Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Abhishek_Singh1
Contributor
Jump to solution

Extract SMTP TLS certificate from management

Hi Folks ,

 

I have two environments - data-centers . One with MTA enabled on Checkpoint gateway and other without .

Now , I am in a process to enable MTA in the other environment as well . 

However the mail exchange service owners no longer have the private keys of the SMTP/TLS certificate used in my first environment , and I am interested in re-using that SMTP/TLS certificate in our another environment .

 

Is there a way to extract the SMTP/TLS certificate used in the MTA setting of the Gateway ? Does the gateway , or management stores the certificate (.pfx / .pkcs7 / .pkcs12) , from where I can extract these to be re-used in other Gateways ?

0 Kudos
1 Solution

Accepted Solutions
Wolfgang
Authority
Authority

You can find the certificate files here on the gateway:

/opt/postfix/etc/postfix/mta_cert.pem
/opt/postfix/etc/postfix/mta_cert_key.pem

But they are overwritten everytime postfix restarts or after policy install.

Wolfgang

 

View solution in original post

5 Replies
Wolfgang
Authority
Authority

Abhishek,

I think it is not possible to get the complete certificate back. If this will be possible you have security breach, anyone can extract your own certificate.

If you don‘t have the private key and the password, why you don‘t recreate a new certificate with your issuing CA and use this on your environment?

Wolfgang

0 Kudos
PhoneBoy
Admin
Admin
It'd most likely be referred to in one of the Postfix configuration files, e.g.:
/opt/postfix/etc/postfix/master.cf
/opt/postfix/etc/postfix/main.cf
Don't edit these files directly.
See also: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...
0 Kudos
Wolfgang
Authority
Authority

You can find the certificate files here on the gateway:

/opt/postfix/etc/postfix/mta_cert.pem
/opt/postfix/etc/postfix/mta_cert_key.pem

But they are overwritten everytime postfix restarts or after policy install.

Wolfgang

 

PhoneBoy
Admin
Admin
I assume the content of the certificates won't change unless you actually change it in SmartConsole.
That said, I would expect it would get rewritten on each policy install.
0 Kudos
Abhishek_Singh1
Contributor
Yes , thats correct . Same cert gets installed/re-written on each policy install 🙂
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events