- CheckMates
- :
- Products
- :
- Quantum
- :
- Management
- :
- UserCheck portal using Certificate not created for...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
UserCheck portal using Certificate not created for HTTPS inspection
For the gateway configured to perform HTTPS inspection, with certificate created and distributed to clients, normal traffic behaves as expected:
But when UserCheck is encountered in the rulebase, the gateway serving its VPN certificate:
Which, as it happens, was not distributed to internal hosts.
Is there a way to address it properly?
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes, on the cluster/gateway properties under UserCheck you can enter the FQDN for UserCheck Portal and import a proper certificate matching it.
For sure FQDN must be resolvable to Cluster/Gateway IP.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes, on the cluster/gateway properties under UserCheck you can enter the FQDN for UserCheck Portal and import a proper certificate matching it.
For sure FQDN must be resolvable to Cluster/Gateway IP.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Just to clarify, the UserCheck portal serves it's own certificate that is not subject to HTTPS Inspection (if I recall correctly).
Thus that certificate needs to be correct/something the client is configured to accept.
It would definitely be better if we could leverage the HTTPS Inspection CA in this case
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Agree with you on idea of using same cert for multiple purposes. It would actually be nice if the CA on SMS would've been a bit more functional with good front end. Some environments do not have PKI in place and could've used Check Point for this purpose.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The front end of the Internal CA is called SmartConsole
Granted, it's not meant as a full CA but for specific functionality, which could potentially be expanded.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
good one
