I am changing the size of the RSA Key 2048 to 4096 to Client VPN because I have a customer who did a vulnerability scan and they indicated that the RSA Key of the certificate of the public ip with which the users are authenticated by VPN with Endpoint Security is vulnerable in 2048 bits so the procedure of sk96591 was performed in the section “VPN Certificate, User Certificate, Client Certificate”.
https://support.checkpoint.com/results/sk/sk96591
I got stuck on the last part that says “Generate the VPN / User / Client Certificate again”.
At first I thought it was the “ipsec VPN” certificate but validating the certificate I had a Public RSA Key of 1024 bits but in the ica management tool I found that it was configured by default 2048, this made me suspect that this is not the certificate that I should renew or generate again.
Could someone tell me what is the exact certificate that is used for the remote VPN's of the users. The users are authenticated by username and password not by certificate, the certificate is only for the authentication of the VPN communication.
I tried to renew the “Ipsec VPN” certificate but when I renewed it I still got 1024, additionally this does not match with the configuration in the Ica Management Tool that had 2048.
In case I have to generate the certificate in the Ica Management Tool, where do I import it?