- Products
- Learn
- Local User Groups
- Partners
- More
AI Security Masters E7:
How CPR Broke ChatGPT's Isolation and What It Means for You
Call For Papers
Your Expertise. Our Stage
Good, Better, Best:
Prioritizing Defenses Against Credential Abuse
Ink Dragon: A Major Nation-State Campaign
Watch HereCheckMates Go:
CheckMates Fest
Hello,
I have a customer who would like to change the ICA certificate from containing the SmartCenter IP address to the SmartCenter FQDN.
I have explained that changing the ICA certificate involves additional tasks, such as re-establishing SIC and updating VPN clients, but the customer is aware of this and accepts it.
I am unable to find a procedure for this, has anyone completed such a change successfully and is it supported ?
Best Regards
Brian Hansen
Hello Andy,
It has turned out the the main issue, was related to the SmartCenter and gateways web certificates, so the plan is to replace these with a certificate signed by the internal CA.
Thank you for all replies.
Best Regards
Brian Hansen
Hey Brian,
Im fairly sure you can do this, BUT, catch is you would need to re-initialize ica from cpconfig on mgmt, then reset sic, as sic would be broken to all gateways managed by it.
Hey Brian,
In addition to Andy's comments, I am not sure if you can replace the IP for a FQDN. Is there any security compliance to do it?
I recommend you to read the R81.20 admin guide for management server. There is a command cp_conf ca that allows you to add the FQDN, I'd test it in lab first.
cp_conf ca
Alisson Lima
CCSM Elite
That should work:
[Expert@CP-MANAGEMENT:0]# cp_conf ca
Usage:
cp_conf ca init # Initializes Internal CA
cp_conf ca fqdn <name> # Sets the name of the Internal CA
[Expert@CP-MANAGEMENT:0]#
Hello Andy,
Thank you for replying.
I do not think this will fix my issue. The issue is that the Commonname (CN) of the certificate contains the IP address of the ICA (by default). The command cp_conf ca fqdn <name>, will do the following:
The Management Server uses the specified "<FQDN Name>" to configure the Certificate Revocation List Distribution Point (CRL DP) property in all certificates that the ICA generates.
The existing certificates for configured objects are not revoked.
The existing ICA certificate is not changed.
Best Regards
Brian Hansen
k, fair enough.
ICA is already based on FQDN by default. It's why you can change the IP of your management server without resetting SIC (if you do it right).
Do you not have the FQDN in yours?
Thats true...changing IP would definitely not break SIC.
Hello Emma,
Thank you for replying.
I do not fully understand, what you mean by the ICA is based on FQDN by default. When I check the certificate, the CN is based on the IP of the SmartCenter, by default.
SIC continues to work after SMC IP change, but AutoRenewal of the Certificate will fail, as that is also IP based.
sk103356:
IP Address of the Internal Certificate Authority (ICA) of Security Management Server / Domain Management Server is automatically added to Check Point Registry file ($CPDIR/registry/HKLM_registry.data) on Security Gateway when SIC is first established (between Security Gateway and Management Server).
If the IP Address of a Security Management Server / Domain Management Server is changed, and SIC is never manually reset (between a Security Gateway and a Management Server), then the AutoRenewal of the Certificate will fail.
Hey Brian,
Happy weekend!
Please let us know how this process goes.
Hello Andy,
It has turned out the the main issue, was related to the SmartCenter and gateways web certificates, so the plan is to replace these with a certificate signed by the internal CA.
Thank you for all replies.
Best Regards
Brian Hansen
Glad you got it.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 65 | |
| 25 | |
| 13 | |
| 12 | |
| 12 | |
| 9 | |
| 8 | |
| 8 | |
| 7 | |
| 7 |
Tue 21 Apr 2026 @ 05:00 PM (IDT)
AI Security Masters E7: How CPR Broke ChatGPT's Isolation and What It Means for YouTue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFTue 21 Apr 2026 @ 05:00 PM (IDT)
AI Security Masters E7: How CPR Broke ChatGPT's Isolation and What It Means for YouTue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFTue 12 May 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point Cloud Firewall delivered as a serviceThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY