worked fine.
Have you tried that?
Andy
