- Products
- Learn
- Local User Groups
- Partners
- More
Welcome to Maestro Masters!
Talk to Masters, Engage with Masters, Be a Maestro Master!
Join our TechTalk: Malware 2021 to Present Day
Building a Preventative Cyber Program
Be a CloudMate!
Check out our cloud security exclusive space!
Check Point's Cyber Park is Now Open
Let the Games Begin!
As YOU DESERVE THE BEST SECURITY
Upgrade to our latest GA Jumbo
CheckFlix!
All Videos In One Space
Hey Guys. Just need a sanity check. Running R77.30 and our VPN Certificate is showing as using SHA1. I am looking at the SHA-1 and SHA-256 certificates in Check Point Internal CA (ICA) article.
It mentions Resetting SIC. Am I correct in assuming this is only if we wanted to re-generate the SIC certificate using SHA256? If we just simply wanted to re-generate the cert used for VPN this is not needed? So for instance all I would need to do is the following if I just wanted a SHA256 cert for VPN:
1. Run cpca_client set_sign_hash sha256 on the mgmt box
2. Re-generate VPN certificate under each gateway
3. Install policy
Thanks!
I believe you are correct.
The setting applies for NEW certificates generated going forward, not for existing ones.
Note that once you do this, you will not be able to generate new SIC certificates for gateways prior to version R71, which do not support SHA2 hashes.
Thanks! I will give it a shot and hopefully all goes well.
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY