Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Wayne_Hammond
Collaborator
Jump to solution

Cant renew expiring certificate

Screenshot 2025-01-02 114202.png

Hi,

My VPN certificate on R81.20 Gateway expires soon and I went through the usual process of deleting the existing and creating a new one, however today I got hit with this message

 

I have not seen this before and cant find anyway round it. Found a similar post about using GuiDBedit, but that didnt work.

 

Any help greatly appreciated

Happy New Year

Wayne

0 Kudos
2 Solutions

Accepted Solutions
AkosBakos
Leader Leader
Leader

Maybe it is time to open a TAC case.

----------------
\m/_(>_<)_\m/

View solution in original post

0 Kudos
Wayne_Hammond
Collaborator

Fixed it.

First took snapshot of SM VM (in case I bust it)

Used GuiDBedit and found entry for VPN refence in the FW object

Deleted it

Saved changes

Said a prayer

Opened Smart Console

VPN reference gone

Pushed policy for good measure

Still gone

Case closed

Thanks for all your help guys !!

View solution in original post

23 Replies
Lesley
Mentor Mentor
Mentor

I never delete and always use renew, have you tried that?

So instead of delete either add or renew?

You try it now to renew it under IPSec VPN correct? 

-------
If you like this post please give a thumbs up(kudo)! 🙂
Wayne_Hammond
Collaborator

Hi Lesley,

The renew option has never been available for certs generated by external CA (i assumed this was the case)

I cannot renew and if i try ADD i cant use the same CN details

 

Cheers

Wayne

0 Kudos
Lesley
Mentor Mentor
Mentor

Ah not self-signed.

What if you create a temp self signed cert and attach that, after that try to remove the old one. 

-------
If you like this post please give a thumbs up(kudo)! 🙂
0 Kudos
Wayne_Hammond
Collaborator

Still no go

0 Kudos
AkosBakos
Leader Leader
Leader

Hi @Wayne_Hammond 

Can you share a little bit larger screenshot? In which menu did you get this message?

Whan you changed this cert last time, this cert was used in clientless VPN too?

Akos

----------------
\m/_(>_<)_\m/
0 Kudos
Wayne_Hammond
Collaborator

Hi Akos,

My larger images seem to get removed. I always do this under IPSecVPN and have never configured Clientless VPN

Cheers

Wayne

0 Kudos
AkosBakos
Leader Leader
Leader

To clarify this, so here:

You add the new one, then can't remove the old one?

2025-01-02 13_45_35-10.211.190.100-R81.20-SmartConsole.png

----------------
\m/_(>_<)_\m/
0 Kudos
Wayne_Hammond
Collaborator

Correct, at the moment I have a cert installed from an EXT CA

When i try to remove (as renew greyed out), the error message appears

I have never seen this before

Thanks

0 Kudos
AkosBakos
Leader Leader
Leader

I had a try, I wanted to delete the cert which was issued by ICA

I got this error: 

2025-01-02 14_08_11-10.211.190.100-R81.20-SmartConsole.png

Maybe helps.

A

----------------
\m/_(>_<)_\m/
0 Kudos
the_rock
Legend
Legend

Weird, just tried in my lab and though its part of 3 commuities, does not give that error.

Andy

0 Kudos
Lesley
Mentor Mentor
Mentor

Make sure that if you have the temp cert active the old one is not configured in a different place.

Did you checked all the menu options in the firewall object itself? Like under VPN clients. 

-------
If you like this post please give a thumbs up(kudo)! 🙂
0 Kudos
Wayne_Hammond
Collaborator

Hi Lesley,

Yes, i cannot see it selected anywhere else

0 Kudos
Lesley
Mentor Mentor
Mentor

I think we need some screenshots. Sometimes a feature is disabled and you need to enable it in order for renewal. 

-------
If you like this post please give a thumbs up(kudo)! 🙂
0 Kudos
AkosBakos
Leader Leader
Leader

We haven't talk about the version. What is current version?

I found this sk, but it is not relevant, R80.20 is not supported, and the error message is totally different.

https://support.checkpoint.com/results/sk/sk108064

Akos

----------------
\m/_(>_<)_\m/
0 Kudos
Wayne_Hammond
Collaborator

Saw that, but it did nothing

Thanks

0 Kudos
AkosBakos
Leader Leader
Leader

Maybe it is time to open a TAC case.

----------------
\m/_(>_<)_\m/
0 Kudos
Wayne_Hammond
Collaborator

Yes time for TAC

AkosBakos
Leader Leader
Leader

Please keep us updated. 🙂

----------------
\m/_(>_<)_\m/
0 Kudos
the_rock
Legend
Legend

I believe what its telling you to do is remove any references of that certificate currently, install policy and then delete option would work.

Andy

0 Kudos
Wayne_Hammond
Collaborator

yes, I am pretty sure all refences have been removed.

Waiting for TAC

Cheers all !!

0 Kudos
Wayne_Hammond
Collaborator

Fixed it.

First took snapshot of SM VM (in case I bust it)

Used GuiDBedit and found entry for VPN refence in the FW object

Deleted it

Saved changes

Said a prayer

Opened Smart Console

VPN reference gone

Pushed policy for good measure

Still gone

Case closed

Thanks for all your help guys !!

the_rock
Legend
Legend

Great!

0 Kudos
AkosBakos
Leader Leader
Leader

Thanks to share with us!

----------------
\m/_(>_<)_\m/
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events