- Products
- Learn
- Local User Groups
- Partners
- More
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Improve Your Security Posture with
Threat Prevention and Policy Insights
Overlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
I encountered a problem today connecting a spark to a central management server in that the SIC one time password that i'd set on the management server contained a question mark, and that caused a problem when trying to use it in CLI commands.
(maybe using a password generator wasn't such a good idea, and keeping it simple would be better)
However, this got me thinking, is there a definition for the requirement of the SIC one time password, as far as, how many characters, what mix is required and importantly what characters are not allowed?
I don't recall seeing one, and searching this evening hasn't turned up anything, so I was wondering if anyone else is aware of a definition?
As far as I know there is no minimal requirement. SIC is a one thing only, when SIC is set certificates are used for communication.
Why the question mark did not work I am not sure could be a bug (would recommend to check the version you have installed).
Could also be user error (no offense) so if someone could reproduce it is worth checking and report as bug.
It's probably not a bug. BASH treats the question mark character as a one-character wildcard in file names. To get it to treat the question mark literally, you need to either escape it with a backslash (not ideal, since then you might need to escape the backslash as well at some point) or enclose the whole string in ticks (technically prime marks, also called commonly called single-quotes).
would be solved them if you perform SIC reset via web interface of the firewall 😉
GAIA embedded I always reset via web interface
Yes, this is why the question mark didn't work for me!
The SIC password is only used once: when trust is established to the management.
It does not need to be complex (i.e. containing "special characters") but you can make it long.
This is a particularly a good idea if you're deploying gateways automatically with cloud-init (relevant for CloudGuard Network instances).
How long the password can be...not entirely sure.
I know some people may disagree when I say this, but honestly, I always say to people you can easily use 1234 for SIC password, since its one-time password needed AND, on top of that, its encrypted, so really no need to be complex. I am fairly certain minimum is 4 characters, not sure about max length though.
Andy
Like you, I would normally use a simple password for SIC, but the password policy is very strict on this site so I tried to conform to that and it bit me!
Lesson learned, but the reason for this post was to see if there was actually a definition of what the SIC password must / must not contain, as I couldn't find anything.
Most likely the reason this isn't documented is because this issue hasn't come up before, given the one-time nature of SIC passwords.
And dont forget this useful sk:
https://support.checkpoint.com/results/sk/sk109148
Akos
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 15 | |
| 10 | |
| 8 | |
| 6 | |
| 5 | |
| 5 | |
| 4 | |
| 4 | |
| 4 | |
| 3 |
Wed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY